Critical Gitea RCE CVE-2026-60004 Actively Exploited in Cryptojacking Campaign
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, by correlating endpoint and network…
Cybersecurity researchers have uncovered a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that hijacks Chromium web browsers to steal session data and…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
A newly disclosed Linux kernel vulnerability, dubbed Zapscape and tracked as CVE-2026-64561, could allow an attacker with kernel privileges inside an L1…
Blockchain security firm Coinspect has identified a critical vulnerability in the popular JavaScript cryptography library CryptoJS, specifically in the CryptoJS.lib.WordArray.random() function, which…
Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after researchers at Pillar Security demonstrated that…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
Ruby on Rails has released fixes for a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), that could allow unauthenticated attackers to read…