Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit.
The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek.
Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit.
The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek.
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.
The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek.
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek.
Other noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas.
The post In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs appeared first on SecurityWeek.
The cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics.
The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek.
It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities.
The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek.
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor.
The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek.
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
The post Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets appeared first on SecurityWeek.
CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.
The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek.
A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators.
The post New Enterprise-Ready MCP Specification Brings New Security Challenges appeared first on SecurityWeek.