Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones' ...
Sentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access ...
Brevo confirms a stolen Cloudflare API key was used to inject ClickFix malware into customer website scripts in a major ...
CrowdStrike links PhantomRaven malware to a bug bounty hunter, finding LLM-generated code, malicious npm packages and ...
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT; Tencent fixed the issue in version 16.3.0.3498 ...
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...
Over 5,400 legitimate websites now serve fake CAPTCHA scams that trick users into pasting malware commands into Windows Run ...
Anthropic says it has blocked efforts to use its artificial intelligence models to carry out cyber attacks and research which ...
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge ...