Cybersecurity

Hugging Face Hacked by Autonomous AI Agent System

Open-source AI platform Hugging Face was hacked by an autonomous AI agent system that gained unauthorized access to internal datasets and credentials.The attack originated...

Critical Nginx Flat Allows Unauthenticated Remote Code Execution

F5 patched a critical nginx heap buffer overflow (CVE-2026-42533) rated 9.2 on CVSS v4, affecting versions since 2011.The flaw allows remote code execution if...

Sandworm Uses ClickFix Fake CAPTCHA to Target Ukraine

Russian state-sponsored hackers from the Sandworm group are using fake CAPTCHA checks to trick Ukrainian targets into executing malware.The campaign, attributed to sub-cluster UAC-0145,...

WordPress core hit by zero-click RCE bug, patch now live

WordPress patched a pre-authentication remote code execution flaw in versions 6.9.5 and 7.0.2 on July 17, 2026.The bug, found by Adam Kues of Searchlight...

ViteVenom: 7 Malicious npm Packages Target Vite Ecosystem

Researchers at Checkmarx uncovered the ViteVenom campaign, a software supply chain attack using seven malicious npm packages targeting the Vite frontend tooling ecosystem.The attack,...

CISA Adds Critical Microsoft SharePoint Flaw CVE-2026-58644 to KEV Catalog

CISA added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644, to its Known Exploited Vulnerabilities catalog.The flaw allows unauthenticated remote code execution and has been...

n8n bug lets one token claim login into wrong user account

A critical identity-binding flaw in n8n's token exchange allowed account takeover when multiple external issuers were trusted.The vulnerability (CVE-2026-59208) matched JWTs on the sub...

Daxin malware resurfaces with Stupig backdoor in Taiwan attack

The Daxin kernel-mode rootkit, dormant for over four years, has resurfaced on a compromised host at a Taiwan-based manufacturing subsidiary alongside a new backdoor...

Latest news

Circle Launches Bitcoin-Backed Borrowing for Institutions Via USDC

Circle launched a Bitcoin-backed borrowing service for institutional clients, allowing eligible Circle Mint customers to deposit BTC as collateral...

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell backdoor on compromised systems.The malware...

Bitmine 98% to 5% ETH goal after $74M buy

Bitmine bought 27,562 ETH, bringing its total holdings to 5,983,940 ETH ($16.1 billion), or 4.9% of the total supply.Chairman...