#News


Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Aug 18, 2026 // 23:28

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) […]

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Aug 18, 2026 // 23:28

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently […]

Your Controls Block Known Attacks. What About the Behavior?

Aug 18, 2026 // 17:17

By Sila Ozeren Hacioglu, Security Research Engineer at Picus Security. A prevention score tells you what a control recognizes. It doesn’t tell you what that […]

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Aug 18, 2026 // 15:41

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. “TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its […]

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Aug 18, 2026 // 14:52

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, […]

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

Aug 18, 2026 // 14:36

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according […]

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

Aug 18, 2026 // 13:52

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence […]

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

Aug 18, 2026 // 13:52

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately […]

Microsoft starts removing WMIC tool used by cybercriminals

Aug 18, 2026 // 13:46

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta […]

CISA: Windows Task Host flaw now exploited by ransomware gangs

Aug 18, 2026 // 13:46

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged […]

Previous 1 38 39 40 41 42 353 Next