Tricks and Treats: GHOSTPULSE’s new pixel-level deception
Update This research covers an update to stage 2 of GHOSTPULSE, originally disclosed by Elastic Security Labs in October 2023. Key takeaways
Update This research covers an update to stage 2 of GHOSTPULSE, originally disclosed by Elastic Security Labs in October 2023. Key takeaways
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said…
Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a fraudulent request that appeared to…
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious…
Ravie LakshmananSep 11, 2026Vulnerability / Cyber Attack PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were…
Kiteworks has announced the acquisition of AI data security company Bonfy.AI, a move aimed at extending real-time policy enforcement over sensitive data exchanged by both…
About four or five years ago, friend and fellow bug bounty hunter Sam Curry asked if I had “ever thought about what was possible to…
Use Python to make the attack repeatable Manual probing is valuable for discovery, but it is a poor regression method. A small Python harness can…
As cloud and AI development continues to grow and change at an unprecedented pace, organizations must prioritize securing these environments at scale. Traditional approaches to…
Introduction We’re excited to introduce a new chapter in our security bounty program on HackerOne that we soft launched in December 2024. Elastic is now…
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming…