New research shows CSS-only payloads in HTML email can break webmail isolation in Outlook, Gmail and others to steal passwords, tokens and hijack UI flows.
A new npm supply-chain campaign planted nearly 800 AI-generated packages that install a cross-platform RAT and infostealer on Windows, macOS and Linux systems.
Researcher Malcolm Stagg unveils NatJack, a NAT flaw that lets adjacent attackers hijack TCP sessions, spoof DNS and exhaust NAT tables on major platforms.
ICE is accessing credit card application data through commercial data brokers and Thomson Reuters CLEAR, bypassing warrants and raising privacy alarms.
Commercial sites are hiding prompt injection payloads in Ask AI buttons, quietly poisoning LLM memory to skew recommendations and challenge security teams.
Forescout found 4,407 internet-facing Rockwell PLCs, including 22 in US cities hit by recent water cyberattacks, highlighting urgent OT exposure risks.
At Black Hat USA 2026, a Palo Alto Networks researcher showed a PoC chain achieving C2-style control in ChatGPT's sandbox, exposing emerging AI runtime risks.