Researchers uncover 7,600 FakeGit GitHub repos, including 800 AI skills and MCP lures spreading SmartLoader malware.
Three malicious RubyGems packages in the SleeperGem attack skip CI runners, target developer machines, and install persistent ...
HollowGraph uses Microsoft 365 calendar events dated to 2050 to receive commands and exfiltrate encrypted files through ...
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source ...
Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service ...
Russian intelligence hijacks exposed cameras to track military routes as Censys flags 87,000 devices matching known-exploited ...
AI-driven discovery widens the exposure window as attackers break out in 29 minutes while critical application flaws take 55 ...
Rapid7 pulls 1,048 files from an exposed server, linking an LLM-assisted phishing pipeline to a live WebDAV campaign ...
This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding ...
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a ...
AI agents inherit long-lived secrets and standing privilege, turning old identity gaps into machine-speed risk across ...
Volexity links UTA0533 to two SonicWall SMA 1000 zero-days used before disclosure to gain root, plant malware, and capture ...