Cybersecurity Threats and Vulnerabilities
Threat actors are exploiting AI chatbot queries to harvest computing power, while an unpatched Comodo flaw allows remote attackers to crash targeted Windows endpoints.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Threat actors are exploiting AI chatbot queries to harvest computing power, while an unpatched Comodo flaw allows remote attackers to crash targeted Windows endpoints.
Hackers are actively exploiting a critical vulnerability in the Everest Forms Pro plugin to take complete control of WordPress sites, creating rogue administrator accounts.
Apple has removed Russia's state-backed messaging app Max from its App Store, citing compliance with sanctions regulations, affecting around 20 million Russian users.
The European Commission proposes laws and strategies to reduce reliance on foreign technology, focusing on semiconductors, cloud computing, and open-source software.
Hackers are actively exploiting a high-severity SolarWinds Serv-U flaw, tracked as CVE-2026-28318, to crash servers, with over 12,000 Serv-U servers exposed online.
Toshiba and Muji warned visitors of suspicious sign-in screens on their websites, potentially collecting credentials, after an issue with the external service hosted at polyfill[.]io.
CVE Lite CLI is a free, open-source command line tool that scans projects in seconds to find and fix vulnerable dependencies in JavaScript and Typescript files.
Anthropic's Project Glasswing program has expanded to 150 organizations in 15 countries, discovering over 10,000 high-severity software vulnerabilities since its launch in April.
Department of Homeland Security Secretary Markwayne Mullin says CISA ideally needs 2,800 personnel to effectively carry out its cybersecurity mission.