Vulnerabilities can lurk within production code for years or decades — and AI tools have opened a gateway to a glut of new long-hidden discoveries.
A spoofed CCleaner download site is spreading a multi-stage malware that hijacks Chrome to steal credentials, cookies, and authentication tokens while recording keystrokes and screenshots.
Critical infrastructure operators are facing a rapidly evolving threat landscape where cyberattacks can create real-world operational disruption with national and economic consequences. In this ...
AI can make SOC teams faster, but only if it fits existing workflows, connects their tools and earns analysts’ trust.
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
The WinSock fix is one of the 398 patches issued today by Microsoft, and SAP’s fix for a vulnerability in Commerce Cloud is one of 29 patches this month.
Two campaigns created 4M+ fake identities to enumerate Microsoft Entra ID accounts — without logins. Learn how to detect the ...
A single AI-assisted researcher discovered the massive blast-radius vulnerabilities using fewer than 20 prompts on publicly available models in less than 24 hours.
Tests show the upcoming model may be able to find and exploit vulnerabilities or carry out attacks on its own, prompting ...
GPT-5.6-Cyber responded to 95% of advanced cyber requests in an OpenAI refusal-rate test and has been used to uncover previously unknown vulnerabilities in Google’s V8 engine.
A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded ...
Typosquatting on popular AI services Paperclip and Browser Use, the malicious skills cracked skills.sh’s trending list, ...