Hasbro Data Breach Exposes Employee Personal Information Following Cyberattack
Toy and game giant Hasbro has disclosed a data breach impacting employee personal information, following earlier disruptions caused by a cyberattack.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,175 stories synthesized.
Toy and game giant Hasbro has disclosed a data breach impacting employee personal information, following earlier disruptions caused by a cyberattack.
Malvertising campaigns are increasingly sophisticated, shifting from deceptive ad content to complex, multi-stage redirect chains and cloaking techniques that hide malicious activity.
Microsoft details the TerminalFix campaign, a sophisticated multi-stage attack using compromised websites, steganography, and reverse tunnels to gain persistent network-level proxy access.
Key findings • 19 malicious npm packages were disclosed simultaneously at 03:31 UTC on August 29, 2026. • All packages were assigned a Critical severity rating. • The burst included both …
Key findings • 40 malicious npm packages were disclosed on August 29, 2026. • All advisories were published within a single minute at 00:31 UTC. • 10 of the packages shared the grafeno- p…
Key findings • 40 malicious npm packages disclosed within an 18-minute window on August 28, 2026 • High-profile package @7nohe/openapi-react-query-codegen (151k weekly downloads) was compromi…
Key findings • 20 vulnerabilities disclosed across MongoDB Connector for BI, multiple drivers, and core services. • High-severity flaws include memory-safety issues, authentication bypass, an…
Key findings • Ten vulnerabilities disclosed in TP-Link devices between August 24-28, 2026, including high-severity command injection and DoS flaws. • Multiple Archer routers vulnerable to co…
Key findings • 25 incorrect access control vulnerabilities disclosed for Totolink T6 router on August 28, 2026. • All flaws affect firmware version 4.1.5cu.748_B20211015, allowing unauthentic…
Key findings • 16 vulnerabilities disclosed across multiple IBM products on August 28, 2026. • IBM Langflow OSS is heavily impacted with eight vulnerabilities, including critical code executi…
Key findings • Eight vulnerabilities disclosed simultaneously for IBM Langflow OSS, impacting versions 1.0.0 through 1.11.1. • Critical flaws include arbitrary code execution and OS command i…
New research introduces 'Perturbation Probing,' a method to diagnose LLM safety vulnerabilities, finding that AI safety mechanisms reside in a thin neural layer susceptible to manipulation.
A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains, occurring after Cosmos Labs was aware of the widespread vulnerability.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack impacted a standalone system containing information on investigation targets, with the ransomware group Qilin claiming responsibility.
Key findings • 16 CVEs disclosed between Aug 25-28, 2026, affecting GIMP, Nokogiri, Dia, file-roller, libsoup, and gdk-pixbuf. • Multiple GIMP image parsing plugins vulnerable to DoS via heap…
Key findings • Four medium-severity vulnerabilities disclosed together in GIMP image parsing plugins. • Flaws include heap out-of-bounds reads and stack out-of-bounds accesses in file-psd, fi…
Key findings • Microsoft Edge: One high and six medium severity vulnerabilities disclosed on August 28, 2026. • Vulnerabilities include type confusion, LLM prompting issues, origin validation…
Kidney dialysis provider DaVita will pay $15 million to settle class action lawsuits stemming from a 2025 ransomware and data theft incident attributed to the Interlock gang, impacting nearly 2.7 million individuals.
An international wave of law enforcement actions has targeted major cybercrime syndicates and state-sponsored hacking groups, leading to arrests, asset seizures, and disruption of critical infrastructure espionage.
Researchers have identified 19 malicious browser extensions for Chrome and Edge containing code designed to steal cryptocurrency wallet secrets and drain funds.
The TITAN ransomware group claims to employ an AI system capable of analyzing 700GB of stolen data per hour, significantly accelerating its extortion tactics.
A former Defense Intelligence Agency IT specialist has pleaded guilty to leaking classified information to a foreign government after being caught in an FBI sting operation.
The looming threat of quantum computers breaking current encryption necessitates proactive cryptographic inventory and migration to quantum-resistant algorithms, with regulatory deadlines fast approaching.
A widespread phishing operation is using SVG files disguised as voicemails to evade email security, impacting thousands of organizations.