CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Researchers have disclosed a vulnerability in Claude for Chrome that allows malicious browser extensions to execute tasks on a user's Gmail, Google Do…
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
Meta has filed a patent for always-on AI voice surveillance technology that analyzes emotional state from vocal patterns and maintains timestamped log…
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Threat actors exploited Meta's artificial intelligence support bot to reset passwords and seize high-profile Instagram accounts this weekend. The comp…
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
Coinspect disclosed a critical vulnerability in cryptocurrency wallet software that attackers are actively exploiting to steal funds. The flaw, dubbed…
Microsoft Reins in RoguePlanet Zero-Day Threat
Microsoft addressed a critical Windows Defender vulnerability exploited by threat actor "Nightmare-Eclipse" after the researcher published a proof-of-…
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has instructed ShareFile customers to immediately shut down Windows servers running Storage Zone Controllers after identifying a cre…
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Binarly firmware researchers discovered six previously unknown vulnerabilities in U-Boot, the bootloader used by millions of embedded devices worldwid…
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
Microsoft BitLocker vulnerabilities expose ATM infrastructure and broader organizational systems to compromise, researchers warn. The flaws exist in B…
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft released patches for CVE-2026-50656, a privilege escalation vulnerability in its Malware Protection Engine that attackers can exploit to gai…
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos researchers analyzed endpoint security telemetry and discovered that legitimate AI coding agents trigger attack detection rules at alarming rat…
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Researchers at Sand Security identified a critical session isolation flaw in Writer, an enterprise AI platform, that enabled attackers to escalate fro…
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
GitHub discovered a vulnerability in its Agentic Workflows feature that allows unauthenticated attackers to extract private repository data through cr…
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers identified a critical vulnerability in Opera GX that allowed malicious websites to silently install browser extensions and harvest sensiti…
Cisco finally confirms attackers exploiting Unified CM flaw
Cisco confirmed active exploitation of a Unified Communications Manager (Unified CM) vulnerability that the company patched in early June. Attackers a…
Opera rolls out Paste Protect feature to fight ClickFix attacks
Opera browser has launched Paste Protect, a security mechanism targeting ClickFix attacks. These attacks manipulate users into pasting malicious comma…
A Record-Breaking Patch Tuesday for June 2026
Microsoft addressed 197 vulnerabilities across Windows and supporting applications in June 2026, setting a new record for exploitable bugs fixed in a …
Microsoft fixes bug that removed Copilot buttons in Outlook
Microsoft resolved a bug that stripped Copilot Chat and Copilot buttons from Classic Outlook in Windows. The issue affected users holding the Copilot …
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
Argo CD, the widely deployed continuous delivery platform for Kubernetes, contains an unpatched vulnerability in its repo-server component that permit…
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Microsoft researchers have identified a novel attack vector targeting AI agents through poisoned tool descriptions. Attackers can manipulate how AI ag…
New BioShocking attack manipulates AI browser into data theft
Researchers have identified a novel prompt injection attack called "BioShocking" that exploits AI-powered browsers by manipulating their language mode…