Tata Nexarc has fixed a critical authentication flaw that exposed login one-time passwords (OTPs) in client-visible API ...
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could let attackers hijack AI agents after a victim ...
Organisations using popular open-source AI tool urged to prioritise patching and investigate potential credential theft.
NemoClaw vulnerability CVE-2026-65105 lets a single malicious webpage permanently rewrite a local AI agent's chat template ...
Cloudflare Workers can now accept inbound TCP connections through a new connect(socket) handler routed via Spectrum, ending ...
Kaspersky researchers found 92,000 malicious attacks disguised as AI services in 2026, with fake ChatGPT, Claude and Gemini ...
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing ...
Fake Adobe Acrobat sites are hiding malware-as-a-service panels, using document lures to target Windows users with harmful ...
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
There is no new OWASP list in 2026: the Top 10:2025 is the current standard. All 10 risks explained, what changed since 2021, ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive ...