A Coldcard firmware flaw weakens wallet seed generation across five models, while Galaxy links a 1,196-address, $70.2 million sweep to the bug.
Adobe patches CVE-2026-48449, a CVSS 10.0 Campaign Classic flaw that could allow code execution without user interaction, ...
Attackers altered Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron wallet addresses across customer sites.
Microsoft links hijacked hotel Wi-Fi to fake updates that deliver CornFlake, steal cloud tokens, and abuse device codes to target travelers.
Azure Cosmos DB's Gremlin flaw let Wiz escape the sandbox and retrieve an account key. Microsoft found no unauthorized ...
HollowFrame and Matryoshka use DLL side-loading and GitHub C2 to gain a persistent foothold on two law firm endpoints.
State-sponsored hackers used compromised South Korean websites to exploit AnySign4PC and install SIGNBT or COPPERHEDGE ...
DPRK-linked macOS malvertising uses fake updates and ClickFix to install a backdoor that fetches a stealer targeting 157 ...
Microsoft 365 Copilot prompt injection can alter report figures and copy hidden instructions into generated files, letting ...
Silver Fox uses a three-driver BYOVD framework, DLL sideloading, and dual watchdogs to keep ValleyRAT running at a Japanese ...
Check Point launches an AI Network Firewall to inspect prompts, model calls, APIs, and agent activity across enterprise ...
Cisco FMC flaw CVE-2026-20316 is under active exploitation, letting unauthenticated attackers use static credentials to ...