N-able addresses critical N-central vulnerabilities exploited by attackers
Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrati...
20 articles
Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrati...
This new protection, currently in development and planned to be enabled by default, aims to combat malware abuse of Chrome's enterprise policy features on un...
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [.
The Baochip-1x is a "mostly" open-source microcontroller that allows for verifiable security.
The vulnerability specifically affects Active Storage versions prior to 7.2.
INC ransomware exploits SonicWall zero-days, prompting compromise fears.
The vulnerability, identified by Block and detailed by Galaxy Research, occurred because a deterministic software pseudorandom number generator (PRNG) was us...
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote acces...
Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds.
A cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a “...
The critical vulnerability in Adobe Campaign Classic, identified as CVE-2026-48449, stems from incorrect authorization and poses a significant risk for remot...
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on...
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-centr...
These seemingly harmless blank pages or "Coming Soon" placeholders can silently collect a visitor's IP address, approximate location, User-Agent string, and ...
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all...
The phishing attacks involve disguised job applicants sending resumes with malicious links or impersonating recruiters with password-protected ZIP files cont...
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (S...
The attack exploited Adform's JavaScript tracking script, "trackpoint-async.js," which is embedded in numerous websites.
Agents need their own identities, scoped to a specific task, and then must be destroyed.
The surge in malicious activity began around July 29, with initial reports identifying the "openconnect-sso" package as compromised.