18 posts were published in the last hour 13:2 : Mate Security Raises $35 Million for Agentic SOC 13:2 : macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets 13:2 : Houston City College Data…
Mate Security Raises $35 Million for Agentic SOC
The startup will use the investment to expand its customer support, sales, and R&D teams.
macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets
macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS…
Houston City College Data Breach Exposes 832k Unique Student Email Addresses
Houston City College has experienced a serious data breach that exposed sensitive personal information of approximately 832,000 unique students and alums.…
120 fake Walmart stores stealing credit cards
A network of more than 120 fraudulent websites impersonating Walmart is actively stealing credit card information from online shoppers.
Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism, Issues Arrest Warrant
Russia’s Federal Security Service (FSB) has formally charged Telegram founder and CEO Pavel Durov with aiding terrorism and issued a warrant for his…
CISA adds Arista and Fortinet flaws to KEV catalog
The U.S.
Fake Recruiters Target Web3 Developers Through Trusted Bitbucket and npm Workflows
A new wave of job scams is hitting Web3 developers who are simply looking for their next role. Attackers pose as recruiters, start friendly chats about…
ThreatLocker Raises $190 Million in Series F Funding
The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation.
Securing What Matters: Why Cyber Resilience Needs Prioritisation
Recent government data shows the scale of cyber threats facing security teams. According to the Cyber Security Breaches Survey 2025/2026, it’s estimated…
JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI…
Mythos Asks the Right Question. It Doesn’t Answer It.
AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve…
Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
Android malware scanners are increasingly misaligning with real-world risk by over-flagging legitimate, high-permission applications while quietly missing…
Managing cyber-physical risk in smart buildings
Smart buildings promise greater efficiency, improved sustainability and enhanced operational oversight. However, as building management systems, security…
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of…
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.…
Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the…
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the…
WhatsApp Adds End-to-End Encryption for Voice and Video Calls
WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its…
A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online
A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network. The toolkit lets operators create…
NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages
NVIDIA has revealed a significant security vulnerability in its BlueField data processing units (DPUs) that could allow virtual machine (VM) users to…
Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System
Broadcom has released a critical security advisory, VMSA-2026-0006, addressing multiple high-impact vulnerabilities across core VMware virtualization…
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
VulnGym Uses AI-Trained APT Attackers to Stress-Test Enterprise Patching Strategies
A new cybersecurity research tool called VulnGym utilizes reinforcement learning to simulate AI-trained advanced persistent threat (APT) attackers…