Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and ...
Western product designers love to build for high-end smartphones connected to uncapped home fiber. It is an easy trap to fall into when working out of offices in London or San Francisco where gigabit ...
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, ...
Infostealer logs expose replayable AI session tokens and API keys that can bypass login controls and enable unauthorized account access.
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
An Evilginx2-based phishing-as-a-service (PhaaS) campaign known as BigBear 2.0 has compromised the Microsoft 365 accounts of ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authen ...
ESIC beneficiaries will need to link Aadhaar with their Pehchan Card to access benefits and services covered by the Social ...
BigBear 2.0 compromised 258 organizations and stole over 5,000 Microsoft 365 credentials using MFA-bypass phishing techniques ...
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations ...
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency ...
This edition of the weekly cybersecurity newsletter bulletin covers critical zero-day discoveries, nation-state router ...