-
DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credenti…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an “undetected” version of the popular Xeno script executor. Security researchers wa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and trafficking-linked operations, and has shared indicators with industry peers and authorities to make the network…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OWASP has launched the Subtractive Security Top 10 project, a security engineering initiative that shifts the focus from adding more detection controls to removing the architectural conditions that enable cyberattacks. The project, led by Christopher F…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability allows un…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An exposed server linked to a Russian‑speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China’s artificial intelligence ecosystem is rapidly advancing through a controversial technique known as model distillation, with mounting evidence suggesting that military-linked entities are extracting high-value capabilities from leading American A…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross‑platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation cam…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers and escalate to remote code execution (RCE). This vulnerability is tracked as CVE-2026-59774 and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


