A one-click Sogou Input Method flaw let UNC3569 deploy GRAYRABBIT backdoor, enabling remote code execution and data theft.
Over 5,400 legitimate websites now serve fake CAPTCHA scams that trick users into pasting malware commands into Windows Run ...
A flaw in Telegram Desktop allowed specially crafted bot messages to execute JavaScript in HTML chat exports and expose ...
GitHub Advanced Security released REST API endpoints on September 10 giving enterprise teams programmatic control over ...
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta ...
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...
The Combat Sports Authority cancelled the event, saying it had not complied with the rules required for such an event.
Someone is afraid of missing out, as defenders rush to patch things up.
Google Threat Intelligence Group says a financially motivated actor used a multi-agent AI framework to plan, build, and run a ...
Proofpoint says at least four espionage groups rapidly adopted BlueMoon, chaining Chrome V8 patch-gap flaws with a Windows LPE to deliver malware including GemStone and ShadowPad.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
Cisco Talos has uncovered a cryptocurrency theft campaign that abuses Google Sheets and the Google Visualization API as a ...