Government Domains Weaponized by Malware
Researchers have discovered a campaign using hijacked Brazilian government websites and authenticated emails to distribute malware.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
Researchers have discovered a campaign using hijacked Brazilian government websites and authenticated emails to distribute malware.
A legacy rootkit reappears in Taiwan alongside a sophisticated new backdoor that executes commands from the Windows logon screen.
New data shows cybersecurity teams are rapidly integrating AI tools despite significant governance and detection shortcomings.
CISA mandates federal agencies secure Oracle E-Business Suite systems by Saturday to mitigate active exploitation risks.
AI can accelerate vulnerability discovery, but the core of offensive security remains the ability to verify technical reality.
The UAT-11795 threat actor is deploying the Starland RAT via trojanized installers to harvest credentials and crypto assets.
Procurement often prioritizes flashy AI demos over security, leaving organizations vulnerable to physical and digital risks.
A configuration oversight in SharkNinja's AWS integration allows unauthorized remote commands on connected robot vacuums.
A new threat actor is compromising corporate networks and deploying encryption in under one day using advanced persistence tools.
F5 has issued an urgent series of patches addressing eight critical and high-severity vulnerabilities across its NGINX and BIG-IP lines.
OpenAI is deploying an automated red-teaming model to aggressively stress-test its systems against persistent prompt injection risks.
The rise of AI-driven vulnerability discovery is forcing a fundamental rethink of traditional, schedule-based security remediation.
A surge in procurement bans across China's elite cybersecurity sector reveals a push to sanitize military contract bidding processes.
Multiple cybersecurity vendors release urgent updates to address critical vulnerabilities in widely used enterprise protection tools.
A critical 9.8 severity vulnerability in Zoom's Windows desktop client exposes millions of users to potential account hijacking.
Modern internet protocols and the rise of AI workflows are challenging the effectiveness of traditional network-centric security.
Mozilla, Google, Adobe, and VMware issue urgent security patches to address a wave of critical vulnerabilities across major platforms.
Researchers are moving beyond theoretical AI capabilities, building automated pipelines to find live vulnerabilities in software.
A sophisticated supply chain attack used legitimate GitHub pipelines to push malicious code via the AsyncAPI npm namespace.
New findings reveal that compromised credentials are now the primary catalyst for ransomware breaches, eclipsing software flaws.