CVE-2026-35616 Exploited to Deliver EKZ Infostealer
Hackers are exploiting a FortiClient EMS flaw to deliver an undocumented credential stealer called EKZ, disguised as a Fortinet endpoint update.
HalluSquatting is an attack where researchers pre-compute fake repository, package, or skill names that AI coding agents predictably invent, register those names first, and load them with malicious instructions.
Hackers are exploiting a FortiClient EMS flaw to deliver an undocumented credential stealer called EKZ, disguised as a Fortinet endpoint update.
California's attorney general sued 23andMe, alleging it failed to protect user data in a 2023 breach affecting nearly 7 million people.
GreyVibe, a previously undocumented threat actor, uses AI to supercharge its cyberattacks, targeting Ukrainian entities since August 2025.
Google Chrome's DBSC feature is now available to all users, preventing account takeovers by cryptographically binding session cookies to a specific device.
A critical-severity zero-day vulnerability in Gogs exposes servers to remote code execution, allowing attackers to compromise the server and read every repository on the instance.
Microsoft has condemned the uncoordinated release of Windows zero-day vulnerabilities, calling them 'never justifiable' and warning of potential legal action against those who enable cybercrime.
A Department of Commerce inspector general report found that the National Institute of Standards and Technology's National Vulnerability Database is plagued by poor planning, duplication, and inefficiencies, resulting in a growing backlog of unprocessed security flaws.
A data breach at Trump Mobile exposed customer data, while a phishing campaign targeted LinkedIn users and a supply chain attack hit 176 NPM packages.
The DDoS-as-a-service market has become more sophisticated, with prices as low as $5 for an attack, making it easier for low-skill users to launch attacks.