Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject ...
Chrome zero-day CVE-2026-87491 is under active attack. See what the V8 flaw can do, why the sandbox matters, and which Chrome ...
Cisco Talos has uncovered a cryptocurrency theft campaign that abuses Google Sheets and the Google Visualization API as a ...
Engineer Tetsuya Wakita built vault-mcp, an open-source system that stores personal AI context in a user-owned Git repo and ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom ...
Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the ...
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced ...
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency ...
Chrome zero-day CVE-2026-85046 is under active attack as the sixth actively exploited Chrome vulnerability of 2026. A type ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...