#News


Rails patches critical Active Storage flaw with RCE potential

Aug 3, 2026 // 04:37

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to […]

Google Chrome may soon block New Tab hijacker extensions by default

Aug 3, 2026 // 04:37

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. […]

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

Aug 3, 2026 // 04:36

Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose […]

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Aug 3, 2026 // 04:35

Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique […]

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Aug 3, 2026 // 04:35

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) […]

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Aug 3, 2026 // 04:34

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the […]

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Aug 3, 2026 // 04:34

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then […]

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Aug 3, 2026 // 04:34

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint […]

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Aug 3, 2026 // 04:34

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary […]

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Aug 3, 2026 // 04:34

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the […]

Previous 1 142 143 144 145 146 353 Next