Chrome Device Bound Session Credentials
Google Chrome's DBSC feature is now available to all users, preventing account takeovers by cryptographically binding session cookies to a specific device.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Google Chrome's DBSC feature is now available to all users, preventing account takeovers by cryptographically binding session cookies to a specific device.
A critical-severity zero-day vulnerability in Gogs exposes servers to remote code execution, allowing attackers to compromise the server and read every repository on the instance.
Microsoft has condemned the uncoordinated release of Windows zero-day vulnerabilities, calling them 'never justifiable' and warning of potential legal action against those who enable cybercrime.
A Department of Commerce inspector general report found that the National Institute of Standards and Technology's National Vulnerability Database is plagued by poor planning, duplication, and inefficiencies, resulting in a growing backlog of unprocessed security flaws.
A data breach at Trump Mobile exposed customer data, while a phishing campaign targeted LinkedIn users and a supply chain attack hit 176 NPM packages.
The DDoS-as-a-service market has become more sophisticated, with prices as low as $5 for an attack, making it easier for low-skill users to launch attacks.
Anthropic confirms plans to release Mythos-class models to the public in the coming weeks, after addressing initial security risks.
A Google security engineer has been accused of using confidential search trends to make over $1.2 million on the prediction marketplace Polymarket.
CrowdStrike has dismantled the Glassworm botnet, which infected hundreds of open-source software with malware, in a coordinated effort with Google and Shadowserver.