Unpatched XRING Flaw in Alibaba’s XQUIC Lets Remote Clients Crash HTTP/3 Servers
A critical unpatched vulnerability, dubbed XRING, has been disclosed in XQUIC, Alibaba's open-source QUIC and HTTP/3 library. Discovered by FoxIO researcher Sébastien…
A critical unpatched vulnerability, dubbed XRING, has been disclosed in XQUIC, Alibaba's open-source QUIC and HTTP/3 library. Discovered by FoxIO researcher Sébastien…
A sophisticated threat actor tracked as O-UNC-066 by Okta is targeting organizations across multiple sectors with a voice-based phishing (vishing) scheme that…
A comprehensive study of 281 popular free Android VPN apps from the Google Play Store, conducted by researchers at the University of…
A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.…
A 41-year-old former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for conspiring with the now-defunct BlackCat ransomware…
Security firm Coinspect has disclosed a crypto wallet flaw called 'Ill Bloom' that is being actively exploited by attackers. The vulnerability stems…
Microsoft has dismantled a destructive Windows backdoor named GigaWiper, which combines three older malicious tools into a single platform. The malware, written…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
GitHub has officially released npm version 12, introducing significant security changes to reduce software supply chain risks. The most notable change is…
AI-powered attacks now move at machine speed, compressing days of work into minutes. Attackers using models like Mythos can craft tailored bait,…