Google has patched an actively exploited Chrome V8 zero-day that lets attackers run code inside the sandbox via a crafted web page.
CVE-2025-25249, a remote code execution vulnerability in Fortinet products, has been exploited in PivotC2 RAT attacks.
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor.
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
A critical vulnerability in MapLibre GL JS could allow attackers to execute zero-click cross-site scripting attacks through ...
Chrome users have another zero-day problem on their hands. Google has patched CVE-2026-87491, a vulnerability in the V8 JavaScript and WebAssembly engine that attackers are already exploiting in the ...
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such ...
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authen ...
The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still ...
A financially motivated actor used an autonomous multi-agent framework to compromise thousands of third-party credentials in ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results