Forescout has identified over 4,400 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide, including 22 in cities affected by recent cyberattacks on…
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
Blockchain security firm Coinspect has identified a critical vulnerability in the popular JavaScript cryptography library CryptoJS, specifically in the CryptoJS.lib.WordArray.random() function, which…
Security researchers have uncovered a class of vulnerabilities in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel that allow attackers…
Agent InfrastructureAI SecurityAmazon Bedrock AgentCoreAmazon Web Services
Attackers breached an organization's Oracle database via a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit named…
Cybersecurity researchers have disclosed details of a factory-shipped backdoor implanted in at least 20 Chinese router models from Zbtlink. According to a…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly patched critical vulnerability in JetBrains TeamCity to its Known Exploited…
active exploitationCI/CD SecurityCISACVE-2026-50522
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and…