CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Ravie LakshmananAug 05, 2026Vulnerability / Patch Management The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added...
Category Added in a WPeMatico Campaign
Ravie LakshmananAug 05, 2026Vulnerability / Patch Management The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added...
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code...
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages...
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom...
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break....
Swati KhandelwalAug 04, 2026AI Security / DevSecOps Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python...
Swati KhandelwalAug 04, 2026Vulnerability / Database Security cPanel has patched a flaw that let an authenticated hosting customer execute SQL...
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images...
Ravie LakshmananAug 04, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity...
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a...
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint,...
Ravie LakshmananAug 03, 2026Vulnerability / Cybercrime The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently...
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an...
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude,...
Ravie LakshmananAug 03, 2026Mobile Security / Vulnerability An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS...