Craneware confirms customer and employee data exposed in security incident.
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch.
Paidwork breach exposes data of 23 million users: Check if you’re affected.
Greedy ransomware crews return for seconds after victims cough up first extortion payments.
A cyberattack targeting Tidewater Telecom disrupted internet service for at least 23 towns in Maine's midcoast region on Sunday, affecting municipal governments and residents, as reported by Statescoop.
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities.
Windmill servers are under active attack.
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
An attacker does not need the reviewer’s broader Azure DevOps permissions.
In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly.
In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly.
Russian Hacker Used Gemini to Manage a Botnet
Trend Micro announced that a Russian hacker used Gemini CLI to manage a small botnet, delegating a significant portion of the technical tasks, including code writing, debugging, command execution, and even transferring the command and control (C2) server, to this AI tool.
Trend Micro announced that a Russian hacker used Gemini CLI to manage a small botnet, delegating a significant portion of the technical tasks, including code writing, debugging, command execution, and even transferring the command and control (C2) server, to this AI tool.
Qualys researchers have disclosed a high-severity vulnerability in Ubuntu’s snap-confine component that allows an unprivileged local user to gain root access. Tracked as CVE-2026-8933, the flaw can give an attacker complete administrative control of an affected computer.