The Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified by researchers as a cryptocurrency miner.
#cybersecurity
https://t.co/MHr9nMYcUk
Microsoft's code-editing software has become a recurring target for hackers looking to harvest credentials, tokens and source code running on developer’s machines.
#cybersecurity
https://t.co/BueJFRNaGM
Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.
#cybersecurity
https://t.co/Y7NUai0HSM
The next threat your server faces may have been helped along by a bot.OpenAI's Codex agent helped uncover a remote denial-of-service exploit that can be launched from a single machine to render vulnerable web servers inaccessible in seconds.
#cybersecurity
https://t.co/wh1hMiHmR9
A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor.
#cybersecurity
https://t.co/PRf2sdUWIl
Everything from access to buckets containing Slack and Jira files to internal databases was left accessible ahead of the award season.
#cybersecurity
https://t.co/rJgh4wnTfq
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer.
#cybersecurity
https://t.co/mwcTpMOzSx
People need to understand that it’s not just the biggest and most powerful AI models that pose security concerns – a whole other area of threat has been vastly underestimated.
#cybersecurity
https://t.co/bFisICvzS2
In April, a single VPN vulnerability led to data breaches at more than seventy financial institutions running Marquis Software's infrastructure, according to American Banker's reporting on the incident.
#cybersecurity
https://t.co/jpKrFNosXI
Since January 2026, the campaign has infected more than 116,000 systems and continues to add between 2,000 and 3,000 new infections per day.
#cybersecurity
https://t.co/WQGim74ktN
Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases.
#cybersecurity
https://t.co/AzvvDav4CL
UK banks are set to receive access to OpenAI’s GPT-5.5 Cyber after being excluded from Anthropic’s latest expansion of Project Glasswing.
#cybersecurity
https://t.co/Q8r73aifpp
Multiple Instagram users had their accounts hijacked after attackers convinced Meta’s AI-powered support tools that they were the legitimate owners.
#cybersecurity
https://t.co/hWE3L65MeL
A key cybersecurity vulnerability database run by the National Institute of Standards and Technology has been crippled by mismanagement and other strategic failings, leading to an extreme backlog, according to a new internal watchdog report.
#cybersecurity
https://t.co/hh9frMrZFb
AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security.
#cybersecurity
https://t.co/e1su14nnQ4
Microsoft has moved to calm an increasingly noisy backlash from the security community after appearing to threaten legal action against a researcher who spent the past several weeks dumping Windows zero-days onto the internet.
#cybersecurity
https://t.co/5V3amveFYy
Netlogon is a remote procedure call (RPC) interface and a core Microsoft Windows Server background service that authenticates services and users on Windows domain-based networks.
#cybersecurity
https://t.co/SUYE951BoF
A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD).
#cybersecurity
https://t.co/6W6yFHpDRk
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI.
#cybersecurity
https://t.co/YlT8gGxUp3
Password manager Dashlane has disabled a number of user accounts as a precaution amid a spate of brute force attacks.
#cybersecurity
https://t.co/6DpUj0LxoJ