-
OWASP has launched the Subtractive Security Top 10 project, a security engineering initiative that shifts the focus from adding more detection controls to removing the architectural conditions that enable cyberattacks. The project, led by Christopher F…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability allows un…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An exposed server linked to a Russian‑speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China’s artificial intelligence ecosystem is rapidly advancing through a controversial technique known as model distillation, with mounting evidence suggesting that military-linked entities are extracting high-value capabilities from leading American A…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross‑platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation cam…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers and escalate to remote code execution (RCE). This vulnerability is tracked as CVE-2026-59774 and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to execute arbitrary code on vulnerable servers without authentication. The update is documented in …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned GitHub repositories to distribute infostealers and exfiltrate sensitive data. The latest evolution sho…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow unauthorized deletion of Parameter Context assets, and a high-severity issue that results in excessive mem…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


