Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
AitM phishingArctic Wolf Labsbusiness email compromisecredential theft
A use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, could allow local users to gain root privileges…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack…
Black Hat USA 2026CVE-2026-50522CVE-2026-56181CVE-2026-63913
PortSwigger's AI-assisted research system, HTTP Terminator, has generated and proven new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The system,…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack…
AppleBlack Hat USA 2026CVE-2026-50522CVE-2026-56181
A newly disclosed Linux kernel vulnerability, dubbed Zapscape and tracked as CVE-2026-64561, could allow an attacker with kernel privileges inside an L1…