LabubaRAT poses as NVIDIA software, profiles security tools, and uses HTTPS, WebView2, or DNS tunneling to maintain remote ...
Two RabbitMQ flaws can expose OAuth secrets or queue metadata, with one potentially enabling full broker takeover in affected ...
Claude for Chrome v1.0.80 still accepts forged clicks from other extensions, triggering Gmail, Docs, and Calendar tasks ...
SAP patches three critical flaws, including a 9.9 NetWeaver ABAP memory bug and default OAuth credentials that may expose ...
OAuth client ID spoofing lets attackers test Entra accounts and stolen passwords without successful sign-ins, leaving ...
Researchers found built-in privacy leaks in 85 browser wallets that can link addresses, survive logout, and expose users ...
Pentera’s MCP Server gives AI assistants access to validated attack paths, helping teams prioritize exploitable risks and ...
JFrog finds 148 npm proxy packages turned student browsers into a DDoS botnet, while a mutable loader lets operators re-arm ...
Microsoft fixes a record 622 CVEs, including two exploited SharePoint and AD FS zero-days, while a Kerberos RC4 change could ...
Microsoft maps three Salesforce intrusion paths that abuse OAuth apps, vendor tokens, and guest access while ordinary sign-in ...
From a rushed ShareFile shutdown to poisoned npm packages and AI assistants tricked into installing malware, here's every ...
Meta filed a patent for an AI that reads your mood from your voice, eyes, and phone and keeps a timestamped log of it.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results