AI-Built Ransomware Toolkit Automates Active Directory Recon and EDR Evasion
Cyberattackers have been utilizing AI-generated ransomware attack toolkits. These AI-powered toolkits can automate Active Directory discovery and…
The 10 Best Antivirus Suites, Ranked
Our editorial team ranked ten security suites on protection, performance, features, and value — with one clear recommendation for most people.
See the Top 10 →
SearchLeak Flaw Chain Turned Microsoft 365 Copilot Into a Data Theft Tool
A dangerous chain of vulnerabilities called SearchLeak in Microsoft 365 Copilot Enterprise allows a potential attacker to take sensitive data from…
AutoJack Exploit Chain Lets a Web Page Hijack Microsoft AutoGen Studio AI Agents
An exploit chain known as AutoJack in Microsoft's graphical interface called AutoGen Studio, used for prototyping artificial intelligence agents…
AryStinger Malware Turns Aging Home Routers Into a Hidden Reconnaissance Network
In terms of functionality (not impact) the AryStinger campaign uses previously unknown malware to convert millions of old home routers into an…
One-Character Linux Kernel Bug Hands Local Users Root and Container Escape
Researchers at Exodus Intelligence posted an illustrated step-by-step way to do a use-after-free attack on Linux which gives an unprivileged local…
Operation Endgame Disrupts SocGholish and Cleans Nearly 15,000 WordPress Sites
Dutch law enforcement agencies working with similar agencies in Germany, Canada and the United States have broken up a criminal network using the…
Operation Endgame Dismantles Amadey and StealC and Recovers 27 Million Credentials
On Monday, Europol announced that the global law enforcement community, working together with several key private-sector organizations, including…
Latest
-
MalwareStealthy Mistic Backdoor Gives Ransomware Brokers Long-Term Network Access
Although the information regarding these events is based upon publicly available sources…
-
VulnerabilitiesNew 7-Zip Flaw (CVE-2026-48095) Enables Code Execution Through Crafted Archives
A new CVE (CVE-2026-48095) in 7-Zip means that malicious archive processing and…
-
BreachesShinyHunters Exploit an Unpatched Oracle PeopleSoft Flaw to Steal Enterprise Data
The exploitation of an unpatched flaw in the Oracle PeopleSoft system by ShinyHunters…
-
IdentityPalo Alto GlobalProtect Authentication Bypass Lets Attackers Open VPN Sessions
CVE-2026-0257 is an "Authentication Bypass" vulnerability in firewalls manufactured by…
-
Cloud & InfraCritical Ubiquiti UniFi OS Bugs Let Attackers on the Network Take Over Devices
All an attacker needs to do is get onto the same network as your UniFi device in order to…
-
VulnerabilitiesCritical Veeam Backup and Replication Bug Lets Any Domain User Run Code
Veeam issued security updates for the Backup & Replication critical security weakness…
-
VulnerabilitiesFFmpeg PixelSmash Flaw Turns Malicious Video Files Into Remote Code Execution
The FFmpeg issue, known as "PixelSmash", allows for Remote Code Execution (RCE) when…
-
AppSecServiceNow Patches Unauthenticated API Flaw That Exposed Customer Instance Data
ServiceNow has issued warnings of a possible security incident because hackers have taken…
-
MalwareMalicious AUR Packages Hit Arch Linux With a Credential Stealer and Kernel Rootkit
More than 400 packages in the Arch User Repository (AUR) are currently being distributed…
-
VulnerabilitiesAI Cyberattacks: Two Years of Insane Vulnerabilities
SAN FRANCISCO – As always, each RSA Conference has its share of buzzwords: Cloud…