An Austrian court has convicted a man of planning to attack a Taylor Swift concert in Vienna nearly two years ago. He was sentenced to 15 years in prison The ...
The method, known as FROST – short for "fingerprinting remotely using OPFS-based SSD timing" – focuses on how different processes compete for storage access. That competition ...
By discreetly measuring EM leaks and SSD operations, attackers leveraging the FROST attack can effectively spy on browser activity from a single open tab.
FROST exploits the Origin Private File System (OPFS), a browser API that lets websites create and store files on a user's ...
Sometime in late May 2026, a poisoned update slipped into the @antv family of JavaScript visualization libraries, the ...
Now sites have a new way to spy on their visitors: measuring subtle interactions with their solid-state drives. The technique ...
GlassWorm poisoned 300 GitHub repositories since 2025, enabling supply chain attacks against developers and organizations.
Disrupts AI-powered exploit-driven attacks earlier in the attack chainEnables security teams to prioritize remediation based on real attacker activity—not severity scoresAutomatically translates explo ...
Ghost CMS SQL injection campaign has compromised 700+ websites — including Harvard University, Oxford University, and DuckDuckGo — using a CVSS 9.4 flaw to inject ClickFix malware lures that trick ...
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.
Developer platform Socket says a malware called TrapDoor is targeting crypto and AI developers across npm, PyPI and Crates, aiming to steal crypto wallet info and browser data.