Threat actors are actively exploiting a maximum-severity remote code execution (RCE) vulnerability in Flowise, an open-source platform used for building AI agents and customized large language model workflows.
The critical flaw, tracked as CVE-2025-59528 with a CVSS score of 10.0,...
Microsoft's terms of service for its Copilot AI assistant include a notable disclaimer that has sparked renewed scrutiny from security and enterprise communities: the product is intended solely for entertainment purposes.
According to the official Copilot terms of use, Microsoft...
A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies that threat actors use to conceal their malicious traffic.
Unlike traditional malware that simply steals data or locks files,...
A highly coordinated cyberespionage campaign has been uncovered targeting a government organization in Southeast Asia, with threat actors deploying a mix of USB-propagated malware, remote access trojans (RATs), and data stealers to secure long-term access to sensitive government systems....
A powerful iOS exploit toolkit known as DarkSword has been publicly leaked on GitHub, dramatically lowering the barrier for cybercriminals to target hundreds of millions of iPhones and iPads still running outdated software.
Security researchers are sounding the alarm as...
A supply chain attack targeting Trivy, the widely used open-source vulnerability scanner, has grown well beyond its initial scope.
What started as a GitHub Actions compromise has now extended to Docker Hub, where three malicious Docker image versions were...
In 2026, managing multiple online accounts is no longer a fringe tactic used by niche operators. It has become core infrastructure for agencies, crypto traders, e-commerce brands, and global marketing teams.
Digital business models have multiplied. A single e-commerce company...
A serious security flaw in Ivanti Endpoint Manager has caught federal attention after the Cybersecurity and Infrastructure Security Agency (CISA) added it to the Known Exploited Vulnerabilities (KEV) catalog on March 9, 2026.
Tracked as CVE-2026-1603, this authentication bypass...
WhatsApp has released a new Android update through the Google Play Beta Program, bringing the version up to 2.26.7.8. The update reveals that WhatsApp is actively developing an optional account password feature designed to add another layer of security...
An ongoing phishing campaign that targets Microsoft 365 users by abusing OAuth tokens to gain long‑term access to corporate data, which focuses on business users in North America and aims to compromise Outlook, Teams, and OneDrive without directly stealing...