A previously undocumented threat actor spent nearly a month running zero-day exploits against SonicWall's SMA 1000 series VPN appliances before either vulnerability was ever publicly disclosed, according to incident-response findings published by security firm Volexity. The group, which Volexity tra...
An attacker drained roughly $18 million in USDC from Ostium, a decentralized perpetuals exchange built on the Arbitrum network, after gaining control of a private key used to sign the platform's price-feed data — not by exploiting a flaw in the protocol's smart contract code.
Blockchain security f...
A woman waiting for a delivery gets a text saying her package is stuck at customs and needs a small fee to release it. She's expecting a parcel, she's on her phone anyway, and the message looks exactly like the ones her courier normally sends. She taps the link, enters her card details on a page tha...
Okta's Red Team has disclosed HollowByte, a denial-of-service flaw in OpenSSL that lets a remote attacker exhaust a server's memory using an 11-byte message and no authentication at all — before any encryption handshake even completes.
The bug lives in how older OpenSSL versions handle the very fi...
A critical vulnerability chain in WordPress core, nicknamed wp2shell, is now being actively exploited in the wild, according to security firm Patchstack, which recorded attack attempts starting just before 7:00 PM ET on Friday — hours after WordPress shipped an emergency patch. The flaw needs no use...
Fraud researchers are warning football fans to be cautious tonight, when Spain and Argentina meet in the World Cup final, as the tournament's closing weeks have driven a fresh wave of fake streaming sites designed to harvest payment details rather than show any football at all.
Kaspersky has track...
TP-Link has patched two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras that let an attacker already on the same local network intercept administrator login credentials and pull sensitive location data from the device without ever logging in.
The more serious flaw, CVE-2026-9770, car...
Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and security advocate at Semgrep, secretly reprogrammed an open-weight AI coding model to write insecure software on command — for under $100 and in roughly an hour, using nothing more than fine-tuning and ten training...
Italy's data protection authority, the Garante, has fined telecom operator WindTre €1,715,600 over two 2025 data breaches that exposed the personal information of more than 365,000 customers — breaches that started not with a line of malicious code, but with a phone call.
According to the regulato...