737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure.

The extensions, publi… Continue reading 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

Posted in Uncategorized

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords.

The weakness affected encrypted r… Continue reading OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

Posted in Uncategorized

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerab… Continue reading Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Posted in Uncategorized

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.

Threat in… Continue reading Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Posted in Uncategorized

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.

The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS sc… Continue reading SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

Posted in Uncategorized

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak.

The vulnerability, rooted in Microsoft Defend… Continue reading ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Posted in Uncategorized

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.

The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on … Continue reading Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Posted in Uncategorized