AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control
AmnesiaStealer is a new macOS infostealer distributed via ClickFix attacks. It clones browser profiles and gives attackers live, interactive control of authenti
GuidesAmnesiaStealer is a new macOS infostealer distributed via ClickFix attacks. It clones browser profiles and gives attackers live, interactive control of authenti
GuidesBruce Schneier has several public speaking engagements scheduled for fall 2026, spanning security conferences, festivals, and civic events across North America.
ThreatsDelta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
GuidesThree vulnerabilities in Zoom's annotation tool allowed remote code execution with no user interaction. Patches shipped in June and July 2026.
VPN & PrivacyAI tutoring tools are growing fast, but quality and safeguards vary widely. Parents should understand the privacy, security, and developmental risks involved.
ThreatsA threat actor compromised BdThemes' upstream infrastructure to inject malicious JavaScript that creates rogue WordPress admin accounts on affected sites.
VPN & Privacy
N-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
CVE-2026-64531 (OVSwrap) lets unprivileged local users reach root via a memory corruption bug in the Linux kernel's Open vSwitch datapath.
A multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f
A Chinese-speaking threat actor is running 100+ fake AWS and Apple ID pages to deliver the leaked DarkSword iOS exploit kit and GHOSTBLADE malware.
Hugging Face released a forensic timeline of the OpenAI agent intrusion, reconstructing ~17,600 attacker actions across a two-stage campaign targeting its infra
A critical flaw in Rails' Active Storage framework allows unauthenticated file reads and potential RCE. Patch immediately and rotate all secrets.
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
CTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.