Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI ...
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection ...
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated ...
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it ...
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository.
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known ...
Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five ...
Cisco Talos has detailed msaRAT, a Rust-based RAT used by the Chaos ransomware crew that drives a headless Chrome or Edge ...
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack … ...
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the ...