Security researchers identified 73 counterfeit Visual Studio Code extensions on the Open VSX repository linked to the GlassWorm information-stealing malware campaign.
The pro-Ukrainian hacktivist group PhantomCore has been actively exploiting multiple vulnerabilities in TrueConf video conferencing servers targeting Russian networks since September 2025.
Anthropic’s Claude Mythos Preview, announced on April 7, is a cybersecurity AI system that identifies vulnerabilities at scale, prompting discussions on the remediation capabilities of security...
Itron, a U.S.-based utility technology company, has revealed a cybersecurity incident involving unauthorized access to its internal IT systems, according to an SEC filing.
A critical vulnerability, CVE-2026-5752, has been disclosed in the Python-based Terrarium sandbox, enabling attackers to achieve arbitrary code execution with root privileges via prototype chain traversal...
Researchers have identified a new LOTUSLITE malware variant linked to Mustang Panda, targeting Indian banking sector themes and South Korean policy circles with espionage tools.
Microsoft issued out-of-band updates to fix a critical privilege escalation vulnerability in ASP.NET Core, tracked as CVE-2026-40372, rated important with a CVSS score of 9.1.
The threat actor Harvester has been linked to a new Linux version of the GoGra backdoor employing the Microsoft Graph API to stealthily command compromised systems...
Researchers have identified a new data wiper malware called Lotus Wiper used in destructive attacks against Venezuela's energy sector at the end of 2025 and early...
Researchers disclosed that Moltbook, a social network for AI agents, left a database exposed, revealing thousands of email addresses and millions of agent API tokens along...
The Seiko USA website was defaced with a message from an attacker claiming to have stolen its Shopify customer database and threatening to release it unless...