Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed security flaw, CVE-2026-20316, impacting Cisco Secure Firewall Management Center…
Ruby on Rails has released fixes for a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), that could allow unauthenticated attackers to read…
Broadcom has released security updates addressing multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion, including three critical-severity flaws. The most severe…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies to siphon funds…
A coordinated cyberattack targeting operational technology (OT) at over 30 community water systems in Minnesota occurred on July 26-27, 2026, prompting a…
Nebula Security researchers have demonstrated that a single visit to a malicious webpage can compromise the Tor Browser by exploiting a patched…
The article discusses how AI models like Anthropic's Mythos are compressing exploit timelines, forcing a reevaluation of vulnerability management strategies. It argues…
The Federal Security Service of the Russian Federation (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and failing to…