- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
- What happens if you visit a WordPress site hacked through wp2shell?
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
- Closing the Identity Gaps in Critical Infrastructure Security
- Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
- Choose Wisely: AI-Generated Coding Risk Varies, A Lot
- New ClickLock Stealer locks your Mac until you hand over your password
- Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
- N-day is Becoming N-Hour. Patching Faster Won't Save You.
- Don’t trust that “FBI agent” in your DMs
- New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
- US seizes over 1,000 websites in FIFA World Cup piracy crackdown
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
- A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
- AI nudify apps spark legal scrutiny of Apple and Google’s profits
- Microsoft shares manual fix for WSUS sync delays and timeouts
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
- Windows LegacyHive zero-day flaw gets free, unofficial patches
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- Estée Lauder discloses data breach via Oracle E-Business flaw
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware
- Hackers steal $23.7 million in crypto from Ostium in off-chain attack
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
- JadePuffer agentic attacks now target AI model data with ransomware
- Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
- 25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
- CISOs Feel the Heat Over AI Risk
- Attackers Combo Up Evasion Tactics for BEC Phishing
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
- Odyssey piracy scams appear within hours of the movie’s release
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- Healthcare giant Abbott probes two cyber incidents amid extortion claims
- An AI SOC Evaluation Guide for Security Leaders
- Cybersecurity Keeps Events 'Uneventful'
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
- Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine