Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search results, copied websites and free-download …
Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks
TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The flaws could allow nearby attackers to run arbitrary commands …
Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect
A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint agent used across thousands of enterprise networks worldwide. The …
Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild
CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands …
Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots
Microsoft is rolling out a fresh line of defense against unwanted digital eavesdroppers in virtual meetings. The tech giant confirmed that Microsoft Teams will soon let administrators automatically block identified …
Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages
Bank customers searching for a login page can now be led into a trap before they receive a suspicious email or text message. Criminals are manipulating Google and Bing results …
New Mysterious AI Model Dubbed Ox Alpha With Free 100 Trillion Tokens a Day for Coders
A mysterious AI system named Ox Alpha has sparked intense speculation across the developer community after appearing on OpenRouter as a free “stealth model” aimed at coding, long-running AI agents, …
Hackers Impersonate ReliaQuest Security Staff to Steal SSO Credentials and MFA Access
ReliaQuest has disclosed a social engineering attack in which threat actors impersonated members of its security team to lure employees to a fraudulent single sign-on page. The incident briefly exposed …
768 Leaked Corporate AWS Keys Remain Active With Full Administrator Access
A new cloud security investigation from Truffle Security has found that 768 publicly exposed AWS credentials still provide full administrative control over corporate AWS environments. The findings highlight a persistent …
Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data
Kimsuky has been linked to a new espionage campaign that turns a Chrome extension into a quiet Gmail collector. The operation begins with convincing phishing emails and ends with attackers …
