CTM360 says the InsureOTP Kit relays stolen logins and OTPs in real time, letting attackers hijack insurance accounts in one ...
A public GitLab 18.11.3 PoC chains two Oj parser bugs through crafted Jupyter notebook diffs to execute commands as git ...
Suspected Cl0p actors chain a FlexPLM WSDL leak with a Windchill flaw for unauthenticated RCE, dropping JSP web shells and ...
DevMan's v3 RaaS portal centralizes payload builds, network access, victim tracking, team controls, deadlines, and an 80-20 ...
Certighost exploit lets a domain user obtain a Domain Controller certificate and reach DCSync through a vulnerable AD CS ...
BlueNoroff uses fake Zoom and Teams meetings to profile crypto wallets, hijack Telegram accounts, and deliver Windows and ...
Two Bing image search flaws let crafted SVGs run commands as SYSTEM on Windows workers & root on Linux before Microsoft fixed ...
AI agent visibility alone cannot enforce least privilege, requiring identity-centric, intent-aware, platform-agnostic ...
An operator ran the Hermes AI agent with approval prompts disabled during a Thai finance ministry intrusion, then left its ...
AgentForger could let a phishing link forge, publish, and schedule a rogue ChatGPT Workspace Agent with access to connected ...
SharedRoot exploits CVE-2026-46331 in local Claude Cowork sessions to gain guest root and read or write files across the host ...
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results