CISA says Microsoft Office and HPE OneView flaws exploited in the wild
At the time of writing, there are no confirmed public reports about attacks exploiting the above-mentioned vulnerabilities.
At the time of writing, there are no confirmed public reports about attacks exploiting the above-mentioned vulnerabilities.
Popular AI-powered forks of VS Code have been found to recommend extensions that do not exist in the Open VSX registry.
The malicious add-ons masquerade as legitimate AI sidebar tools.
The vulnerability enables unauthenticated RCE by allowing attackers to inject and run shell commands on exposed devices.
Hudson Rock says initial access was likely obtained using credentials harvested by infostealers like RedLine, Lumma, and Vidar.
The campaign, dubbed ‘PHALT#BLYX,’ begins with phishing emails posing as reservation cancellations from popular hotel booking platforms.
Kimwolf is believed to be an Android variant of AISURU and may be behind a series of record-setting DDoS attacks late last year.
The group has maintained “high-intensity intelligence gathering activities” against Ukrainian institutions throughout 2025.
The attackers gained access after Trust Wallet’s developer GitHub secrets were exposed.
The operation uses social engineering and technical evasion techniques, delivering malware through trojanized HWP documents.
Showing elements 321 - 330