Cybersecurity

North Korea macOS Malvertising Uses Fake Update, Blockchain C2

North Korean hackers are using a fake macOS update screen to trick users into running malicious Terminal commands.The campaign employs blockchain-hosted command-and-control (C2) via...

Azure Cosmos DB flaw could let attackers access all tenant databases

Security researchers at Wiz discovered a vulnerability in Azure Cosmos DB that could have allowed an attacker to gain full read and write access...

Hidden Word prompts worm through Copilot, alter figures

Hidden instructions in Word documents can make Microsoft 365 Copilot rewrite financial figures and copy the same payload into the finished file, according to...

FCC bans foreign robots, power inverters from US market

The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from import, marketing, or...

Rails critical Active Storage bug lets attackers read files remotely

Ruby on Rails patched a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), allowing unauthenticated file read on servers using libvips.Attackers can extract secret_key_base, database...

RufRoot vulnerability allows unauthenticated RCE in Ruflo

A maximum-severity vulnerability (CVE-2026-59726, CVSS 10.0) in the open-source AI agent platform Ruflo allows unauthenticated remote code execution.The flaw, codenamed RufRoot, exploits an unauthenticated...

Firefox JIT bug CVE-2026-10702 exploited via malicious webpage

Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.The vulnerability also compromises Tor Browser, with no...

Joyfill npm beta releases drop blockchain-linked RAT

Two beta npm packages from @joyfill were compromised to deliver the DEV#POPPER remote access trojan, using a multi-blockchain resolver structure.The malware retrieves encrypted commands...

Latest news

Brazil mandates 24-hour hold on crypto transfers over $10k

Brazil's central bank will require virtual asset service providers to place holds of up to 24 hours on transfers...

Senate Files Motion to Advance Crypto Clarity Act

Senate Majority Leader John Thune filed a motion to proceed on the Clarity Act early Saturday, initiating the procedural...

Crypto finally sheds ‘get rich quick’ label: Nansen CEO

Nansen CEO Alex Svanevik says crypto is shifting from "toy world" reputation to real-world assets like tokenized stocks and...