Pwn2Own Berlin Day Two: $523K In Exploits Awarded
Day Two of Pwn2Own Berlin 2026: $523K awarded for 24 zero-days on Day One. SharePoint, Exchange, and Safari under attack today. The race for Master of Pwn intensifies
Day Two of Pwn2Own Berlin 2026: $523K awarded for 24 zero-days on Day One. SharePoint, Exchange, and Safari under attack today. The race for Master of Pwn intensifies
Microsoft has released RAMPART and Clarity, two open-source security tools designed to help developers build safer AI agents. RAMPART provides a security testing framework for AI agents, while Clarity offers risk assessment and monitoring capabilities. These tools address growing concerns about AI a
Chinese-language Phishing-as-a-Service (PhaaS) platforms have significantly evolved, now incorporating artificial intelligence and sophisticated MFA bypass techniques. These commercial services lower the barrier to entry for cybercriminals, offering turnkey phishing solutions with advanced evasion c
Google has released an emergency security update for Chrome addressing multiple critical vulnerabilities, including CVE-2025-0411 and CVE-2025-0410, which could allow remote attackers to execute arbitrary code on affected systems. These high-severity bugs affect Chrome’s V8 JavaScript engine and ANG
AI is reshaping OSINT: automation powers modern investigations while legacy social tracking tools lose access. The game has changed for digital investigators.
Threat actors are employing sophisticated social engineering tactics by disguising malicious Linux payloads as legitimate SSH-related files during software package installations. The attack leverages user trust in familiar system utilities, hiding malware within files named to resemble standard Open
Microsoft just took down Fox Tempest, a criminal network that helped hackers sign malware with fake certificates to bypass security. Trust nothing.
Threat actors conducted an aggressive reconnaissance campaign against SonicWall firewall interfaces, generating over 597,000 scanning sessions within a nine-day period. This massive scanning operation targeted publicly exposed SonicWall management interfaces, likely seeking vulnerable devices for ex
23andMe is facing a major lawsuit following allegations that the genetic testing company attempted to conceal a significant data breach exposing sensitive DNA and ancestry information of millions of users. The lawsuit claims 23andMe failed to promptly disclose the breach, implement adequate security
AI-powered security research just exposed critical macOS flaws. Anthropic’s Mythos model helped discover vulnerabilities that bypass Apple’s memory protection.