On the second day of the Pwn2Own Ireland 2025 competition, security researchers demonstrated 56 previously unknown vulnerabilities, earning a total [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a high-severity Windows Server Message Block (SMB) vulnerability is [...]
Microsoft has addressed a maximum-severity vulnerability in ASP.NET Core, identified as CVE-2025-55315, which is an HTTP request smuggling flaw within the Kestrel [...]
Oracle has released an emergency security update for a critical zero-day vulnerability, tracked as CVE-2025-61882, in its E-Business Suite (EBS). [...]
Signal has introduced a new cryptographic defense named Sparse Post-Quantum Ratchet (SPQR) to protect user communications against potential future quantum [...]
Two distinct spyware campaigns, dubbed ProSpy and ToSpy, are deceiving Android users by posing as legitimate messaging applications. The malicious [...]
A maximum-severity vulnerability in Fortra's GoAnywhere managed file transfer (MFT) software is being actively exploited by attackers. Tracked as CVE-2025-10035, [...]
A ransomware attack targeting critical airport systems caused significant disruptions at several major European airports over the weekend. The incident [...]
A critical zero-click vulnerability, named ShadowLeak, has been discovered in OpenAI’s ChatGPT Deep Research agent, allowing attackers to extract sensitive [...]
A self-propagating supply chain attack has compromised at least 187 npm packages, beginning with the popular @ctrl/tinycolor library, which receives [...]
A new phishing-as-a-service platform named VoidProxy is targeting Microsoft 365 and Google accounts, even when protected by third-party single sign-on [...]
A threat actor known as WhiteCobra is distributing fraudulent extensions across the Visual Studio Marketplace and OpenVSX registry, targeting developers [...]
A recently identified ransomware variant, named HybridPetya, mimics the behavior of the infamous Petya/NotPetya malware but adds the capability to [...]
A malfunction in Microsoft’s anti-spam service is mistakenly flagging legitimate URLs as malicious, preventing users from opening links in Exchange [...]