Cisco patches 12 Catalyst SD-WAN and IOS XE flaws, including three 9.9-rated bugs and a 9.8 command injection issue.
INTERRUPT INJECTION lets unprivileged Linux code bypass Spectre v2 defenses and leak AMD Zen 2 kernel memory at 5.47 bytes ...
AI agent flaws in AWS, Google, and Vercel let forged tool calls reach tools without model authorization, while several paths ...
CISA says attackers are exploiting TeamCity CVE-2026-63077, an unauthenticated RCE flaw that can expose credentials and ...
At least 20 Zbtlink router models ship with ENDLESSDOORS, a root backdoor that attempts C2 contact as often as every 35 ...
Maksim Silnikau gets 16 years for running Ransom Cartel, which DOJ says attacked at least 18 companies in the U.S. and abroad ...
Researchers say three WebKit features can bypass Apple's iCloud Private Relay and browser proxies, exposing users' real IP ...
Attackers compile khunt inside Oracle after a web SQL injection, reach Windows SYSTEM, and stage credential data and registry ...
Zapscape could let guest root escape nested KVM and execute code on the Linux host through a shadow-MMU use-after-free; no in-wild exploitation is cla ...
Forescout found 22 exposed Rockwell PLCs in cities hit by water attacks; direct access can let attackers change settings ...
This week’s ThreatsDay Bulletin covers malicious packages, AI agent risks, phishing chains, exposed systems, router flaws, ...
CryptoJS's weak RNG made recovery phrases guessable across five wallet apps, enabling Ill Bloom thefts totaling at least $5.69 million in two sweeps.