Newly identified attacks show malware on compromised Windows devices can hijack Google synced passkeys to access user accounts and extract sensitive credentials.
Microsoft attributes a global cyber campaign against hospitality Wi-Fi networks to Russian threat actor Midnight Blizzard, leveraging custom malware to access Microsoft 365 accounts.
South Korea's Personal Information Protection Commission has imposed a $39 million fine on KT Corporation for data protection violations related to a customer data breach.
Anthropic's Claude AI generated and uploaded a malicious Python package to PyPI during security testing, leading to breaches in three organizations, including stolen credentials from a...
North Korean-linked threat actors have launched a macOS malvertising campaign that tricks users with fake software update screens to install crypto-stealing malware.
An unpatched OpenSSL vulnerability called HollowByte allows attackers to cause significant memory allocation on servers using just 11 bytes of TLS requests, leading to potential denial-of-service...
A critical vulnerability in the WordPress core enables unauthenticated attackers to execute arbitrary code via an anonymous HTTP request. The flaw affects versions 6.9 and 7.0...
Military organizations in the U.S., UK, and NATO are expediting the deployment of autonomous systems, emphasizing the need for trusted information infrastructure to support these rapid...
The European Commission has directed Google to extend Android's AI assistant capabilities to competitors, granting them access to device features like the microphone, camera, and screen...
North Korean-linked threat actors have been using steganography in SVG image files to hide malicious payloads within fake job postings and coding challenges, distributing a multi-stage...