Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A security vulnerability in Telegram Desktop allows attackers to embed malicious JavaScript in messages that, when viewed, can exfiltrate chat content and account data from the desktop application, bypassing the intended rendering sandbox.
AWS published a deep dive on using the AWS Security Reference Architecture for PCI DSS compliance, providing guidance for security controls and audit logging in regulated cloud environments.
A threat actor tracked as Red Heron has leveraged the critical Gitea RCE vulnerability CVE-2026-60004 to compromise 13 organizations, targeting software development infrastructure for source code and credential theft across multiple industry sectors.
Anthropic's CEO has publicly called for a strategic industry shift from improving AI capabilities to implementing robust control mechanisms, reflecting growing concern about capability development outpacing safety governance.
Attackers are actively scanning for exposed Vite development servers to steal AWS and Azure cloud credentials, exploiting Vite's default dev server configuration that binds to all interfaces without authentication.
The Pro-Ukraine Hacking Cat group has deployed new custom malware variants against Russian targets, featuring enhanced persistence and data theft capabilities that reflect ongoing evolution in hacktivist cyber operations.