The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions.
Tag: EN
GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are…
Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted…
Scammers Are Watching Airline Complaints and Posing as Customer Support
Check Point uncovers thousands of fake support accounts, with hundreds more appearing every day A delayed flight. Missing luggage. A refund that never…
Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch.
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from…
Scattered Spider Social Engineering Attacks on UK Retailers
A wave of cyberattacks against major UK retailers in April 2025 has highlighted the continuing effectiveness of social engineering tactics employed by the…
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
Top 30 Cybersecurity Interview Questions And Answers For 2026
By HOC Team | Updated: September 2026 Read time: ~24 min Cybersecurity hiring in 2026 is both…
VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a…
Microsoft warns of cloud storage and financial fraud campaign
Microsoft has warned customers about two sophisticated social engineering campaigns targeting corporate accounts and financial systems.
PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
A phishing campaign using a fake tax-audit notice is deploying VenomRAT through a signed copy of Notepad++. The operation, tracked as PAPERMILL, uses an…
Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
A supply chain attack targeting the Admin Menu Editor Pro WordPress plugin has compromised more than 1,500 WordPress websites after threat actors breached…
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate…
SE Labs Launches PIVOT Testing Program
SE Labs, a UK-based security testing provider, unveiled PIVOT on September 15, a new six-month testing program designed to evaluate cybersecurity vendor…
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root…
Robinhood engineers charged in $50K crypto fraud
Two engineers at Robinhood Markets face federal criminal charges for allegedly using insider information about upcoming cryptocurrency listings to profit…
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass…
Dataminr, Crisis24 integrate AI threat detection
Dataminr has embedded its Multi-Modal Fusion AI technology into Crisis24’s Horizon platform, creating an enhanced threat detection system for enterprise…
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
