FBI disrupted proxy infrastructure used in China-linked espionage to profile and steal data from U.S. critical infrastructure ...
CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.
Two unpatched Kaltura mwEmbed flaws allow unauthenticated file read and could enable RCE through unsafe deserialization.
INTERPOL's Operation Jackal IV arrests 58 people, identifies 263 suspects, and disrupts fraud and laundering networks across ...
Aikido finds Claude Opus 4.6 bypassed a seven-day booking limit in 9 of 10 OpenClaw runs, with two runs canceling another ...
AnonyMousKIT uses AI voice agents posing as Apple Support to request passcodes, Apple ID credentials, and live 2FA codes from ...
Agentic AI lets SOCs investigate alerts and threat hypotheses using network telemetry before escalating evidence-backed cases ...
CISA adds actively exploited CVE-2026-21962 to KEV; the Oracle flaw can expose or alter critical data via unauthenticated ...
Mirage2FA targets Microsoft 365, with 48% of targeted emails potentially compromised and 9,000+ potential session-theft ...
Attackers are scanning for two miniOrange SAML flaws, including CVE-2026-15981, that can bypass login and grant WordPress ...
Marimo fixes CVE-2026-75149, an 8.7-severity flaw that can launch an MCP command before notebook cells run in edit mode.
U.S. Treasury sanctions Iran-linked cyber actors under Operation Economic Outcast, targeting MOIS-linked hackers tied to U.S.