Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

2 hours ago
Mayura Kathir

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The…

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

3 hours ago

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These…

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

3 hours ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities…

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

3 hours ago

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through…

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

4 hours ago

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools…

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

4 hours ago

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and…

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

5 hours ago

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and…

Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection

5 hours ago

Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities…

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

6 hours ago

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root…

CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages

7 hours ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance urging service providers to deliver timely, accurate, and…