Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Homebrew 7.0.0 has been released with a built-in GUI and enhanced security controls including improved sandboxing for formula execution and better integrity verification for downloaded packages.
Members of the 'Black Axe' cybercriminal group have been extradited from multiple countries following coordinated international law enforcement operations targeting the financially motivated organized crime network.
A malicious Twitch browser extension with 30,000 installs has been caught leaking OAuth authentication tokens, potentially compromising user accounts and linked third-party services through persistent token theft.
Attackers hijacked the official HBO Max Reddit account to distribute malware, using the account's verified status badge to post malicious links in popular subreddits and trick users into downloading malware.
Researchers have demonstrated a new DDRop attack that breaks the confidentiality guarantees of Intel TDX and AMD SEV-SNP trusted execution environments by exploiting DRAM access patterns to leak data from encrypted memory regions.
The 3BB attacker is exploiting MeshCentral open-source remote management software to deploy backdoors and gain root access to Windows and Linux systems, using the tool's legitimate capabilities to evade detection.