Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in G...
20 articles
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in G...
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter appl...
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-1...
Security researchers have revealed a recently patched flaw in ChatGPT’s isolation system that could have allowed attackers to access data from a victim’s con...
Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance, vulnerability r...
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for persi...
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arb...
U.S.
Best value overall: Bitdefender — competent managed XDR at pricing that mid-market organizations can approve, which most of this list cannot claim. Best dete...
Best value overall: Huntress — published pricing, purpose-built for small business, and genuinely good at the threats that segment faces. Best response autho...
Best value overall: Microsoft Defender XDR — included in Microsoft 365 E5 and genuinely strong across Microsoft’s own surface, which for most organizations i...
Best value overall: Microsoft Defender for Endpoint P2 — included in Microsoft 365 E5 and genuinely competitive, which makes its marginal cost zero for a lar...
Best value overall: Bitdefender — leading detection at mid-range pricing with a light footprint. Best free option: Malwarebytes’ scanner, which cleans an inf...
cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to creat...
Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticat...
Information-stealing malware is expanding its collection logic to target locally stored data from AI coding agents, including Claude, Cursor, Codex, Cline, C...
Ivanti has released security updates addressing 10 vulnerabilities in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The vulnerabilities inclu...
A cryptocurrency-stealing campaign that abuses Google Sheets and the Google Visualization API as a covert command-and-control channel, delivering obfuscated ...
Google released Chrome version 153 to the Stable channel for Windows, macOS, and Linux, including 230 security fixes and addressing CVE-2026-87491, a zero-da...
A large-scale Redis cryptojacking operation targets thousands of exposed Linux servers by abusing unauthenticated Redis deployments to install XMRig cryptocu...