Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws.
Microsoft patched a SharePoint flaw after attackers had already exploited it as a zero-day.
CVE-2026-58644 affects every supported on-premises SharePoint version and can lead to remote code execution.
CISA has now added it to KEV.
CVE-2026-58644 affects every supported on-premises SharePoint version and can lead to remote code execution.
CISA has now added it to KEV.
Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.
The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for password resets.
The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for password resets.
Australian regulator declines to find Qantas responsible for 5.67 million customer data exposure.
Daxin malware resurfaces with new backdoor targeting Taiwan manufacturer.
🤔1
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing.
China 'just erased' US AI lead — Axios
Moonshot AI drops Kimi K3 — an open-weight model that BEATS Anthropic's Opus 4.8 on several benchmarks
And it's ~40% cheaper
Moonshot AI drops Kimi K3 — an open-weight model that BEATS Anthropic's Opus 4.8 on several benchmarks
And it's ~40% cheaper
wp2shell now has two CVEs, and a working proof-of-concept is public.
> CVE-2026-63030 breaks REST batch routing
> CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
> CVE-2026-63030 breaks REST batch routing
> CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
OpenSSL quietly fixed HollowByte, a flaw where an 11-byte TLS request can reserve up to 131 KB of server memory per connection.
On the glibc systems researchers tested, that memory remained frozen until restart.
On the glibc systems researchers tested, that memory remained frozen until restart.
Seven malicious npm packages are targeting Vite developers.
They stay quiet during installation. Import one, and it starts a RAT delivery chain that can steal credentials, exfiltrate files, and open a reverse shell.
They stay quiet during installation. Import one, and it starts a RAT delivery chain that can steal credentials, exfiltrate files, and open a reverse shell.
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft.
Cyber Dispatch™️
Seven malicious npm packages are targeting Vite developers. They stay quiet during installation. Import one, and it starts a RAT delivery chain that can steal credentials, exfiltrate files, and open a reverse shell.
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT.
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets.
New Russian-speaking attacker UAT-11795 targets US and Europe with novel malware.
Italy fines Wind Tre $2 million for data breaches affecting 365k customers.
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants.