Socket’s Threat Research Team has uncovered a massive supply-chain abuse campaign leveraging npm’s public registry and unpkg.com’s...
cybersecurity
Cisco Talos has confirmed that ransomware operators are now abusing Velociraptor, an open-source digital forensics and incident...
Researchers from Palo Alto Networks Unit 42 have discovered a new phishing trend where attackers trick victims...
Major AI platforms are increasingly developing browser-based intelligent agents capable of performing tasks such as browsing the...
CrowdStrike has sounded the alarm on an ongoing mass exploitation campaign targeting Oracle E-Business Suite (EBS) applications...
Microsoft Threat Intelligence has issued a warning following the discovery of active exploitation of a newly disclosed...
A newly disclosed vulnerability in DrayTek’s Vigor routers, tracked as CVE-2025-10547, could allow remote attackers to execute...
Oracle has issued an emergency Security Alert addressing a critical vulnerability (CVE-2025-61882) in Oracle E-Business Suite, warning...
IBM’s enterprise Linux subsidiary, Red Hat, has confirmed that its managed repository—hosted on the GitLab platform—was compromised...
The latest analysis from Trellix ARC reveals the unexpected return of XWorm, a notorious Remote Access Trojan...
Recently, GreyNoise observed a sudden and highly coordinated wave of exploitation attempts targeting CVE-2021-43798, a Grafana path...
The WARMCOOKIE backdoor has resurfaced with new features, expanded infrastructure, and updated delivery mechanisms, according to a...
The Termix project has disclosed a critical authentication bypass vulnerability in its official Docker image, exposing sensitive...
The security of the open-source software supply chain was once again tested when JFrog’s security research team...
A new report from Sekoia.io’s Threat Detection & Research (TDR) team reveals how attackers are weaponizing industrial...
The U.S. Federal Communications Commission (FCC) recently and inadvertently released a 163-page PDF document in its public...
A newly disclosed local privilege escalation vulnerability, CVE-2025-41244, has been exploited as a zero-day in the wild,...
Western Digital (WD) has patched a critical vulnerability in its My Cloud NAS platforms that could allow...
Broadcom has released patches for three vulnerabilities affecting VMware vCenter Server and VMware NSX, with severities rated...
The Apache Fory project, a high-performance multi-language serialization framework, has disclosed a critical vulnerability (CVE-2025-61622) that could...
Doxense has issued an urgent security advisory addressing a critical remote code execution (RCE) vulnerability in its...
Broadcom has released patches addressing three vulnerabilities in VMware Aria Operations and VMware Tools, with severities ranging...