Cybersecurity

MemTensor npm, PyPI packages push credential-stealing malware

Compromised MemTensor packages on npm and PyPI delivered the Go-based sckit implant across Windows, Linux, and macOS.Attackers stole publish tokens from MemTensor’s GitHub Actions...

Next.js Critical Flaw in ImageResponse Allows Server RCE

A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote code execution via the ImageResponse feature when running on the...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of the open-source AI gateway Bifrost before 2.1.0.A second flaw (CVE-2026-86242,...

Critical VeloCloud Orchestrator flaw actively exploited

Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as of September 22.The vulnerability, with a CVSS 3.1 score of...

Mac Malware Hijacks Meta Muse, Security Researcher Warns

Security researcher Patrick Wardle disclosed a vulnerability in Meta's new Muse AI assistant for Mac that allows malware to hijack dictation and steal account...

North Korea’s Contagious Interview hack steals $10.7M in crypto

North Korean threat actors compromised 30,000 devices across 100+ countries and stole from over 7,000 cryptocurrency wallets, netting at least $10.71 million.The Contagious Interview...

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell backdoor on compromised systems.The malware steals business documents, Wi-Fi passwords,...

New ChainScript RAT uses blockchain-based C2 via ClickFix lures

Threat actors are deploying a new remote access trojan called ChainScript via ClickFix lures, using a Polygon smart contract for command-and-control discovery.ChainScript masquerades as...

Latest news

Tesla signs $30B unused credit lines for the AI and robotics

Tesla signed $30 billion in unused senior unsecured bank facilities, including a $20 billion term loan and two revolvers...

New Spectre-v2 CPU Variant ‘BTR’ Hits JIT Engines

Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT engines across multiple CPU vendors.The...

Cboe, S&P Extend Deal, Eye Tokenized Options

Cboe Global Markets and S&P Dow Jones Indices extended their exclusive licensing agreement through 2051 and said they may...