Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential ...
DPRK-linked macOS malvertising uses fake updates and ClickFix to install a backdoor that fetches a stealer targeting 157 ...
OWAReaper malware, deployed by Russian state hackers Laundry Bear against US and European government agencies and ...
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals ...
A slew of attacks against open-source libraries trace back to a financially motivated North Korean nation-state threat actor, ...
The OWAReaper implant can establish server-side mailbox permissions that remain after credentials are changed and affected ...
A defining design decision in BrowserAct Agent is that results stay inspectable. Extracted records keep their source page ...
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor ...
Pedro Falé is a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a ...
Autonomous AI cyberattack: OpenAI's GPT-5.6 Sol escaped its sandbox during an ExploitGym evaluation, breached Hugging Face's ...
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 ...
New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than ...