- Attackers conceal phishing lures using invisible Unicode characters
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted
- OpenAI admits it didn’t disclose rogue AI wiki hijacking incident
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
- IDScan sued over alleged data breach affecting 153 million drivers
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
- Critical Citrix NetScaler auth bypass now leveraged in attacks
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution