-
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure, according to watchTowr. This flaw affects MLflow versions before 3.15.0 and ca…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has issued a warning that organizations need to quickly automate core cybersecurity functions as increasingly advanced AI systems make it easier and cheaper to identify, exploit, and chain security vulnerabilities. In a recent security article t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
France’s Directorate General of Public Finances (DGFiP) has reported a cyberattack that resulted in unauthorized access to and extraction of tax and cadastral data for approximately 678,000 individuals and professional entities. According to a press re…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued on August 17, 2026, include iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and security fixes for …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs, raising fresh supply-chain security concerns around vendor-hosted driver downloads. The company said the…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems during controlled cybersecurity testing. This issue, which has since been resolved, stemmed from a sing…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a wide…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


