HAProxy backdoor attributed to North Korea ran undetected inside two South Korean organizations for nine to ten months, using ...
Deal reached to delete data stolen from Canvas hackers News The company that operates the online learning system Canvas said it struck a deal with hackers to delete the data they pilfered in a ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing ...
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable ...
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency ...
The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still ...
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject ...
Attackers persuade employees to accept a remote-control request during screen sharing or to open Quick Assist and provide its ...
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant ...
A newly disclosed AI security threat dubbed Workflow Identity Hijacking could let attackers extract sensitive enterprise data ...
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused ...
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced ...