A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
LoongLeak vulnerability in Loongson 3A5000 and 3A6000 CPUs lets any unprivileged program read disk encryption keys and root ...
Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.
Patch Tuesday August 2026 closed a Windows kernel zero-day (CVE-2026-68820) that North Korea's Lazarus Group had been ...
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday.
A single AI-assisted researcher discovered the massive blast-radius vulnerabilities using fewer than 20 prompts on publicly available models in less than 24 hours.
Microsoft patches 398 flaws, including exploited CVE-2026-68820 that lets local attackers reach SYSTEM, plus four unauthenticated 9.8 RCEs.
Artificial intelligence has become a target for attackers rather than only a tool they use, according to CrowdStrike Holdings Inc.’s “2026 Threat Hunting Report,” released today. The annual report ...
The OpenWrt project has released updated versions that fix security vulnerabilities, some of which are classified as critical risks.
Security researchers at Searchlight Cyber have used OpenAI’s GPT5.6 Sol Ultra to successfully develop a full exploit chain for two critical WordPress Core vulnerabilities. The first vulnerability, ...
Researchers at Paradigm Shift have published the technical details of usbliter8, a new unpatchable iPhone BootROM vulnerability that enables arbitrary code execution on devices powered by Apple’s A12 ...
Security research firm Paradigm Shift today published details of a new BootROM vulnerability affecting Apple's A12 and A13 chips, along with a working proof-of-concept exploit named "usbliter8." The ...