Cybersecurity

Placeholder domain third-party.com now serves ClickFix malware

The long-trusted documentation placeholder domain "third-partycom" has been weaponized to serve a ClickFix malware lure to Windows users.Unlike "examplecom," the domain was not IANA-reserved...

Critical WordPress RCE bug actively exploited within hours

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, just hours after its public disclosure.The unauthenticated remote code execution (RCE) flaw carries a...

MikroTik SSH flaws chained for full router takeover

A chain of two SSH vulnerabilities—CVE-2026-67279 and CVE-2026-86060—allows unauthenticated attackers to gain full administrative control over exposed MikroTik RouterOS devices.Active exploitation began before patches...

MemTensor npm, PyPI packages push credential-stealing malware

Compromised MemTensor packages on npm and PyPI delivered the Go-based sckit implant across Windows, Linux, and macOS.Attackers stole publish tokens from MemTensor’s GitHub Actions...

Next.js Critical Flaw in ImageResponse Allows Server RCE

A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote code execution via the ImageResponse feature when running on the...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of the open-source AI gateway Bifrost before 2.1.0.A second flaw (CVE-2026-86242,...

Critical VeloCloud Orchestrator flaw actively exploited

Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as of September 22.The vulnerability, with a CVSS 3.1 score of...

Mac Malware Hijacks Meta Muse, Security Researcher Warns

Security researcher Patrick Wardle disclosed a vulnerability in Meta's new Muse AI assistant for Mac that allows malware to hijack dictation and steal account...

Latest news

KelpDAO Sues LayerZero Over $292M Bridge Exploit

KelpDAO has filed a lawsuit against LayerZero and its CEO Bryan Pellegrino over a $292 million exploit of its...

Musk Says SpaceX Could Lead AI Race Within Six Months

Elon Musk predicted SpaceX could match Anthropic's Claude Fable and OpenAI's GPT-6 within two to three months and reach...

Block brings Bitcoin Lightning payments to x402 for AI agents

Block has joined the x402 Foundation, alongside Google, Microsoft, AWS, and Coinbase, to support an open payment standard for...