Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs
Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...
Japan Digital Agency Breach Exposes 246,000 Records After VPN Intrusion
Attackers exploited a previously patched VPN weakness to enter Japan’s shared government IT environment, potentially exposing about 246,000 personal records. The incident highlights the continuing danger of delayed...
Two Critical Flaws in a Popular WordPress Calendar Plugin Put 600,000+ Sites at Risk of Full Takeover
Two unauthenticated, maximum-severity vulnerabilities in the widely used 'The Events Calendar' WordPress plugin could let attackers seize full control of more than 600,000 websites without ever logging in....
Chinese Hacking Crew Weaponizes Critical Gitea Flaw to Hijack Self-Hosted Git Servers Worldwide
A Chinese-speaking intrusion set tracked as Red Heron is exploiting a critical remote-code-execution bug in self-hosted Gitea instances, deploying a custom Linux implant and rootkit against victims in...
Luciferus Markets Subscription AI for Malware Development on Criminal Forums
A service called Luciferus is being promoted on an underground forum as an unrestricted AI assistant for malware-related requests. Researchers confirmed its willingness to generate RAT code, but...
Apple’s Largest Coordinated Update Closes 273 Unique Vulnerabilities
Apple has issued coordinated updates across its device ecosystem addressing 273 unique CVEs. The fixes cover remote code execution, kernel privilege escalation, authentication bypass, privacy failures and web-content...
Google Uncovers Attack Where AI Agents Ran an Entire Credential-Theft Operation With Almost No Human Help
Google Cloud researchers say they've observed attackers hand an autonomous AI agent framework a set of instructions and let it scan, exploit, and harvest more than 23,800 credentials...
Attackers Are Quietly Cloning Domain Controllers’ Password Database — Then Deleting the Evidence
Incident responders at Huntress have documented a stealthy attack pattern in which intruders use Windows' own shadow-copy tooling to clone and steal the Active Directory password database, then...