Mass scanning campaign targets Vite development servers for cloud credentials
The operation utilizes an exploit for CVE-2026-39364, a critical flaw affecting Vite versions 7.1.
20 articles
The operation utilizes an exploit for CVE-2026-39364, a critical flaw affecting Vite versions 7.1.
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communi...
The vulnerability, identified as CVE-2026-82079, affects Switch systems running firmware versions prior to 23.0.
Here are five ways teams can stay resilient as adversaries gain access to frontier AI models.
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center.
The DDRop attack requires an adversary with existing software control of a server and brief physical access to install a custom interposer circuit board betw...
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol t...
The integration embeds Dataminr's Multi-Modal Fusion AI into Horizon, processing text in 150 languages, along with image, video, audio, and sensor data from ...
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [.
The extension, named "Twitch Enhanced Viewer | JeetBot," was available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store, with approximat...
Homebrew, widely used on macOS, is frequently targeted by threat actors to distribute info-stealer malware.
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. T...
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Securit...
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
Google has begun routing some organic Search result links through opaque google.com/goto?
Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives...
UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detect...