CVE-2025-25249, a remote code execution vulnerability in Fortinet products, has been exploited in PivotC2 RAT attacks.
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
A critical vulnerability in MapLibre GL JS could allow attackers to execute zero-click cross-site scripting attacks through ...
Chrome users have another zero-day problem on their hands. Google has patched CVE-2026-87491, a vulnerability in the V8 JavaScript and WebAssembly engine that attackers are already exploiting in the ...
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such ...
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authen ...
The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still ...
Researchers found a phishing service relaying live Google sign-in sessions to intercept passwords, 2FA codes, and active ...
Attackers persuade employees to accept a remote-control request during screen sharing or to open Quick Assist and provide its ...
Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results