New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manag…
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manag…
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, u…
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive infor…
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and o…
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and oth…
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecos…
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten signi…
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wal…
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing …
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails applica…
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in mult…
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of exi…
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platf…
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its mode…
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on expos…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed…
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report …
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran o…