Security researcher uncovers the SLEEPWALKER Windows backdoor featuring a custom bytecode language, passive network activation, DLL side loading, and stealth capabilities.
CISA adds the critical Gitea remote code execution vulnerability CVE 2026 60004 to its Known Exploited Vulnerabilities catalog following reports of active exploitation.
OX Security has uncovered a campaign abusing 24 npm packages and unpkg mirrors to host fake Cloudflare CAPTCHA pages that can redirect users to phishing infrastructure.
Researchers have uncovered a malware campaign using FTP banners as dead drop resolvers to deliver E4del and PINHOLE RATs, introducing a new technique for command and control operations.
GitLab CVE-2026-19478 is being actively exploited after disclosure, allowing unauthenticated attackers to modify or delete public projects under certain conditions.
Cisco has released security updates addressing nine vulnerabilities in Crosswork platforms and Secure Workload Software, including five critical flaws with CVSS 10.0 ratings.
Check Point Research has disclosed a technique that uses Microsoft Defender BTR.sys driver to perform kernel level operations without exploiting a software vulnerability.
Security researchers at Cycode have identified critical flaws in NASA AIT-GUI software that allow attackers to issue unauthenticated spacecraft commands.
Check Point Research uncovers StopAndProtect operation using nearly 2,000 hacked WordPress websites for malware distribution, surveillance, and data theft.
CISA has added a critical Ray vulnerability to its KEV catalog after active exploitation reports. The flaw could allow remote code execution through browser based DNS rebinding attacks.