CVE-2026-61500 is a critical authentication bypass in Rejetto HTTP File Server, discovered by Anthropic Mythos AI and exploited within 24 hours of public disclosure by a China-linked actor targeting ...
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows ...
The tech company confirms that its PCI Detokenisation Service has now attained Payment Card Industry Data Security Standard ...
Executive SummarySalt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding ...
TIKTOUK targets exposed WordPress backups to steal cloud and email credentials, with 50,000 credentials found across 37,000 domains.
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.
"I'm just checking to see if it's fixed," "It's pointed at the test DB," "I cleaned up the things I made for verification at ...
Threat Labs has identified a macOS malware campaign using a fake Zoom installer to deliver a two-stage backdoor named ...
Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.
With Claude Code mods, I created a guard that rejects specific types of operations before the tool executes them. On the ...
Fake Zoom installers trick Mac users into revealing passwords and deploy CloudSyncD backdoor, with active command servers ...
Rapuncel infostealer campaign stole browser passwords and crypto wallet data from Windows users after a Microsoft-signed kernel driver killed 145 antivirus and EDR tools -- the same driver that scored ...