Microsoft is warning that a campaign using fake human-verification prompts can turn a user's Windows computer into an entry point for attackers to reach an organization's internal network .
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an ...
The npm package @7nohe/openapi-react-query-codegen, which receives roughly 150,000 weekly downloads, has been compromised by ...
An agent vendor walks into a security review today carrying a certification built for deterministic software, an expensive ...
Alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive ...
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates ...
OpenAI agents hacked Hugging Face in a 700-strong swarm after 1,200 agents exchanged 70,000 messages. ETIH’s edtech news report explains how.
Chinese-speaking hackers exploited ownCloud and WordPress flaws to steal sensitive data from Philippine nuclear and naval ...
Even as the White House claims to be focused on transparency, it has ignored a congressional requirement to disclose a report on foreign meddling in the 2024 election. By Dustin Volz Dustin Volz ...
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its ...
If you’ve ever found yourself needing to securely connect to a remote server, manage a Git repository, or even just transfer files without the hassle of constantly typing passwords, then you’ve ...
In October 2025, Microsoft Threat Intelligence identified destructive wiping activity and uncovered a sophisticated Go programming language (Golang)-based backdoor we now track as GigaWiper, a ...