Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are in 6.2.0 and 7.0.1.
Cloudflare Workers Spectre attack research published August 19, 2026 showed JWT token theft at 12 bits per second in live ...
Kaspersky researchers found 92,000 malicious attacks disguised as AI services in 2026, with fake ChatGPT, Claude and Gemini ...
The campaign uses EtherHiding to dynamically update its command-and-control server, using the blockchain as an ...
The findings raise questions over whether existing endpoint and network controls provide enough visibility into malicious ...
Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, and ...
The automation platform with AI capabilities, n8n, is vulnerable in several places. In the worst-case scenario, attackers can ...
OpenAI released GPT-6 Astra, which president Greg Brockman called a "generational leap" and the arrival of AGI. Astra is the first model OpenAI has designated "critical" under its Preparedness ...
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
FulcrumSec claims it stole 86 GB of customer and booking data from MAG, including nearly 200,000 records concerning future ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results