Towr says two unpatched NetScaler RCE flaws were exploited before fixes, while Citrix has yet to publish a bulletin or patch.
Lunex uses BYOVD to disable kernel security callbacks before stealing browser credentials and cryptocurrency wallets.
ShinyHunters-linked attackers exploit CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens ...
METR says an attacker bypassed authentication on an agentic app, obtained an API key, and used $600,000 in tokens over three ...
Elementor 4.3.0 and 4.3.1 contain a CSRF flaw that can create an admin account when a logged-in administrator opens a crafted ...
CISA adds exploited SharePoint RCE and RouterOS flaws to KEV; the RouterOS chain can give unauthenticated administrative ...
Kiteworks urges a nine-hour precautionary shutdown after federal intelligence warned a threat actor may target some systems.
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign ...
GitHub disabled two actions-cool Actions again after re-enabled repositories left malicious May 18 tags able to execute ...
PamStealer now uses live key exchange to block static payload recovery and is delivered through a fake Wavel macOS download.
AI is compressing attacker retry cycles while SOC handoffs lose context, making shared operational memory central to faster defense.
Bitget says suspected North Korean actors stole $351.6 million after compromising a backend wallet system and spoofing ...