-
JetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds the total number of bugs patched across the previous 23 milestones comb…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Adobe has released a critical security update for Adobe Campaign Classic to address multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code and access sensitive data through unauthorized file system reads. This advis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address a critical authentication bypass vulnerability. This flaw could allow attackers to gain unauthorized access to affected systems by exploiting weaknesses in SAML-based single sign-o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively grading host hardware for cryptomining suitability, then exiting without dropping a single binary. C…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-ser…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end‑to‑end offensive operations wi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed, often within minutes. These short-lived misconfigurations can include Amazon RDS and DocumentDB sn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


