-
WhatsApp has initiated a limited beta rollout of a feature called Scam Alert, which utilises an on-device machine learning model to identify potentially scam messages from non-contacts while maintaining end-to-end encryption. Meta has provided a detail…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Adobe has released critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing 17 vulnerabilities that could enable arbitrary code execution, privilege escalation, bypass of security features, denial-of-service attacks, and memory exp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launch up to 100 encryption threads, a design that compresses the time defenders have to detect and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Kimwolf v7 build shows the Android and IoT botnet shifting from an all-in-one compromise toolkit into a more specialized DDoS and proxy-relay payload. The latest variant removes embedded scanning, exploitation and brute-force logic, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A China-linked threat actor has reportedly utilized a multi-agent artificial intelligence framework to conduct a nearly autonomous intrusion campaign targeting government entities in Taiwan and across Asia. This operation demonstrates how agentic AI ca…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Phantom Stealer is a .NET-based credential-harvesting malware that combines PNG-backed payload concealment, PowerShell-driven process injection, and telemetry suppression to steal passwords, browser data, cryptocurrency wallets, and sensitive local fil…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated threat campaign, referred to as “City-Forum,” is targeting publicly accessible Salesforce Experience Cloud sites and ServiceNow Service Portals, aiming to enumerate and extract data exposed to anonymous users. Security firm Reco, which …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Palo Alto Networks has released security advisories for multiple vulnerabilities in the GlobalProtect App that could allow a local attacker to elevate their privileges to SYSTEM on Windows or to root on Linux and macOS systems. These advisories were pu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has released version 7.0.4 to address a high-impact authenticated remote code execution (RCE) vulnerability. This flaw could allow users with Author-level privileges or higher to execute code on affected websites. The vulnerability, tracked a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


