Large enterprises scramble after supply-chain attack spills their secrets 2025-03-16 22:03 tj-actions/changed-files corrupted to run credential-stealing memory scraper.
Android apps laced with North Korean spyware found in Google Play 2025-03-12 18:03 Google's Firebase platform also hosted configuration settings used by the apps.
Apple patches 0-day exploited in “extremely sophisticated attack” 2025-03-11 16:03 0-day exploited by maliciously crafted web content to break out of security sandbox.
Nearly 1 million Windows devices targeted in advanced “malvertising” spree 2025-03-07 15:03 Malware stole login credentials, cryptocurrency, and more from infected machines.
Massive botnet that appeared overnight is delivering record-size DDoSes 2025-03-06 08:03 Eleven11bot infects video recorders, with the largest concentration of them in the US.
Threat posed by new VMware hyperjacking vulnerabilities is hard to overstate 2025-03-04 16:03 Just one compromised VM can make all other VMs on that hypervisor sitting ducks.
Serbian student’s Android phone compromised by exploit from Cellebrite 2025-02-28 18:02 Android users who haven't installed Google's February patch batch should do so ASAP.
Copilot exposes private GitHub pages, some removed by Microsoft 2025-02-27 18:02 Repositories, once set to public and later to private, still accessible through Copilot.
Google Password Manager finally syncs to iOS—here’s how 2025-02-26 08:02 Chrome for iOS no longer syncs solely to iCloud.
How North Korea pulled off a $1.5 billion crypto heist—the biggest in history 2025-02-24 18:02 Attack on Bybit didn't hack infrastructure or exploit smart contract code. So how did it work?