A flaw in Adobe’s Acrobat Chrome extension could let websites access WhatsApp Web content rendered in the browser, underscoring how sensitive data can surface after encryption has already done its job.
A newly disclosed SharePoint Server flaw cluster shows how an exposed enterprise portal can move from a single HTTP request to remote code execution and, in some deployments, lingering persistence.
When automated traffic overtakes human traffic, captcha stops looking like a simple checkpoint and starts looking like a fragile control built for a different era.
ANY.RUN has added in-browser data inspection to its Interactive Sandbox, a move that targets the runtime tricks behind redirect-heavy phishing pages and post-load DOM changes.
Cloudflare and major browser makers are exploring PACTs, a protocol meant to help separate legitimate traffic from bots without relying only on brittle signals like IP reputation.
A malicious VBScript lure dressed up as a document shows how trusted chat channels can carry administrative tools into the wrong hands.
A leak-feed allegation against icsecurity.com shows how modern extortion now trades as much on pressure and reputation as on verified technical compromise.
A ransomware-themed post named a healthcare site and attached a long incident string, but the publicly visible evidence supports only an extortion claim - not a confirmed breach.
A new traffic balance puts automation ahead of people in HTML page requests, forcing defenders to rethink what a "visitor" really means.
Traffic measurements show automated bots now account for 57.5% of HTTP requests to HTML pages, a shift that forces security teams to rethink what “normal” web activity looks like.
A reported 6 million-user jump since 2024 is less about one app’s popularity than about how browser choice screens can change user behavior inside a regulated ecosystem.
Underminr highlights a familiar weakness in web infrastructure: if attackers can bend request routing inside trusted delivery systems, they may be able to hide malicious activity behind a brand people already trust.
CVE-2026-42897 has pushed Exchange operators into mitigation-first mode, with temporary controls now doing the job a patch would normally handle.
A banking site’s trusted ad script quietly handed logged-in session data to Temu, exposing a regulatory and security blind spot.
Google’s latest Chrome update quietly arms users and developers against hidden trackers and drive-by exploits by supercharging lazy loading for video and audio.
A groundbreaking update to OWASP ZAP brings elusive browser-based vulnerabilities into the security spotlight.
Google bets big on Merkle Tree Certificates to outsmart quantum codebreakers and keep HTTPS lightning-fast.