TIKTOUK targets exposed WordPress backups to steal cloud and email credentials, with 50,000 credentials found across 37,000 domains.
When it comes to removing Burmese pythons, one snake does not equal another. A new study by researchers at the University of ...
A TerminalFix intrusion campaign that uses ClickFix-style social engineering, PowerShell execution, DLL sideloading, and a ...
Google report focuses on exploit of CVE-2026-88772, which executed lateral movement a month before a patch existed.
Unknown attackers exploit a patched Citrix NetScaler flaw to gain root access and deploy web shells and a tunneler.
Python SDK could allow a malicious MCP server to steal OAuth authentication material and take over AI agent accounts. The ...
Burmese pythons are using trees to bask during Florida's cooler months with the heavy adult snakes preferring cypress species ...
MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access. Analysis of the ...
Storm-3168, an AI-orchestrated threat actor also known as JADEPUFFER, used two compromised service principals to delete 100+ ...
PortSwigger published http-terminator on September 28, 2026, an AI-assisted research pipeline for discovering HTTP ...