A flaw in Telegram Desktop allowed specially crafted bot messages to execute JavaScript in HTML chat exports and expose ...
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
Proofpoint researchers identified BlueMoon, an exploit kit used by at least four espionage-linked threat clusters since late ...
Proofpoint says at least four espionage groups rapidly adopted BlueMoon, chaining Chrome V8 patch-gap flaws with a Windows LPE to deliver malware including GemStone and ShadowPad.
A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of ...
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
AWS has published a reference implementation for testing AI agents through GitHub Actions, allowing developers to run ...
The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under ...
Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the ...
PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...