New Ghost Phishing Wave Using EvilTokens Bypasses Traditional Email Security
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
Researchers Abhishek Kumar and Carsten Maple have discovered a novel workflow-level jailbreak method that bypasses safety guardrails in GitHub Copilot. The study,…
Account takeover (ATO) attacks are shifting from credential stuffing to targeting identity verification and recovery layers as passkeys become mainstream. According to…
New research from Carnegie Mellon University PhD student Jacob Ginesin, also a cryptographic auditor at Cure53, reveals that GitHub's 'Verified' commit badge…
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows any logged-in user to gain full root…
A critical vulnerability in Google's Dialogflow CX, dubbed 'Rogue Agent' by security firm Varonis, could have allowed an attacker with edit permissions…
A new Android malware operation called RedWing is being offered as a ready-made bank-fraud service on Telegram, allowing low-skill criminals to take…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…