Uncategorized

Flowise AI Agent Builder Injection Vulnerability Exploited in Attacks, 15,000+ Instances Exposed

Threat actors are actively exploiting a maximum-severity remote code execution (RCE) vulnerability in Flowise, an open-source platform used for building…

5 months ago

Microsoft Copilot Terms of Service Label Copilot is for Entertainment Purposes Only

Microsoft's terms of service for its Copilot AI assistant include a notable disclaimer that has sparked renewed scrutiny from security…

6 months ago

GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks

A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies…

6 months ago

Hackers Use USB Malware, RATs, and Stealers in Espionage Attacks on Southeast Asian Government

A highly coordinated cyberespionage campaign has been uncovered targeting a government organization in Southeast Asia, with threat actors deploying a…

6 months ago

DarkSword Exploit Chain That Can Hack Millions of iPhones Leaked Online

A powerful iOS exploit toolkit known as DarkSword has been publicly leaked on GitHub, dramatically lowering the barrier for cybercriminals…

6 months ago

Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub

A supply chain attack targeting Trivy, the widely used open-source vulnerability scanner, has grown well beyond its initial scope. What…

6 months ago

Managing Multiple Online Accounts in 2026: Security, Structure, and Scalability

In 2026, managing multiple online accounts is no longer a fringe tactic used by niche operators. It has become core…

6 months ago

CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks

A serious security flaw in Ivanti Endpoint Manager has caught federal attention after the Cybersecurity and Infrastructure Security Agency (CISA)…

6 months ago

WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security

WhatsApp has released a new Android update through the Google Play Beta Program, bringing the version up to 2.26.7.8. The…

7 months ago

Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens and Gain Persistent Access

An ongoing phishing campaign that targets Microsoft 365 users by abusing OAuth tokens to gain long‑term access to corporate data,…

7 months ago