Breaches, vulnerabilities, and the defenses that matter.
+follow topic ← all stories
Security US military-targeted apps contain Chinese and Russian code More than one-eighth of apps targeting US troops include third-party code from adversarial nations, creating potential supply chain vulnerabilities in military mobile infrastructure.
Security Linux kernel publishes over 400 CVEs in 24 hours A sudden surge in Linux kernel vulnerability disclosures highlights shifting security practices or accumulated technical debt in foundational infrastructure.
Security Suno AI music platform breach exposes 55 million user accounts A major breach of an AI-driven consumer platform demonstrates that AI companies handling user data face the same security challenges as traditional services.
Security Palo Alto GlobalProtect VPN vulnerability exploited in Qilin ransomware attacks A critical authentication bypass flaw in widely deployed enterprise VPN infrastructure is now being weaponized by a known ransomware operation.
Security Windows LegacyHive zero-day receives unofficial patches from third-party security researchers Windows systems remain vulnerable to privilege escalation attacks until Microsoft ships official patches, leaving admins to evaluate third-party remediation.
Security WordPress critical vulnerability under active exploitation with public proof-of-concepts A critical flaw affecting the world's most popular content management system is being actively exploited with dozens of public attack tools available.
Security Estée Lauder data breach traced to Oracle E-Business Suite vulnerability A flaw in widely deployed enterprise resource planning software exposed HR data at a Fortune 500 company, highlighting third-party platform risk.
Security SonicWall SMA1000 zero-day vulnerabilities exploited for weeks before disclosure Two unpatched flaws in widely deployed enterprise VPN appliances allowed attackers to install custom malware before vendors became aware.
Security JadePuffer autonomous AI agent deploys ransomware targeting AI training data and model checkpoints Attackers now use autonomous AI agents to encrypt AI infrastructure assets including training datasets and vector databases, escalating threats to organizations deploying machine learning.
Security Cursor, Codex, Gemini CLI, and Antigravity AI coding tools vulnerable to sandbox escape attacks Popular AI coding assistants allow attackers to escape security sandboxes by writing files that host tools later execute, potentially compromising developer workstations.
Security HollowGraph malware uses Microsoft 365 calendars as command-and-control channel Attackers now exploit legitimate calendar features in compromised Microsoft 365 accounts to hide malicious communications within everyday business activity.
Security Microsoft 365 calendars exploited as command-and-control infrastructure in espionage campaign Attackers are weaponizing trusted Microsoft cloud services to evade detection, hiding espionage commands in calendar appointments scheduled decades into the future.
Security OpenCode raises security concerns about VSCode extension execution Developer tools that execute code from remote repositories without clear isolation boundaries introduce supply chain risks to local development environments.
Security Romania's entire land registry database wiped by hacker A successful attack on a national land registry threatens property rights and legal certainty for an entire country's real estate system.
Security Paidwork user database with 23 million records leaked online A database containing bank account numbers, payout histories, and personal details for 23 million users of a gig economy platform is now publicly accessible.
Security Hugging Face breached via autonomous AI agent system An autonomous AI agent breached a major AI repository, exposing internal datasets and credentials — a new attack vector combining AI capabilities with traditional intrusion methods.
Security WordPress remote code execution vulnerability discovered using AI-assisted research A security researcher used AI tools to discover a WordPress vulnerability valued at $500,000 by exploit brokers, demonstrating AI's growing role in vulnerability research.
Security ServiceNow AI Platform critical vulnerability now under active exploitation A critical code execution flaw in ServiceNow's enterprise AI platform is being actively exploited, threatening organizations using the widely deployed IT service management system.
Security ViPNet Update Mechanism Exploited to Target Russian Government Agencies Supply chain attacks targeting secure networking software demonstrate how trusted update mechanisms become high-value vectors for government espionage.
Security XZ Backdoor Documented in New Book 'Half a Second' The 2024 XZ Utils supply chain attack—one of the closest calls in open-source security—now has a comprehensive written account examining how it was discovered and stopped.