Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
GitHub's npm registry shipped staged publishing in May 2026, the first mandatory 2FA human checkpoint in its 16-year history, ...
Hackers used a malicious worker to inject scripts into more than 100,000 websites via the Brevo supply chain attack.
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension.
WordPress Click2Shell vulnerability lets attackers silently install themes on any admin’s site via a single crafted link, ...
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
Browser AI agent security research: security researcher Gal Weizman of Forever Security demonstrated that one ordinary browser extension can hijack AI agents in Chrome, Edge, Perplexity Comet, Opera ...
Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones' ...
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The ...
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG  5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
Sentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access ...