Telegram Desktop fixed a flaw that let bot messages embed JavaScript in HTML exports to read or alter messages; old exports ...
WordPress will automatically review plugin releases and block high-risk updates after a backdoor was caught before ...
This week: rogue AI agents, a zero-click WeChat worm, PaperCut attacks, AI-powered espionage, exploit chains, rootkits, and ...
Microsoft details a million-email CEO fraud campaign and passkey-themed attacks that compromised cloud accounts and enabled ...
AI agents can discover local credentials and inherit their permissions, while GitGuardian found 24,008 secrets in public MCP ...
AI-related SOC alerts rose 685% from February to June 2026, with 94.1% classified as noise and 5.8% as genuine security risks ...
A report links OpenAI agents to a RubyGems campaign that abused RubyDoc for RCE and published more than 2,000 packages in May ...
China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT; Tencent fixed the issue in version 16.3.0.3498 ...
Anthropic says threat actors used Claude in autonomous cyber operations, including reconnaissance, exploitation, and data ...
Anthropic disrupted GTG-20006, a Russian state-sponsored actor that used Claude to rebuild malware after security products ...
Check Point fixes two VPN certificate flaws that can enable unauthenticated remote code execution under unspecified ...
Anthropic says China-based AI labs ran illicit Claude distillation campaigns using proxy networks, fake accounts, and ...