Recent threat activity reveals attackers increasingly exploit trusted systems and AI components rather than direct breaches, emphasizing growing risks within everyday technology.
Researchers reveal Showboat, a Linux malware used since mid-2022 in a campaign against a Middle Eastern telecom company, offering remote shell, file transfer, and SOCKS5 proxy...
CISA has enhanced its Known Exploited Vulnerabilities Catalog by adding a new nomination form to facilitate reporting and inclusion of actively exploited vulnerabilities.
A maximum severity flaw in the latest Python FastAPI implementation of ChromaDB exposes servers to unauthenticated remote code execution. Immediate attention is advised for affected deployments.
GitHub is investigating an alleged breach after the TeamPCP hacker group claimed to have accessed thousands of its private code repositories. The company is reviewing the...
GitHub is investigating a potential security breach following claims by the threat actor TeamPCP of unauthorized access to thousands of internal repositories.
A newly disclosed Windows zero-day privilege escalation vulnerability, called MiniPlasma, allows attackers to gain SYSTEM-level access on fully patched systems. A proof-of-concept exploit has been publicly...
A local privilege escalation vulnerability in the Linux kernel's rxgk module has been patched, but a proof-of-concept exploit is now publicly available, enabling attackers to obtain...
Two new Windows zero-day vulnerabilities have been disclosed involving a BitLocker bypass and a privilege escalation in the Collaborative Translation Framework. The flaws were detailed by...
AI hallucinations, or confidently incorrect outputs, are creating security challenges by misleading human operators in critical infrastructure settings.