Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
Images of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.
A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.
Companies 'don't want their IP exposed, so they're willing to pay'
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.
The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeCh...
It was discovered that HSQLDB incorrectly handled specially crafted
database files. An attacker could possibly use this issue to overwrite
arbitrary files.
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The num...
Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers.
Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Mage...
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information could be used for scam emails, fraudulent calls or lett...
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.
FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory S...
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the activity under the name PREY-0058 and notes it shares...
Several security issues were fixed in Gzip.
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The d...
A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said.
The cybersecurity firm said in a report that it u...
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.
The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek.
Administrators are advised to check their deployments for newly created user accounts they don’t recognize.
The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.