New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
Two security firms have independently discovered that Atlassian's Rovo AI assistant can be tricked into sending sensitive Jira and Confluence data to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability affecting Progress Kemp LoadMaster to its Known…
N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed…
Metabase has disclosed a maximum-severity zero-day vulnerability in its business intelligence and data visualization software that is being actively exploited in the…
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
Open source software is undergoing a forced maturation, driven by a convergence of threats and regulatory pressures. The article argues that while…