ToxicPanda 2.0 and GoldDigger Expand Android Banking Malware Campaigns
ToxicPanda 2.0 adds 167 remote commands and targets 349 financial institutions. GoldDigger expands to South Africa and the U.K. via fake airline and retail apps
ToxicPanda 2.0 adds 167 remote commands and targets 349 financial institutions. GoldDigger expands to South Africa and the U.K. via fake airline and retail apps
A critical GitLab flaw rated CVSS 9.4 requires no authentication to exploit. Self-managed users should patch immediately or restrict GraphQL access.
Two new papers examine how LLMs fail to control sensitive information flow based on context, and how reasoning and reinforcement learning may help.
AmnesiaStealer is a new macOS infostealer distributed via ClickFix attacks. It clones browser profiles and gives attackers live, interactive control of authenti
Delta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
N-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
A multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f
A critical flaw in Rails' Active Storage framework allows unauthenticated file reads and potential RCE. Patch immediately and rotate all secrets.
Microsoft fixed 570 vulnerabilities in July's Patch Tuesday, nearly triple last month's record. AI-assisted discovery is driving the surge in patch volume.
OpenAI is temporarily lifting GPT-5.6 Sol's five-hour usage cap for Plus, Pro, and Business plans and issuing a one-time usage reset.
Attackers compromised the Injective Labs GitHub repository to publish a malicious npm package that exfiltrates private keys and mnemonic phrases.
AI is rapidly widening the gap between skill and ability in cyberattacks. The same tools that strengthen defense also enable harm.