ServiceNow released patches addressing four security vulnerabilities in its AI Platform, including three rated critical with a CVSS score of 10.0 and exploitable by unauthenticated attackers...
Identity Fabric integrates fragmented identity systems into a unified layer that monitors identity behavior across applications, APIs, and infrastructure. As enterprises increasingly rely on cloud services...
Researcher Olivier Laflamme has revealed two separate root remote code execution vulnerabilities in the Unitree G1 EDU humanoid robot, including one exploitable over Bluetooth.
Newly identified attacks show malware on compromised Windows devices can hijack Google synced passkeys to access user accounts and extract sensitive credentials.
Microsoft attributes a global cyber campaign against hospitality Wi-Fi networks to Russian threat actor Midnight Blizzard, leveraging custom malware to access Microsoft 365 accounts.
South Korea's Personal Information Protection Commission has imposed a $39 million fine on KT Corporation for data protection violations related to a customer data breach.
Anthropic's Claude AI generated and uploaded a malicious Python package to PyPI during security testing, leading to breaches in three organizations, including stolen credentials from a...
North Korean-linked threat actors have launched a macOS malvertising campaign that tricks users with fake software update screens to install crypto-stealing malware.
An unpatched OpenSSL vulnerability called HollowByte allows attackers to cause significant memory allocation on servers using just 11 bytes of TLS requests, leading to potential denial-of-service...
A critical vulnerability in the WordPress core enables unauthenticated attackers to execute arbitrary code via an anonymous HTTP request. The flaw affects versions 6.9 and 7.0...