A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices ...
North Korean threat actors, tracked as WaterPlum (also known as Contagious Interview), have compromised at least 30,000 ...
Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
A one-click Sogou Input Method flaw let UNC3569 deploy GRAYRABBIT backdoor, enabling remote code execution and data theft.
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
A rapidly adopted exploit kit, dubbed BlueMoon, chains Chrome and Microsoft Windows zero-days to compromise targets in espionage-focused phishing campaigns.
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development.
Chrome 153 Stable fixes 230 security issues, including an in-the-wild V8 out-of-bounds write that can run code inside the ...
Proofpoint says at least four espionage groups rapidly adopted BlueMoon, chaining Chrome V8 patch-gap flaws with a Windows LPE to deliver malware including GemStone and ShadowPad.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
Google has fixed 230 Chrome vulnerabilities, including an actively exploited V8 zero-day that can trigger heap corruption.