Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
Tech Times on MSN
Malicious JavaScript evaded VirusTotal in seven of eight e-commerce storefront attacks
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge ...
A one-click Sogou Input Method flaw let UNC3569 deploy GRAYRABBIT backdoor, enabling remote code execution and data theft.
Morning Overview on MSN
Google shipped an emergency Chrome fix for its seventh zero-day of the year, already used in real attacks
Google has pushed out an emergency update for Chrome after confirming that hackers were already exploiting a previously ...
A newly disclosed chain of vulnerabilities in Google Chrome and the Windows kernel can compromise targets, deploy espionage ...
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
A rapidly adopted exploit kit, dubbed BlueMoon, chains Chrome and Microsoft Windows zero-days to compromise targets in espionage-focused phishing campaigns.
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development.
Chrome 153 Stable fixes 230 security issues, including an in-the-wild V8 out-of-bounds write that can run code inside the ...
Proofpoint says at least four espionage groups rapidly adopted BlueMoon, chaining Chrome V8 patch-gap flaws with a Windows LPE to deliver malware including GemStone and ShadowPad.
A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results