Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before ...
Google PageBreak found over 500 verified XSS flaws across company web apps and plans closer CodeMender integration for code ...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
Report URI CSP alerts surfaced a ClickFix campaign on compromised e-commerce sites using Base64 loaders and a fake verification overlay.
At this point, keeping a WordPress site secure is starting to feel less like website maintenance and more like playing Whac-A-Mole with a keyboard. Patch one plugin, another vulnerability appears.
The Chinese-speaking operator used three different open source AI harnesses - Strix, Cairn, and Hermes - to run the ...
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already ...
Google has released a new security update for the Chrome browser, addressing a total of 12 vulnerabilities. Among these is a high-severity zero-day flaw that is currently being exploited in real-world ...
Manchester Airports Group data breach exposed 8.7 million customer records when extortion group FulcrumSec found an Iterable API key left in publicly visible JavaScript -- no server intrusion required ...
Every year, the Tri-Valley proves the same point: big things don't require big-city addresses. This corner of the Bay Area — ...
AI agents hacking retailers stole more than 600,000 credit card records from hundreds of online stores since July 2026, at $25.46 per target -- first documented case of fully autonomous criminal ...
Over 5,400 legitimate websites now serve fake CAPTCHA scams that trick users into pasting malware commands into Windows Run via ClickFix attacks.