Over 50,000 Stripe API keys exposed, highlighting fraud risks
Over 50,000 Stripe API keys have been exposed across public code repositories, GitHub Actions logs, and misconfigured web servers, demonstrating the immediat...
Over 50,000 Stripe API keys have been exposed across public code repositories, GitHub Actions logs, and misconfigured web servers, demonstrating the immediat...
Socket researchers identified 40 malicious extensions and 37 others disguised as unrelated utilities, all linked through shared code, infrastructure, and pub...
Discovered by Zimperium's zLabs team, ToxicPanda 2.0 leverages the Android Accessibility Service to enable wireless debugging, effectively gaining shell acce...
A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If explo...
The database, belonging to U.S.
Sakura Internet, a key provider of digital infrastructure services in Japan and a domestic partner for the Government Cloud program, discovered the breach on...
The campaign, originating from an IPv6 range provided by LSHIY LLC, leveraged reused credentials and the legacy Resource Owner Password Credentials (ROPC) OA...
The AI SAST agent identifies vulnerabilities, including logic flaws missed by traditional tools, and reduces false positives.
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network pattern...
The hacking group, identified as Salt Typhoon, compromised hundreds of companies, including major players like AT&T, Verizon, Viasat, Charter, and Windst...
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC pa...
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Expl...
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purch...
Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabi...
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and a...
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities.
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorize...
Corero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI analysis, ...
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Mult...
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.