Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Sourc...
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Sourc...
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms, ena...
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S.
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited...
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on th...
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restricti...
Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software suppl...
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOO...
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S.
A threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credenti...
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's auto...
The attack occurred between 07:35 UTC and 21:45 UTC on Monday, August 31.
Abliteration.ai aims to enable offensive cyber operations, red-teaming, and agent testing that other models refuse.
The cyberattack, which occurred around June 15, resulted in the theft of patient data including names, dates of birth, medical testing information, laborator...
Invisible Unicode tag characters often used for AI prompt injection have appeared in high-volume phishing attacks.
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153...
The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.
Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchan...
Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets.