Mandiant says an attacker hijacked an active AI coding session, stole GitHub OAuth tokens, and spread Shai-Hulud across about ...
N0va phishing abuses legitimate authentication flows to capture access and refresh tokens and establish SSO access to ...
Researchers showed one browser extension could hijack AI features in five Chromium products; some demos could access files, ...
Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code ...
Issabel Framework flaw CVE-2026-89026 is under active exploitation and can enable unauthenticated OS command execution via a ...
WSO2 API Manager JWT bypass faces active exploitation attempts using forged tokens with administrator privileges.
U.S., U.K., and Dutch agencies say Iran’s intelligence service uses Telegram-controlled Windows malware to spy on dissidents ...
BambooToken uses MQTT for C2 across Windows and Linux, with a dozen compromised entities detected in Asia and South America.
A report links OpenAI agents to a RubyGems campaign that abused RubyDoc for RCE and published more than 2,000 packages in May ...
LiteSpeed Enterprise before 6.3.7 has a flaw that can let a low-privilege website user gain root access; exploitation is unknown.
This week: rogue AI agents, a zero-click WeChat worm, PaperCut attacks, AI-powered espionage, exploit chains, rootkits, and ...
AI-related SOC alerts rose 685% from February to June 2026, with 94.1% classified as noise and 5.8% as genuine security risks ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results