Adversa says encrypted prompt injection can make Grok send a user's name, location, tier, and chat prompts to an ...
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing ...
Zombie Card rewrites Visa NFC expiry data in transit, reviving expired cards at one tested U.S. bank without breaking card ...
A Meta AI agent exposed sensitive company and user data to unauthorized employees for over two hours, triggering a Sev 1 ...
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks ...
Manic Android malware targets 169 apps and can relay collected data through nearby infected devices when the source phone is ...
Firefox extensions pose as Web3 products to steal recovery phrases, private keys, keyrings, credentials, and clipboard data.
ToxicPanda 2.0 adds 167 remote commands, targets 349 financial institutions, and uses Android accessibility to harvest PINs.
OpenAI pauses frontier RL training for two weeks, keeps its largest planned run on hold, and adds stricter monitoring and ...
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are ...
Citrix fixes NetScaler CVE-2026-19490, a CVSS 9.3 authentication bypass affecting certain Gateway, AAA, and SAML ...