A government organization providing cloud infrastructure to Indian companies is inadvertently distributing malware.
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing ...
Magento zero-day vulnerability CVE-2026-75650 exploited a fully patched store for three days before Adobe released APSB26-146 on September 7. A self-updating Rust backdoor survived the patch, evaded ...
PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
A financially motivated actor used an autonomous multi-agent framework to compromise thousands of third-party credentials in ...
Threat actors are actively abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files ...
AI agents helped attackers launch a cloud credential theft campaign in under six hours, stealing thousands of third-party ...
Threat actors are beginning to test a new way to evade AI-powered security tools: placing harmful prompt-injection content ...
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose ...
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension ...
Google Threat Intelligence Group says a financially motivated actor used a multi-agent AI framework to plan, build, and run a ...
Security Solution to mitigate agentic AI risks. Built to scan before adoption, test before deployment and protect after ...