Pwn2Own Berlin 2026 Awards $1.3M For 47 Zero-Days
Pwn2Own Berlin 2026 wraps up: $1.3M paid out for 47 zero-days. DEVCORE takes Master of Pwn with $505K. Three intense days of enterprise exploits.
Pwn2Own Berlin 2026 wraps up: $1.3M paid out for 47 zero-days. DEVCORE takes Master of Pwn with $505K. Three intense days of enterprise exploits.
A critical vulnerability dubbed “Cordyceps” has been discovered in GitHub Actions workflows, enabling attackers to hijack CI/CD pipelines across major organizations including Microsoft, Google, and Apache. The flaw exploits misconfigurations in GitHub Actions that allow malicious actors to inject co
Threat actors are leveraging weaponized Virtual Hard Disk (VHDX) files to deploy Remcos RAT, a powerful remote access trojan. This attack vector bypasses traditional security measures by exploiting Windows’ native ability to mount virtual disk images, delivering the malware payload through multiple
CISA has added CVE-2026-42897, an actively exploited Microsoft Exchange Server XSS vulnerability, to its Known Exploited Vulnerabilities catalog. Federal agencies have until May 29, 2026 to remediate the flaw, which enables spoofing attacks via Outlook Web Access.
Nvidia plans to raise over $25 billion through its first bond offering since 2021, marking a significant corporate finance move for the world’s leading AI chip manufacturer. While primarily a financial maneuver, this massive capital raise has downstream cybersecurity implications for critical infras
Security researchers have uncovered a sophisticated adware network comprising 152 malicious Chrome extensions disguised as wallpaper customization tools. With over 105,000 combined installations, these extensions injected unwanted advertisements, generated fake traffic, and potentially harvested use
AI voice cloning is evolving fast. From customer service to deepfake scams, synthetic voices are reshaping communication and security threats alike.
An AI-powered fuzzing agent has uncovered 21 previously unknown zero-day vulnerabilities in FFmpeg, the ubiquitous multimedia processing library used by billions of devices worldwide. This discovery marks a significant milestone in automated vulnerability research, demonstrating AI’s capability to i
The Dropping Elephant threat actor group has evolved its tactics by abusing Windows’ legitimate GoogleErrorReport scheduled task to maintain persistent access on compromised systems. This sophisticated evasion technique allows the attackers to blend malicious activity with normal system processes, m
Organizations worldwide are inadvertently storing user passwords in plain text within Active Directory (AD) description fields, creating a critical security vulnerability. This widespread practice bypasses password hashing mechanisms and grants unauthorized access to anyone with basic AD read permis