A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
Hackers are exploiting CVE-2026-60004, a critical remote code execution vulnerability affecting the Gitea development ...
MuddyWater-linked threat actors are using a backdoor named Dindoor that abuses the legitimate Deno runtime to execute ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
When OpenAI’s agents went rogue in July, they demonstrated ingenuity and drive beyond what many experts imagined — a ...
A critical vulnerability in the Node.js sandboxing library, isolated-vm, has exposed a serious risk to AI agents, automation ...
A critical isolated-vm flaw lets untrusted JavaScript escape the V8 sandbox and potentially hijack the host process.
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat ...
Microsoft disclosed a critical remote code execution vulnerability affecting its Entra ID cloud identity service.
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX ...