FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used …
Palo Alto Networks Acquires Console to Build AI Agents for Autonomous Security Operations
Palo Alto Networks has acquired Console, an AI-native platform that will strengthen Cortex by enabling AI-driven security workflows to investigate, prioritize, and remediate threats at machine speed. The acquisition comes …
Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers
Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM …
Hackers Pose as IT Support on Microsoft Teams to Take Remote Control of Windows PCs
Cybercriminals are posing as IT technicians on Microsoft Teams and persuading employees to hand over control of their Windows computers. The campaign turns a familiar support conversation into a direct …
Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems
Silver Fox-linked hackers are using counterfeit software installers to break into Windows systems and weaken the protections meant to stop them. The campaign relies on convincing download pages that copy …
Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks
SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances. The flaws could allow unauthenticated attackers to access sensitive functionality and enable …
Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems
HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary …
Hackers Hide a Full Remote Access Trojan Inside a Real Exodus Crypto Wallet
Cybercriminals have been caught using a tampered installer for the Exodus cryptocurrency wallet to plant a full remote access trojan. The program looks close enough to the real wallet, but …
Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws
Google has released Chrome 152.0.7977.75/.76 for Windows and macOS and Chrome 152.0.7977.75 for Linux, addressing 26 security vulnerabilities across the browser. The update includes two critical use-after-free flaws affecting Shared …
Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems
A newly disclosed vulnerability in Hugging Face Transformers could allow malicious AI model repositories to place attacker-controlled Python files on a user’s system before the user approves remote code execution. …
