Thousands of hacked sites use fake CAPTCHA prompts to trick visitors into running malware. Learn the warning signs before ...
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...
“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent ...
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain.
CVE-2025-25249, a remote code execution vulnerability in Fortinet products, has been exploited in PivotC2 RAT attacks.
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
A critical vulnerability in MapLibre GL JS could allow attackers to execute zero-click cross-site scripting attacks through ...
Chrome users have another zero-day problem on their hands. Google has patched CVE-2026-87491, a vulnerability in the V8 JavaScript and WebAssembly engine that attackers are already exploiting in the ...
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such ...
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authen ...