New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
Latest cybersecurity news, breaches, vulnerability disclosures and industry developments.
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
Two security firms have independently discovered that Atlassian's Rovo AI assistant can be tricked into sending sensitive Jira and Confluence data to…
Open source software is undergoing a forced maturation, driven by a convergence of threats and regulatory pressures. The article argues that while…
Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack…
Forescout has identified over 4,400 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide, including 22 in cities affected by recent cyberattacks on…
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
Attackers breached an organization's Oracle database via a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit named…
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau, a 40-year-old Belarusian national, to 16 years in prison on August 5, 2026,…