The type confusion vulnerability allows a guest-to-host sandbox escape which can lead to remote code execution ...
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have ...
Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
A critical vulnerability in the Node.js sandboxing library, isolated-vm, has exposed a serious risk to AI agents, automation ...
Cloudflare Workers Spectre attack research published August 19, 2026 showed JWT token theft at 12 bits per second in live ...
Zuma’s retraction of vote-buying claims; ActionSA sues ANC’s Maepa over alleged AI-fake claims; And, son of Uganda's ...
A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft ...
A critical isolated-vm flaw lets untrusted JavaScript escape the V8 sandbox and potentially hijack the host process.