BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
A DeepSeek Harness flaw let attacker-supplied text push AI agents to disable the file sandbox; fixed npm releases start at ...
Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.
A Microsoft Defender patch bypass PoC demonstrates arbitrary file read as SYSTEM on the latest Windows version.
CISA added actively exploited N-able N-central CVE-2026-86218 to KEV, with federal agencies ordered to patch by September 11.
F5 BIG-IP malware injects a PHP web shell into memory, leaving targeted scripts unchanged on disk while commands run through ...
Alby warns a critical Hub flaw could let attackers take over internet-exposed wallets; versions 1.19.0 and later are not affected.
Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an ...
Infostealer logs expose replayable AI session tokens and API keys that can bypass login controls and enable unauthorized account access.