China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT; Tencent fixed the issue in version 16.3.0.3498 ...
Anthropic's Threat Intelligence team has disclosed a sweeping new report detailing how state-sponsored espionage groups, ...
Proofpoint says at least four espionage groups rapidly adopted BlueMoon, chaining Chrome V8 patch-gap flaws with a Windows LPE to deliver malware including GemStone and ShadowPad.
A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of ...
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant ...
Accordion racks are having a bit of a moment. Instead of using one to hang your coats, mount it above a window and hang ...
A Windows post-exploitation toolkit linked to a ransomware investigation used reverse shells, credential theft utilities, ...
Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education ...
Microsoft has announced Project Zenith, a preconfigured Windows 11 experience meant for developer-class PCs with coding tools ...
The AI platform ServiceNow which offers both hosted and on-premises versions just patched a trifecta of CVSS-10 vulnerabilities. CVSS rankings are determined by the severity of a flaw, the ease of ...
Cronos validators halted block production after an attacker exploited Tectonic, the chain’s largest lending protocol, for ...
Microsoft Threat Intelligence has discovered TerminalFix, a campaign that uses fake CAPTCHAs to trick users into running PowerShell scripts.