Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Aggregated from vendor advisories, security research, and industry publications.
Plus dozens of PoCs in the public domain
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances…
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed pr…
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on t…
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Goo…
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model che…
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions.
IC3 says any account claiming to represent it is fake
An expired card, overzealous spam filter, and broken authenticator create havoc with a very clear moral
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today.
Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
Chinese open-weight model GLM 5.2 happily obliged
Convenience store and gas station chain Sheetz announced it is replacing VMware across its network of more than 830 retail locations with StorMagic’s SvHCI hyperconverged infrastru…
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protoc…
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltra…
Take a Network Break! In this week’s episode our red alert highlights two critical vulnerabilities in RabbitMQ, and we dig into listener follow-up about data centers in space. This…
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments…
OOXML may carry an ISO certificate, but only Office can be trusted to render it properly
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control an…
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attac…
Redmond has stabilized new installations, but existing deployments remain stuck in sync purgatory
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware fo…
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for ass…
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, an…
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often…
Chatbots and agents will have to come clean about who – or what – users are talking to
On this week's episode of The Kettle, we welcome a special guest to discuss how the AI datacenter buildout is setting the world on fire – literally