Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts
3+ hour, 56+ min ago (492+ words) A phishing kit known as Kali365 is targeting U.S. organizations through device code phishing attacks that abuse Microsoft’s legitimate authentication process to hijack Microsoft 365 accounts. Unlike conventional phishing campaigns that direct targets to counterfeit login portals, Kali365 sends victims to a real Microsoft…...
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
4+ hour, 10+ min ago (661+ words) A new Linux vulnerability dubbed “RefluXFS” is a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in…...
What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development
5+ hour, 42+ min ago (586+ words) The rapid adoption of AI coding assistants has transformed software development, enabling developers to generate production-ready applications in minutes rather than days. But as organizations increasingly rely on AI-generated code, a new question has emerged: what kinds of security flaws…...
Cloudflare Data Reveals Which World Cup Teams Moved the Global Internet Most
7+ hour, 9+ min ago (665+ words) The 2026 World Cup did more than fill stadiums and television screens. It reshaped when millions of people used the Internet, creating noticeable surges and dips in web activity across countries. The shifts were tied to local kickoff times, streaming habits,…...
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
5+ hour, 29+ min ago (675+ words) Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth…...
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
4+ hour, 40+ min ago (418+ words) A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage no clicks, downloads, or credential theft required. Security researchers…...
ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
5+ hour, 15+ min ago (370+ words) ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. Successful exploitation could allow threat actors to gain control over vulnerable routers, potentially leading to network…...
Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption
5+ hour, 45+ min ago (481+ words) Iran-linked hackers are not relying only on loud attacks, public leaks, or website defacements. They are quietly building access inside companies, cloud accounts, service providers, and industrial networks that could later be used to disrupt operations during a crisis. Recent…...
Apple Releases Fixes for Hide My Email Flaw that Exposes Users' Real Email Addresses
6+ hour, 31+ min ago (438+ words) Apple has released a security fix addressing a critical flaw in its iCloud+ “Hide My Email” feature that could expose users’ real email addresses, undermining the core privacy promise of the service. The vulnerability, which reportedly remained unresolved for over…...
Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains
7+ hour, 44+ min ago (563+ words) Royal ransomware turned ordinary Windows compromises into enterprise-wide crises by pairing a phishing foothold with fast domain takeover. In incidents reviewed by responders, the operators used Qbot to gain a presence and then expanded their reach before deploying encryption. The…...