An attacker drained roughly $18 million in USDC from Ostium, a decentralized perpetuals exchange built on the Arbitrum network, after gaining control of a private key used to sign the platform's price-feed data — not by exploiting a flaw in the protocol's smart contract code.

Blockchain security f...

A woman waiting for a delivery gets a text saying her package is stuck at customs and needs a small fee to release it. She's expecting a parcel, she's on her phone anyway, and the message looks exactly like the ones her courier normally sends. She taps the link, enters her card details on a page tha...

Okta's Red Team has disclosed HollowByte, a denial-of-service flaw in OpenSSL that lets a remote attacker exhaust a server's memory using an 11-byte message and no authentication at all — before any encryption handshake even completes.

The bug lives in how older OpenSSL versions handle the very fi...

A critical vulnerability chain in WordPress core, nicknamed wp2shell, is now being actively exploited in the wild, according to security firm Patchstack, which recorded attack attempts starting just before 7:00 PM ET on Friday — hours after WordPress shipped an emergency patch. The flaw needs no use...

Fraud researchers are warning football fans to be cautious tonight, when Spain and Argentina meet in the World Cup final, as the tournament's closing weeks have driven a fresh wave of fake streaming sites designed to harvest payment details rather than show any football at all.

Kaspersky has track...

Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and security advocate at Semgrep, secretly reprogrammed an open-weight AI coding model to write insecure software on command — for under $100 and in roughly an hour, using nothing more than fine-tuning and ten training...