U.S. CISA adds a Langflow flaw to its Known Exploited Vulnerabilities catalog

3 months ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Langflow to its Known Exploited Vulnerabilities catalog. The…

Coruna exploit reveals evolution of Triangulation iOS exploitation framework

3 months ago

Kaspersky found Coruna iOS exploits reuse updated code from the 2023 Operation Triangulation attacks, suggesting a possible link. Kaspersky researchers…

Researchers uncover WebRTC skimmer bypassing traditional defenses

3 months ago

Researchers found a new skimmer using WebRTC to steal and send payment data, bypassing traditional security controls. Sansec researchers discovered a…

Russian authorities arrest alleged LeakBase admin behind stolen data marketplace

3 months ago

Russian authorities arrested the alleged LeakBase admin for running a marketplace selling stolen data since 2021. Russian law enforcement has…

Russian national convicted for running botnet used in attacks on U.S. firms

3 months ago

A Russian hacker got 2 years in prison, $100K fine, and $1.6M judgment for running a botnet used in ransomware…

Patch now: TP-Link Archer NX routers vulnerable to firmware takeover

3 months ago

TP-Link patched a high severity flaw (CVE-2025-15517) in Archer NX routers that could let attackers bypass authentication and install malicious…

Recent Navia data breach impacts HackerOne employee data

3 months ago

A Navia breach exposed personal data of nearly 300 HackerOne employees after attackers compromised the benefits provider. HackerOne revealed that…

FCC targets foreign router imports amid rising cybersecurity concerns

3 months ago

The FCC will ban new foreign-made routers in the U.S. over security risks, unless approved by DHS or defense authorities.…

Cybercrime group Lapsus$ claims the hack of pharma giant AstraZeneca

3 months ago

Cybercrime group Lapsus$ claims it hacked AstraZeneca, stealing 3GB of data including credentials, code, and employee information. The Lapsus$ group…

Malicious LiteLLM versions linked to TeamPCP supply chain attack

3 months ago

TeamPCP backdoored LiteLLM v1.82.7–1.82.8, likely via Trivy CI/CD, adding tools to steal credentials, move in Kubernetes, and keep persistent access.…

This website uses cookies.