The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have ...
Chrome security update 151.0.7922.169/.170 patches 15 vulnerabilities, including two Critical sandbox-escape buffer overflows ...
Risky security flaws are found in 45% of AI-generated code tests. Here are the 5 checks that make a vibe coded app safe to ship.
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
Many countries have made progress, but others have slid backwards in terms of LGBTQ+ acceptance.
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. Although the threat actor has targeted government ...
China-linked Jewelbug used shared infrastructure to conduct government espionage and cryptocurrency fraud, logging more than ...