The U.S. Department of State is offering a reward of up to $10 million for information regarding Zhang Yu, a…
GitHub CodeQL is the bundled baseline for GitHub estates, Snyk Code and SonarQube lead the developer-first lane, and Checkmarx/Veracode/Fortify anchor…
Attackers are exploiting CVE-2026-88771, a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy reverse shells,…
Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security…
A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing…
MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages. Linked to an apparent single operator active…
Ernst & Young (EY) has warned that a data breach exposed personal and financial information belonging to clients of Goldman…
Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI…
CyberXero, a Russian-speaking initial access broker combining conventional exploitation tools with AI agents to pursue global website compromises and targeted…
The FBI and U.S. Secret Service issued a joint cybersecurity advisory warning that operators of "FortiBleed" continue to target internet-facing…