-
Two vulnerabilities in Anthropic’s Claude for Chrome extension could allow a malicious browser extension to trigger AI-driven actions affecting a victim’s Gmail, Google Docs, and Google Calendar data. These issues are still reproducible in Claude for C…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A suspected China-linked threat actor has integrated Anthropic’s Claude Code and DeepSeek-v4-pro into an active intrusion campaign targeting government entities, Taiwanese industry, and financial-services organizations. TencShell was first documented b…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fortinet has released security updates for seven vulnerabilities affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox, including a high-severity flaw that could expose Virtual Network Computing (VNC) access across all network interfaces…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Notepad++ has released version 8.9.7, codenamed “Slava Ukraini.” This update addresses five security vulnerabilities related to session-file handling, environment-variable expansion, ZIP extraction, macro validation, and the Windows installation proces…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A threat campaign discovered in mid-July 2026 abused the compromised Artlist subdomain new-blog. artlist[.]io to distribute a Remote Access Trojan through a fake CAPTCHA prompt. The operation combined stolen WordPress credentials, blockchain-based Ethe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In July 2026, Microsoft addressed a record total of 570 vulnerabilities, including three zero-days, two of which were exploited in the wild and one that was publicly disclosed. The release includes 59 Critical vulnerabilities, with Remote Code Executio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Four AsyncAPI packages previously affected by the Shai-Hulud: The Second Coming campaign have been compromised again, with new malicious releases delivering a RAT-focused build of the Miasma worm. The impacted versions are @asyncapi/generator 3.3.13.3….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
According to a reproducible wire-level analysis of version 0.2.93, xAI’s Grok Build CLI allegedly transmitted entire Git repositories, including unread files and commit history, to xAI infrastructure by default. The researcher noted that the behavior a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hundreds of thousands or millions of fictional applications. The technique …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitm…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


