Pwn2Own Berlin 2026 Awards $1.3M For 47 Zero-Days
Pwn2Own Berlin 2026 wraps up: $1.3M paid out for 47 zero-days. DEVCORE takes Master of Pwn with $505K. Three intense days of enterprise exploits.
Pwn2Own Berlin 2026 wraps up: $1.3M paid out for 47 zero-days. DEVCORE takes Master of Pwn with $505K. Three intense days of enterprise exploits.
The Handala hacking group has claimed responsibility for breaching California Water Service (Cal Water), one of the largest investor-owned water utilities in the United States. The group alleges exfiltration of sensitive data and threatens to release it publicly. This incident adds to growing concer
A critical vulnerability in the Linux kernel, tracked as CVE-2024-43503 and dubbed “DirtyClone,” allows local attackers to escalate privileges to root level. This marks the fourth significant kernel flaw discovered in just six weeks, affecting multiple Linux distributions. The vulnerability resides
A sophisticated phishing campaign is targeting Signal users, particularly journalists and activists, attempting to steal backup recovery keys that would grant attackers access to encrypted message histories. The attack leverages social engineering tactics mimicking official Signal communications, ex
Google plans to fundamentally redesign its search engine with agentic AI capabilities by 2026, introducing autonomous agents that can perform multi-step tasks on behalf of users. This transformation raises critical cybersecurity concerns around data privacy, authentication, API security, and the exp
Citrix has disclosed six critical vulnerabilities affecting NetScaler ADC and Gateway products that could enable denial-of-service (DoS) attacks and memory corruption exploits. The vulnerabilities, ranging from CVE-2025-22392 to CVE-2025-22397, impact multiple NetScaler versions and require immediat
OpenAI has introduced Lockdown Mode for ChatGPT, a new security feature designed to defend against prompt injection and data exfiltration attacks. This opt-in mode restricts the AI’s ability to process external content, click links, and execute certain commands that attackers exploit to manipulate m
New TencShell malware gives attackers complete remote control of infected systems—full screen access, browser data theft, and UAC bypass capabilities detected
Researchers have demonstrated a novel AI worm capable of carrying its own lightweight language model to infected systems, enabling autonomous decision-making without relying on external infrastructure. This self-contained approach allows the malware to operate completely offline, evade traditional d
Attackers are reviving the Evil MSI (Microsoft Installer) technique, leveraging BASE64 encoding and statistical obfuscation to bypass detection mechanisms. This campaign exploits Windows Installer’s legitimate functionality to execute malicious payloads while evading traditional signature-based secu