A phishing page designed to evade security tools accidentally broke its own credential-stealing operation after a coding ...
Two critical Next.js flaws enable unauthenticated remote code execution on Windows-hosted apps using the Image Optimization ...
A critical vulnerability in the Node.js sandboxing library, isolated-vm, has exposed a serious risk to AI agents, automation ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type ...
The new attack bypasses ECC protection on systems running Nvidia GPUs and can produce double- and triple-bit errors, ...
A critical isolated-vm flaw lets untrusted JavaScript escape the V8 sandbox and potentially hijack the host process.
Cloudflare Workers Spectre attack research published August 19, 2026 showed JWT token theft at 12 bits per second in live ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing ...
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have ...
The popular key-value database keyv and other widely used npm packages were targeted in a supply chain attack. The potential damage is significant.