Google says threat actors hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several of its domains.
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.
Bitdefender uncovered Midnight Mimosa, a firmware-level Android malware campaign shipping preinstalled on budget smartphones ...
The US has seized MicroScan and FishHub, tools used by Flax Typhoon and other Chinese APTs in critical infrastructure ...
Anthropic’s OSS Scanner sends unreviewed AI bug reports to opt-in open source projects, while a new program brings Claude to ...
Citrix urges customers to immediately patch CVE-2026-107406, a critical NetScaler vulnerability leading to remote code ...
Participants earned over $1.2 million at Pwn2Own Ireland 2026 for exploits targeting Google Pixel 10 phones, AI infrastructure, and smart home tools.
GWU researchers developed a mathematical model to predict when local AI transformer models tip into rogue behavior during ...
Cisco has patched over a dozen critical vulnerabilities that could lead to RCE, DoS, privilege escalation, and other types of ...
Experts are split on whether security awareness training works and a cognitive psychologist explains how it could be improved ...
Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products ...
Department of State is offering $10 million for information on Zhang Yu, a Chinese national accused of taking part in the Hafnium attacks.