New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
What's new: A new Go-based botnet named NadMesh has emerged, targeting exposed AI services to harvest cloud keys and Kubernetes...
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
What's new: Researchers have identified seven malicious npm packages targeting the Vite frontend tooling ecosystem, part of a software supply...
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
What's new: A flaw in OpenSSL, named HollowByte, allows attackers to freeze server memory with 11-byte TLS requests. This issue...
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
What's new: A critical vulnerability, dubbed wp2shell, has been discovered in WordPress core that allows unauthenticated attackers to execute code...
NSAuditor AI Enterprise 0.46.0: Every PCI DSS Citation Derived From the Standard Itself — and Guarded So It Cannot Drift
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
What a Network Security Auditor Actually Does (and What They Can’t)
NSAuditor AI Enterprise 0.45.0: Evidence That Says Only What It Can Prove