Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX ...
ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal ...
A critical flaw (CVSS 9.4) in NASA/JPL's AIT-GUI let anyone send unauthenticated commands to spacecraft instruments.
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public ...
Researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa's ...
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog.
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be ...
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite ...
NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure ...
Google tracks 3 Russian-linked espionage clusters using legitimate authentication tools to target researchers, diplomats and ...
StopAndProtect turned nearly 2K hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance ...
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog.