Threat actors are actively abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files ...
Researchers demonstrate InjectEave EM attack, SIM swapper is sentenced to prison, and VulnCheck reviews vulnerabilities found via Glasswing.
A government organization providing cloud infrastructure to Indian companies is inadvertently distributing malware.
AI agents helped attackers launch a cloud credential theft campaign in under six hours, stealing thousands of third-party ...
Magento zero-day vulnerability CVE-2026-75650 exploited a fully patched store for three days before Adobe released APSB26-146 on September 7. A self-updating Rust backdoor survived the patch, evaded ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authen ...
A financially motivated actor used an autonomous multi-agent framework to compromise thousands of third-party credentials in ...
Chrome zero-day attacks, router hijacks, Coder’s supply chain breach, image-free QR phishing, and more security news.
MCP is now stateless at the protocol level. The Mcp-Session-Id header and the initialize/initialized handshakes that linked ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
External data should be treated as hostile until it has been checked, constrained, and transformed for the specific place it will be used. That applies whether the data comes from a browser form, a ...
GENEVA — An 18-year-old man with a sword attacked a school Friday in central Sweden, leaving one person dead and at least two others seriously injured, a police chief said. Police Chief Tommy ...