Telegram Desktop fixed a flaw that let bot messages embed JavaScript in HTML exports to read or alter messages; old exports ...
A one-click Sogou Input Method flaw let UNC3569 deploy GRAYRABBIT backdoor, enabling remote code execution and data theft.
Discover how the Qwen3.8-27B local LLM was used to build a functional first-person 3D zombie shooter game in just five hours ...
Over 5,400 legitimate websites now serve fake CAPTCHA scams that trick users into pasting malware commands into Windows Run ...
Google has pushed out an emergency update for Chrome after confirming that hackers were already exploiting a previously ...
Espionage groups have been using BlueMoon, an exploit kit chaining recent Chrome and Windows zero-day vulnerabilities.
A newly disclosed chain of vulnerabilities in Google Chrome and the Windows kernel can compromise targets, deploy espionage ...
When a victim opens the HTA, Windows invokes mshta. exe, a legitimate Microsoft utility designed to execute HTML Applications. The malicious file pushes its own window off-screen and loads remote ...
Proofpoint identified the BlueMoon exploit kit being used by at least four hacking groups, some linked to Chinese state ...
Welcome readers! With this weekly series, we'll walk you through the top developments in AI and cybersecurity and explain why ...
A small JavaScript exploit called Deathray can freeze the macOS interface after a user opens a website. The bug affects ...
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...