Latest news

  1. Threat Intel via SecurityWeek

    NightmareStresser DDoS Service Disrupted in International Operation

    Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.

  2. Threat Intel via Security Affairs

    RatHat Turns Android Accessibility Into an Attack Weapon

    RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new…

  3. Breaches via HIPAA Journal

    Settlement Resolves Class Action Data Breach Complaint Against Community Dental Care

    Community Dental Care, a nonprofit Medicaid dental provider in the state of Minnesota, has agreed to settle class action litigation over a 2024 cyberattack and data…

  4. AI Security via Palo Alto Networks Unit 42

    A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

    Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents.

  5. Vulnerabilities via Infosecurity Magazine

    CISA Upgrades Vulnerability Reporting Platform with More Automation

    The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT

  6. Threat Intel via SecurityWeek

    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

  7. Vulnerabilities via BleepingComputer

    New Check Point flaw lets hackers execute code with root privileges

    Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.

  8. AI Security via The Hacker News

    Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

    A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm…

  9. Threat Intel via ESET WeLiveSecurity

    ‘Nudify’ apps: What to do if someone makes a fake nude of you

    Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images

  10. AI Security via Help Net Security

    Arcjet brings security controls and audit trails to AI agents

    Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance…

  11. Vulnerabilities via Ubuntu Security

    USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities

    It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated…

  12. Vulnerabilities via Help Net Security

    Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

    Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same…

  13. Vulnerabilities via Ubuntu Security

    USN-8730-3: Linux kernel (Azure) vulnerability

    A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following…

  14. Vulnerabilities via Ubuntu Security

    USN-8761-2: Linux kernel (Azure FIPS) vulnerabilities

    Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system.

  15. Vulnerabilities via Ubuntu Security

    USN-8729-2: Linux kernel (Raspberry Pi Real-time) vulnerabilities

    Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system.

  16. Vulnerabilities via Ubuntu Security

    USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilities

    It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated…

  17. Vulnerabilities via SecurityWeek

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

  18. Vulnerabilities via Ubuntu Security

    USN-8725-2: Linux kernel (AWS) vulnerabilities

    Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system.

  19. Vulnerabilities via Ubuntu Security

    USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities

    Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks…

  20. Vulnerabilities via Help Net Security

    Android apps can now check security patches down to individual device components

    New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security…