Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions
2+ hour, 54+ min ago (654+ words) A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access. The campaign turns excitement around game footage and a forthcoming official video into a route for installing…...
Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds
4+ hour, 9+ min ago (722+ words) Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search results, copied websites and free-download lures to place dangerous Java files in front of players....
Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks
4+ hour, 59+ min ago (419+ words) TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The flaws could allow nearby attackers to run arbitrary commands with root privileges, potentially leading to full device compromise and attacks against devices connected to the…...
Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect PAN
6+ hour, 51+ min ago (444+ words) A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint agent used across thousands of enterprise networks worldwide. The disclosure, published through a dedicated research site, has reignited debate…...
768 Leaked Corporate AWS Keys Remain Active With Full Administrator Access
21+ hour, 31+ min ago (600+ words) A new cloud security investigation from Truffle Security has found that 768 publicly exposed AWS credentials still provide full administrative control over corporate AWS environments. The findings highlight a persistent failure in credential rotation, secret management, and cloud account monitoring. Truffle…...
Microsoft Teams' New Policy Lets Admins Automatically Block Meeting Bots
18+ hour, 21+ min ago (531+ words) Microsoft is rolling out a fresh line of defense against unwanted digital eavesdroppers in virtual meetings. The tech giant confirmed that Microsoft Teams will soon let administrators automatically block identified external meeting bots from entering meetings, closing a gap that…...
Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild
18+ hour, 10+ min ago (421+ words) CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user. The vulnerability affects Zimbra installations in…...
New Mysterious AI Model Dubbed Ox Alpha With Free 100 Trillion Tokens a Day for Coders
21+ hour, 27+ min ago (469+ words) A mysterious AI system named Ox Alpha has sparked intense speculation across the developer community after appearing on OpenRouter as a free “stealth model” aimed at coding, long-running AI agents, and production workloads. The identity of its developer remains undisclosed....
Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data
21+ hour, 32+ min ago (618+ words) Kimsuky has been linked to a new espionage campaign that turns a Chrome extension into a quiet Gmail collector. The operation begins with convincing phishing emails and ends with attackers gaining access to messages, attachments, and a victim’s computer. Its…...
WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks
22+ hour, 6+ min ago (433+ words) A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks. The flaw has a CVSS severity score of 9.8. It can allow unauthenticated attackers to upload malicious files, execute…...