Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Researchers found that leaked n8n API tokens from public GitHub commits allowed authenticated access to 321 out of 896 reachable instances. These tokens can be used to access workflow definitions, execution data, and stored credentials, potentially compromising connected systems.
Researchers found that leaked n8n API tokens from public GitHub commits allowed authenticated access to 321 out of 896 reachable instances. These tokens can be used to access workflow definitions, execution data, and stored credentials, potentially compromising connected systems.
A cluster of 77 malicious 'evil twin' extensions was discovered on the Open VSX marketplace, impersonating legitimate developer tools to exfiltrate system information. The extensions, uploaded between July 26 and August 1, 2026, have since been removed.
A cluster of 77 malicious 'evil twin' extensions was discovered on the Open VSX marketplace, impersonating legitimate developer tools to exfiltrate system information. The extensions, uploaded between July 26 and August 1, 2026, have since been removed.
Malwarebytes for Android has introduced a new Junk Cleaner tool in version 5.22 to help users manage storage clutter. The feature identifies three categories of unnecessary files: leftover and residual files, old and large downloads, and hidden app caches.
Unitel, Angola's dominant mobile operator, experienced a cyberattack that caused outages on the same day as its government-owned public offering. The incident highlights the critical need for robust cybersecurity measures during high-stakes financial events like IPOs.