Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
A high-severity path traversal vulnerability in the open-source developer platform Windmill, tracked as CVE-2026-29059 (CVSS 7.5), is under active exploitation. The flaw…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms,…
Cybersecurity researchers at Sand Security have disclosed a now-patched critical session isolation vulnerability in Writer, an enterprise generative AI platform. The flaw,…
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The…
Microsoft has discovered a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for.…
Reflectiz offers continuous monitoring for 'Ask AI' links carrying memory instructions, providing a free cheat sheet for auditing web exposure and cleaning…
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…