• Home
  • Web
  • Branding
  • Print
  • 3D & Motion
  • Email Marketing
  • Digital Marketing
  • Presentations & Decks
  • Photography
  • Contact

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

How Synthetic Identity Fraud is Coming for Machine Identities

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

The Fastest Path to AI Adoption Runs Through Security

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

Why Modern SOCs Need Multi-Layered Detections

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

N-day is Becoming N-Hour. Patching Faster Won't Save You.

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

  • «
  • 1
  • 2
  • 3
  • 4
  • »

01792 951582

Swansea SA5 9DB.

Instagram    |    Linkedin
Work
  • Web
  • 3D & Motion
  • Brand Identity
  • Print
Information
  • Contact
  • FAQs
  • Terms & Conditions
  • Privacy Policy
  • Cookies

All content on this site © Pentagon Design Ltd. 2010 - 2026

Registered in England & Wales. No. 06061392