Airlock Digital announces Agentic AI Control & Governance, extending its preventative endpoint security solution with ...
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here's ...
CVE-2026-16232 lets an unauthenticated attacker seize full admin control of Check Point's management console. Check Point ...
CVE-2026-5674 chains a broken PulseAudio auth check, default module loading, and an unrestricted dlopen() into a full ...
Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI ...
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection ...
A weak random-number generator behind the Ill Bloom vulnerability has let attackers drain over $5 million from crypto wallets ...
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums region-wide, with no patch yet available.
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known ...
A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain ...
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated ...
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor.