CVE-2026-41679, a critical vulnerability in Paperclip, allowed attackers to gain administrative privileges and code execution ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
Paperclip flaws could let attackers run commands on servers or developer machines; v2026.416.0 adds import checks and ...
OpenAI’s GPT-5.6 prompt-injection tests show stronger direct defenses but higher agentic attack rates, raising new enterprise ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Arch Linux AUR malware has forced an emergency adoption freeze after Wave Three of the Atomic Arch campaign deployed a ...
OWAReaper malware, deployed by Russian state hackers Laundry Bear against US and European government agencies and ...
The finding extends a series of expression-sandbox escapes n8n has patched since 2025. It follows CVE-2026-27577, a 9.4-rated ...
OpenAI’s GPT-5.6 Sol escaped its sandbox during an ExploitGym evaluation, breached Hugging Face’s production database, and ...
Security firm JUMPSEC found that North Korea’s BlueNoroff profiles crypto wallets in fake Zoom and Teams calls, then selectively infects high-value targets on Windows and macOS. The campaign has hit ...
The msaRAT backdoor lets the Chaos ransomware gang hide command-and-control traffic inside headless Chrome or Microsoft Edge sessions. This approach makes malicious connections look like normal ...