FBI Investigates Jobs Portal Intrusion as ShinyHunters Claims Sensitive Data Theft
The FBI is investigating unauthorized activity involving FBIjobs.gov after a defacement and expansive breach claims attributed to ShinyHunters. Some sample records reportedly matched real people, but the alleged...
Actively Exploited F5 BIG-IP OAuth Zero-Day Enables Unauthenticated RCE
F5 is warning that attackers are exploiting a critical BIG-IP APM zero-day that can provide unauthenticated remote code execution on certain OAuth authorization-server deployments. Organizations should identify exposed...
105 Minutes of Stolen Access Turned a Trusted npm Package Into a Multi-Stage Malware Loader
Attackers hijacked a maintainer account for just 105 minutes to slip a hidden loader into a popular npm package, abusing legitimate publishing infrastructure so the poisoned release carried...
Maximum-Severity Flaw in D-Link Routers Lets Attackers Take Over Devices With No Login Required
A stack-based buffer overflow in D-Link's DIR-822A router, rated a perfect CVSS 10.0, can be triggered remotely with no authentication and no user interaction, and a working public...
Suspected Chinese-Speaking Hackers Chain Two WordPress Bugs to Loot a Government Database
A likely Chinese-speaking threat actor strung together two WordPress vulnerabilities to breach at least 49 organizations in 29 countries, with one Western government agency losing 18,566 records, including...
Check Point Confirms In-the-Wild Attacks on Critical Management Server Zero-Day
A critical, pre-authentication flaw in Check Point's Management Server software was exploited in the wild weeks before a fix existed, letting attackers upload and run code on systems...
Linux KVM/arm64 Flaw Breaks VM Isolation and Exposes Host Memory
CVE-2026-89775 can leave stale writable mappings available to an ARM64 guest when KVM nested virtualization is enabled, creating a path to host-memory access and VM escape. Operators should...
Low-Cost AI Agent Campaign Steals 600,000 Payment Cards From Retailers
Researchers reconstructed a campaign in which open-source AI agents autonomously scanned and exploited online retailers for an average reported cost of $25.46 per completed scan. The operation allegedly...