U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog.
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government ...
StopAndProtect turned nearly 2K hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance ...
An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password ...
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours.
U.S. CISA adds Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog.
Microsoft tracked +30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting ...
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that ...
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in ...
Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature.
7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what ...
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of ...