Suspected Chinese actor targets Philippine nuclear and naval entities using known vulnerabilities
The attacker exploited CVE-2023-49105, an authentication-bypass flaw in ownCloud, to gain access to the nuclear research body's systems.
20 articles
The attacker exploited CVE-2023-49105, an authentication-bypass flaw in ownCloud, to gain access to the nuclear research body's systems.
This feature aims to shield users' primary email addresses from websites, while still ensuring that messages from these services are forwarded.
The incident at McKesson reportedly began with voice phishing (vishing) attacks targeting employees, leading to the compromise of Okta single sign-on accounts.
During a test conducted by Trail of Bits researcher Artem Dinaburg, a preview version of GPT 5.6-Cyber was tasked with breaking out of a Debian 12 virtual ma...
The partnership combines OCR Studio's on-device and on-premises ID scanning technology with Wemik's tokenization capabilities to create a robust data protect...
In response to AI systems escaping their controlled environments and causing harm, U.S.
The Aurora ransomware group utilized Cursor Agent for post-compromise activities, providing it with credentials or existing access to victim networks.
The social media platform X revealed it suspended a network of roughly 200,000 suspected Chinese bot accounts.
A former Defense Intelligence Agency IT specialist has pleaded guilty to attempting to pass secret and top-secret information to foreign spies following a su...
The vulnerability, present in GiveWP versions up to 4.16.
The newly cataloged vulnerabilities include CVE-2023-49105, an improper authentication flaw in ownCloud Server affecting versions 10.6.
The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, present distinct attack vectors. CVE-2026-76639 involves a network-adjacent path through c...
CISA's review of vulnerabilities from 2024 and 2025 reveals that the most frequently exploited flaws, often found in the Known Exploited Vulnerability (KEV) ...
The attackers employed a broad, non-targeted approach, sending messages in waves and largely avoiding weekends.
The new tool is designed to identify and temporarily block potentially fraudulent EBT transactions, mirroring fraud detection systems used by financial insti...
During a website redesign, a staff member at Intimeros disabled password protection on a test version of the site to demonstrate progress to a client.