ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
ASOS has started notifying affected customers in the U.S.
20 articles
ASOS has started notifying affected customers in the U.S.
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to exec...
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain...
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns.
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations t...
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to ...
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in t...
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manuall...
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Vi...
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These vulnerabilitie...
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo but ...
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despit...
The U.S.
Microsoft is introducing a new Microsoft Teams meeting policy that automatically blocks identified external bots. This aims to address growing concerns regar...
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint agen...
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security s...
North Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giv...
ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and succe...
A newly discovered AI system called Ox Alpha has emerged on OpenRouter, sparking widespread speculation within the AI community regarding its origin, technic...
Threat actors are actively exploiting a critical operating system command injection vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570...