WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Operation QUICSILVER targets Myanmar government and IT sectors with graduation lures that deploy the Go-based QUICAgent ...
Akamai finds the top 5% of enterprise AI users interact at 12 times the rate of the bottom 50%, concentrating shadow AI risk.
AI-powered PLC attacks, GitLab exploits, npm backdoors, cloud leaks, auth abuse, and payment fraud lead this week’s ...
Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
OMICRON Threat Intelligence correlates OT vulnerabilities, assets, and 300+ protocols to help energy teams focus on relevant risk.
Verifiable search data gives AI teams reproducible inputs for testing, incident review, drift monitoring, and model oversight ...
TikTok will pay $400 million to settle a U.S. child privacy case alleging COPPA violations involving users under 13 and Kids ...
New malware abuses DoFun Android head unit updaters to deliver JarService, run ad fraud, and download the Zhima reverse proxy ...
GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects ...
Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and ...
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing ...