Your vulnerability scanner is sorting by the wrong signal. How to use CVSS, EPSS, and local context to prioritize remediation ...
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and ...
Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows vulnerabilities to deploy backdoors and surveillance ...
A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which ...
A cyber-attack on a popular open source package manager in May was the work of OpenAI agents, security researchers have revealed. Starting on May 11, the agents apparently flooded the RubyGems ...
Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are ...
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the ...
Turn those boring chores into small enjoyable moments.
Explore the latest news, real-world incidents, expert analysis, and trends in Vulnerability — only on The Hacker News, the leading cybersecurity and IT news platform.
Ukrainian hackers leak Russia's naval secrets; ShinyHunters hack the FBI; tech firms disrupt EvilTokens PhaaS.
With each year, technology grows more mainstream and as such, cybersecurity grows in demand. This paper aims to explore the ...