The Hidden Danger of SVG Files with Embedded JavaScript: Zero-Click Execution
SVG files aren’t just images—they can execute JavaScript, load external scripts, and hide malicious code through encoding. In certain contexts,…
SVG files aren’t just images—they can execute JavaScript, load external scripts, and hide malicious code through encoding. In certain contexts,…
Cybercriminals are increasingly weaponizing SVG files to deliver hidden JavaScript and phishing payloads, bypassing traditional defenses and posing a serious…
Bouygues Telecom has confirmed a cyberattack exposing the personal and banking details of 6.4 million customers. The breach, reported to…
Pandora and Chanel hit by Salesforce-related data breaches. ShinyHunters used social engineering to steal customer data, sparking concerns over third-party…
A critical zero-day exploit chain named ToolShell is actively targeting on-premises SharePoint servers, enabling remote code execution and persistent access.…
Operation Eastwood dismantled NoName057(16), a pro-Russian DDoS network targeting Ukraine and its allies. Coordinated by Europol and Eurojust, the global…
Join us at Swiss Cyber AI 2026 in Lugano, where industry leaders will explore the intersection of artificial intelligence and…
A new phishing technique mimics an Excel file interface with a "Download ALL" button. Users are tricked into entering credentials,…
North Korea’s Lazarus Group escalates its Contagious Interview campaign with XORIndex malware in npm packages, targeting developers and crypto holders…
Fortinet has released a critical security patch for FortiWeb addressing CVE-2025-25257, a high-severity SQL injection vulnerability that allows unauthenticated attackers…