CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed
A maximum-severity RCE vulnerability (CVE-2025-59528, CVSS 10.0) in the popular Flowise AI agent builder is under active attack. Over 15,000 instances are still exposed online. Here’s what you...
Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15
Google has patched CVE-2026-5281, a use-after-free zero-day in Chrome’s WebGPU engine already exploited in the wild. It’s the fourth Chrome zero-day of 2026. CISA has mandated federal agencies...
Unpatched Adobe Reader Zero-Day Has Been Silently Exploiting Users Since December
A highly sophisticated zero-day exploit targeting Adobe Reader has been active since December 2025, requiring just a single click to open a PDF. No patch is available yet...
APT28’s FrostArmada: How Russian Hackers Built an 18,000-Router Army to Steal Microsoft 365 Credentials
Russia’s APT28 compromised over 18,000 routers across 120 countries to silently hijack DNS and steal Microsoft 365 credentials from government agencies and cloud providers. An international disruption operation...
A Silent Killer Sneaking into Your Code: New Campaign Targets VS Code Developers
From seemingly innocuous extensions to stealthy trojans, the threat landscape for developers is evolving. While the world continues to grapple with the ever-shifting tide of cybersecurity threats, a...
GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities
Security researchers have uncovered vulnerabilities in GitLab’s Community Edition and Enterprise Edition platforms, prompting the company to release critical security patches. On December 10th, 2025, Gitlab released update...
VSCode: A New Wave of Malware Exploits the Heart of Creative Workflows
The lines between personal work and corporate security are increasingly blurring, especially for developers. With tools like Visual Studio Code (VS Code) becoming integral to both individual projects...
A Sneaky New Threat: Microsoft Teams Calls and QuickAssist Lead to Stealthy Malware Attacks
From phishing calls to fileless malware, the evolution of cyberattacks is alarmingly rapid. The latest threat employs a sophisticated blend of social engineering and technical prowess to bypass...