#News


Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

Aug 5, 2026 // 14:08

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, […]

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Aug 5, 2026 // 13:38

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive […]

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Aug 5, 2026 // 12:54

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and […]

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

Aug 5, 2026 // 12:48

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and […]

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Aug 5, 2026 // 12:28

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and […]

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

Aug 5, 2026 // 10:59

An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber […]

OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

Aug 5, 2026 // 03:36

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website […]

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Aug 5, 2026 // 01:37

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to […]

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Aug 5, 2026 // 01:36

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to […]

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Aug 5, 2026 // 00:56

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. The platform has been active […]

Previous 1 59 60 61 62 63 353 Next