17 old software bugs that took way too long to squash
In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code.
20 articles
In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code.
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, th...
The unauthorized network, named "Delta WiFi Fast," was reportedly created by passengers attending the DEF CON hacker conference.
The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent repor...
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the sys...
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As att...
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakn...
Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185...
42Critical 355Important 1Moderate 0Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploit...
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity i...
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened.
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and...
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researcher...
Security researchers have disclosed “GhostJacking,” a new class of attacks that exploits trusted observability and security platforms to manipulate AI agents...
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
Anthropic has launched a machine-readable content-marking initiative for materials generated by its Claude models. This initiative combines invisible text wa...
Abyssos, a modular C++ remote-access trojan that combines credential theft, browser-session hijacking, file exfiltration and hidden VNC control in a single p...
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...
Companies are sending sensitive data, including injury reports, pizza orders, and test credentials, to domains like @noreply.us and @noreply.