OpenSSL HollowByte Memory Leak Vulnerability
Eleven bytes are enough to force a weak OpenSSL server to use up to 131 KB of RAM. After that, it waits for a message that never comes. Following a sudden drop, the code...
A major leak has struck documents tied to the construction of India’s largest nuclear power plant. Alleged engineering-system blueprints, supplier details, inspection reports, and insurance papers have all surfaced in the public domain. The...
Robot vacuums have long roamed our homes unattended. Yet on certain Shark models, the cleaning came bundled with an unnoticed doorway for strangers. A security researcher uncovered a critical vulnerability that allows commands to...
Home cameras rarely stray beyond the local network. Nevertheless, vulnerabilities in the TP-Link Kasa EC70 and EC71 allow an attacker already inside that network to intercept administrator credentials and glean the device’s location. CVE-2026-9770:...
A plain archive file can easily turn into a bad hacking tool. Luckily, the maker of 7-Zip just launched version 26.02 to fix a huge flaw in XZ file tasks. During a real attack,...
The security firm Searchlight Cyber just found a major flaw inside the core WordPress code. This remote code execution flaw does not require any login steps. Any rogue user can run harmful code on...
Microsoft has announced the date after which millions of Windows 11 devices will be left without protection. The corresponding notice has already appeared in the Windows message center. Who Is Affected and Who Is...
The standard synchronization feature in Google Chrome can quietly transform your browser into a surveillance tool. Furthermore, an attacker requires no malicious software or technical expertise. They merely need brief physical access to another...
A mundane password prompt can swiftly transform your macOS desktop into a perilous snare. Specifically, a novel malicious program named ClickLock completely paralyzes the operating system. It persistently halts all functionality until the owner...
Two leaders of the notorious Scattered Spider hacking syndicate recently received severe prison sentences. Specifically, a judge sentenced the hackers to five years and six months for their digital assault on Transport for London...
Since late April 2026, compromised websites have been distributing a new modular malware with the curious name “TELEPUZ” through the ClickFix scheme. According to Elastic, the attackers replace a familiar error-fix prompt with instructions...
Merely twelve days after the first fully automated data-encryption attack came to light, Ant Group has unveiled a free tool designed to halt dangerous artificial intelligence commands before they execute. Developed by Ant Group’s...
From Assistant to Orchestrator Artificial intelligence no longer merely whispers isolated commands to hackers. Instead, it orchestrates nearly the entire assault. It manages everything from pinpointing vulnerabilities to traversing networks and exfiltrating data. Recently,...