ARTICLES LIST 2026 2025 2024 2023
DATE |
NAME | Info |
CATEG. |
WEB |
|
30.8.26 |
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor | Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix , that aims to trick users into running a malicious command in | Virus | The Hacker News |
|
30.8.26 |
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE | Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. | Vulnerebility | The Hacker News |
|
30.8.26 |
Android 17 adds ECH support to make web browsing harder to track | Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks. | OS | BleepingComputer |
|
30.8.26 |
Australia arrests alleged TeamPCP hackers behind supply-chain attacks | Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. | BigBrothers | BleepingComputer |
|
30.8.26 |
Microsoft rolls out fix for Windows 11 crashes, gaming issues | Microsoft has started rolling out a permanent fix for a known issue that causes system crashes and gaming issues on Windows 11 devices. | OS | BleepingComputer |
|
30.8.26 |
Carhartt data breach exposes information of 12.9 million accounts | The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. | Incindent | BleepingComputer |
|
30.8.26 |
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday | CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. | Vulnerebility | BleepingComputer |
|
30.8.26 |
ATF confirms “major incident” after recent Qilin breach claims | ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. | Incindent | BleepingComputer |
|
30.8.26 |
Critical Avada WordPress theme flaw enables zero-click RCE | A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. | Exploit | BleepingComputer |
|
30.8.26 |
New GPUThor attack defeats NVIDIA ECC protection for root access | A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. | Attack | BleepingComputer |
|
30.8.26 |
Meta agrees to $18 billion settlement over teen social media harms | Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. | Social | BleepingComputer |
|
30.8.26 |
Boston Scientific says cyberattack disrupted operations globally | Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. | Incindent | BleepingComputer |
|
30.8.26 |
Hackers target Microsoft SharePoint RCE chain with PoC exploit | Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. | Exploit | BleepingComputer |
|
30.8.26 |
FBI disrupts proxy network enabling Chinese espionage operations | The FBI has disrupted infrastructure associated with a technical "quartermaster" that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. | BigBrothers | BleepingComputer |
|
30.8.26 |
Snowflake ends service-account passwords. Now comes the hard part | Snowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. | Hack | BleepingComputer |
|
29.8.26 |
Ubiquiti patches three max severity security vulnerabilities | Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. | Vulnerebility | BleepingComputer |
|
29.8.26 |
Microsoft tests new privacy controls for Windows 11 desktop apps | Microsoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. | OS | BleepingComputer |
|
29.8.26 |
Hackers now exploit critical Gitea flaw in code injection attacks | Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). | Exploit | BleepingComputer |
|
29.8.26 |
LACMA data breach last year exposed social security and medical data | The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. | Incindent | BleepingComputer |
|
29.8.26 |
Hackers abuse npm mirrors to host phishing redirect pages | Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. | Phishing | BleepingComputer |
|
29.8.26 |
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes | A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. | Phishing | BleepingComputer |
|
29.8.26 |
Massive DDoS attack disrupts Norway’s government digital services | A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. | Attack | BleepingComputer |
|
29.8.26 |
Hospital operator Nutex Health says data stolen in cyberattack | Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. | Incindent | BleepingComputer |
|
29.8.26 |
Microsoft PowerToys adds Alt+Tab-style switching for an app's windows | Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. | OS | BleepingComputer |
|
29.8.26 |
WhatsApp adds stronger two-step verification, multiple passkeys | WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. | Social | BleepingComputer |
|
29.8.26 |
Hackers breached over 270 Zimbra servers in ongoing attacks | Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. | Incindent | BleepingComputer |
|
29.8.26 |
Police arrests dozens of suspects in global cybercrime crackdown | Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. | BigBrothers | BleepingComputer |
|
29.8.26 |
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices | An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. | Vulnerebility | BleepingComputer |
|
29.8.26 |
Hackers target WordPress sites in miniOrange auth bypass attacks | Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. | Vulnerebility | BleepingComputer |
|
29.8.26 |
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network | Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same | Incindent | The Hacker News |
|
29.8.26 |
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable | Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. | Cryptocurrency | The Hacker News |
|
29.8.26 |
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication | Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the | Vulnerebility | The Hacker News |
| 28.8.26 | Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers | Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is | OS | The Hacker News |
| 28.8.26 | ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known | Exploit | The Hacker News |
| 28.8.26 | 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code | Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six | Cryptocurrency | The Hacker News |
| 28.8.26 | Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth | Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU , | Vulnerebility | The Hacker News |
| 28.8.26 | Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL | ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring | Vulnerebility | The Hacker News |
| 28.8.26 | China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access | VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics ( ZBT ), | Vulnerebility | The Hacker News |
| 28.8.26 | Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server | cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), | Vulnerebility | The Hacker News |
| 28.8.26 | PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions | PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF | Exploit | The Hacker News |
| 28.8.26 | APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations | Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye | APT | The Hacker News |
| 28.8.26 | Threat landscape for industrial automation systems. Q2 2026 | The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems. | ICS | SECURELIST |
| 28.8.26 | OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face | OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last | AI | The Hacker News |
| 28.8.26 | Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE | Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow | Vulnerebility | The Hacker News |
| 28.8.26 | Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers | Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. | Hack | The Hacker News |
| 28.8.26 | Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks | The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in | Hack | The Hacker News |
| 28.8.26 | Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools | Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT . "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. | Virus | The Hacker News |
| 28.8.26 | GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address | Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware | Virus | The Hacker News |
| 27.8.26 | New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access | Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. | Attack | The Hacker News |
| 27.8.26 | CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. | Exploit | The Hacker News |
| 27.8.26 | TikTok reaches $400M settlement with US over COPPA violations | The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). | Social | BleepingComputer |
| 27.8.26 | ReliaQuest confirms failed data-theft attack after ShinyHunters breach | Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. | Incindent | BleepingComputer |
| 27.8.26 | Microsoft Teams now lets admins block external bots from meetings | Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. | OS | BleepingComputer |
| 27.8.26 | South Korean startup platform breach exposes key management failures | A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. | Incindent | BleepingComputer |
| 27.8.26 | Microsoft: August updates break printing, PDF export in WPF apps | Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. | OS | BleepingComputer |
| 27.8.26 | CISA orders urgent patching of actively exploited Zimbra flaw | The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. | Exploit | BleepingComputer |
| 27.8.26 | Microsoft shares temporary fix for Windows 11 gaming issues | Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. | OS | BleepingComputer |
| 27.8.26 | ToxicPanda Android malware uses VPN permissions to block Google Play | The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. | Virus | BleepingComputer |
| 27.8.26 | FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations | The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司). | BigBrothers | The Hacker News |
| 27.8.26 | Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler | Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore , an | Virus | The Hacker News |
| 27.8.26 | NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions | Cybersecurity researchers have disclosed details of a new adversary-in-the-middle ( AitM ) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. | Hack | The Hacker News |
| 27.8.26 | CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted | ICS | The Hacker News |
| 26.8.26 | Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code | The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. | Vulnerebility | The Hacker News |
| 26.8.26 | Exploits and vulnerabilities in Q2 2026 | This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks. | Exploit | SECURELIST |
| 26.8.26 | Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine | The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never | AI | The Hacker News |
| 26.8.26 | Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests | Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, | AI | The Hacker News |
| 26.8.26 | OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation | OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence | AI | The Hacker News |
| 26.8.26 | INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown | An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 | BigBrothers | The Hacker News |
| 26.8.26 | Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode | An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER , that stays inert in | Virus | The Hacker News |
| 26.8.26 | Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched | Exploit | The Hacker News |
| 26.8.26 | Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes | Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. | AI | The Hacker News |
| 26.8.26 | U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches | The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of- | ICS | The Hacker News |
| 25.8.26 | A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw | Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the | AI | The Hacker News |
| 25.8.26 | WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android | Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users | Social | The Hacker News |
| 25.8.26 | Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode | Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model | Vulnerebility | The Hacker News |
| 25.8.26 | Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows | Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets | Phishing | The Hacker News |
| 25.8.26 | 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages | Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for | CyberCrime | The Hacker News |
| 25.8.26 | E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands | Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers ( DDRs ) to deliver two | Virus | The Hacker News |
| 25.8.26 | Escape found the same XSS in two AI chatboxes. The vulnerability was in the Markdown renderer. | Weeks apart, at two unrelated companies, Escape's AI pentesting agent found the same stored XSS. Both had shipped a customer-facing chat where the model emits Markdown and the frontend renders it with raw HTML enabled and no sanitizer, so anything the model can be made to say executes in the browser of whoever reads the transcript next. | AI | ESCAPE |
| 25.8.26 | Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | VulnCheck’s Initial Access Intelligence team shipped an exploit last week chaining two recently disclosed Microsoft SharePoint CVEs that, when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers: | Exploit | VULNCHECK |
| 25.8.26 | What is EvilTokens?: The PhaaS Platform That Tells Attackers What to Do After They Get In | As competition in the underground phishing market increases, so does the quality of the products and services offerings, particularly among the Phishing as a Service (PhaaS) category. EvilTokens is completely reshaping how PhaaS affiliate programs operate: rather than offering initial access alone, it also provides malicious analytics services informed by operator experience and AI-driven insights. | Phishing | FLARE.IO |
| 25.8.26 | Extended Rapid Response: Zimperium Identifies RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile | The recent research on The Growing Threat of Browser-in-the-Browser (BitB) Recruitment Scams highlights an escalating trend in social engineering: threat actors impersonate real HR personnel across multiple well-known companies to execute highly convincing, interview-themed phishing attacks. By scraping public profile data, attackers craft hyper-realistic scheduling flows designed to bypass traditional user skepticism. | Spam | ZIMPERIUM |
| 25.8.26 | PSD3, PSR and the Rise of Privacy-Preserving Behavioural Analytics | Fraud has changed. Controls for a world of stolen credentials, compromised accounts, and unauthorised transactions need to be revisited, because today's reality is different. Customers are manipulated into authorising payments themselves through scams, social engineering, remote access tools (RATs), malware, and impersonation attacks. | CyberCrime | THREATFABRIC |
| 25.8.26 | VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | NOTE: This research originated from an interaction with the Lynx Ransomware Group, which enabled me to thoroughly explore the Veeam CVE Exploit history. As a result, I discovered a previous exploit that predates the latest Veeam vulnerability. I have also made a quick ATTACK TTP MATRIX dedicated for Veeam Backup & Replication | Vulnerebility | THEREVENFILE |
| 25.8.26 | The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it | Two project-flow extensions sit quietly for five minutes after you open your editor. The Kanban board renders, the webview loads, everything looks like a normal project-management tool. Then, once the IDE has settled and the developer has moved on to something else, a setTimeout fires. The extension reaches out to a free DuckDNS subdomain over plain HTTP, grabs a JavaScript file, and runs it with new Function. | Hack | YEETH SECURITY |
| 25.8.26 | Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access | Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign | Vulnerebility | The Hacker News |
| 25.8.26 | Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP | Exploit | The Hacker News |
| 25.8.26 | Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning | Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by | Virus | The Hacker News |
| 24.8.26 | Imobiliare.ro, Klark.ai, Fortinet VPN, E-Commerce Skimming, and Solimut SQLi | SOCRadar Dark Web Team identified several new underground posts involving alleged database leaks, exposed remote access, and access-for-sale activity. The findings include an alleged Imobiliare.ro user database sale, administrative Fortinet SSL-VPN access tied to a UAE hotel reservation firm, an alleged Klark.ai data leak, a U.S. e-commerce iframe skimming operation, and alleged SQL injection access affecting Solimut Mutuelle de France. | CyberCrime | SOCRADAR |
| 24.8.26 | Cisco Crosswork, Secure Workload CVEs Patched | Cisco released security updates for Cisco Crosswork and Cisco Secure Workload, addressing nine vulnerabilities across the two product families. | Vulnerebility | SOCRADAR |
| 24.8.26 | CVE-2026-19478: GitLab GraphQL Flaw Exploited | GitLab has patched CVE-2026-19478, a critical code injection vulnerability affecting self-managed Community Edition (CE) and Enterprise Edition (EE) instances. Under certain conditions, an unauthenticated remote attacker could leverage a GraphQL directive to modify or delete public projects and user data. | Vulnerebility | SOCRADAR |
| 24.8.26 | CVE-2026-69836: Microsoft Entra ID RCE Fixed | Microsoft recently disclosed CVE-2026-69836, a critical Remote Code Execution (RCE) vulnerability in Microsoft Entra ID (formerly Azure Active Directory). Because this issue affected a Microsoft-hosted cloud service, remediation was applied on the backend rather than through a traditional customer patch. | Vulnerebility | SOCRADAR |
| 24.8.26 | ShinyHunters Claims ReliaQuest Breach | A ShinyHunters-associated leak site listed ReliaQuest on August 23, 2026, raising questions about a potential data extortion attempt against the cybersecurity provider. | Incindent | SOCRADAR |
| 24.8.26 | Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain | The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s Activation Lock on stolen devices. | Phishing | SOCRADAR |
| 24.8.26 | Inside the Ecosystem & Operations: LockBit 5.0 Ransomware Group | LockBit began operating independently under the name ABCD ransomware in September 2019, and from the end of December 2019, it established the current LockBit brand by using the .lockbit extension. | Ransom | S2W |
| 24.8.26 | Frequently asked questions about the active threat to Siemens S7 Series PLCs | A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. | AI | TANABLE |
| 24.8.26 | 1 in 20 Stealer Log Victims are Threat Actors | When analysts examine stealer logs, the underlying assumption is that each infected device belongs to a victim. However, cybercriminals are not immune to the same operational mistakes as everyone else. | CyberCrime | FLARE.IO |
| 24.8.26 | The Age of Autonomous Attacks is Here | In July 2026, Hugging Face was breached by an autonomous agent swarm that had broken out of an OpenAI Sandbox and was attempting to succeed at ExploitGym, a cyber benchmark. | AI | FLARE.IO |
| 24.8.26 | July 2026 Threat Trend Report on Ransomware | The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. | Ransom | AHNLAB |
| 24.8.26 | WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords | Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from | Virus | The Hacker News |
| 24.8.26 | Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account | Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management | Vulnerebility | The Hacker News |
| 24.8.26 | Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor | Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed | CyberCrime | The Hacker News |
| 24.8.26 | The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk | Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and | AI | The Hacker News |
| 24.8.26 | A Social Engineering Attempt Against ReliaQuest: What We Found | ReliaQuest was the target of a social engineering attack. While unsuccessful beyond temporarily exposing one identity, the attempt was an important reminder of the persistent tactics of threat actor groups and what all organizations can do to guard against them. We are sharing the full details of this attempt for transparency and so others can learn from this playbook. | Social | RELIAQUEST |
| 24.8.26 | UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit | Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux | APT | The Hacker News |
| 23.8.26 | Hackers infect Android car head units with proxy botnet malware | A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. | Virus | BleepingComputer |
| 23.8.26 | Named Pipes Under Attack: Securing Windows Interprocess Communication | Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. | Hack | BleepingComputer |
| 23.8.26 | New SynkLoader malware pushed in Microsoft Teams phishing campaign | A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. | Virus | BleepingComputer |
| 23.8.26 | Hundreds of leaked AWS keys give full control over corporate accounts | More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. | Hack | BleepingComputer |
| 23.8.26 | Microsoft blames Windows gaming issues on RGB lighting devices | Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. | OS | BleepingComputer |
| 23.8.26 | Is Online Privacy Possible? How Digital Identities Can Help | Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. | Security | BleepingComputer |
| 23.8.26 | Microsoft rolls out Classic Outlook theme for New Outlook users | Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. | OS | BleepingComputer |
| 23.8.26 | CISA orders feds to patch actively exploited TrueConf Server flaws | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. | Exploit | BleepingComputer |
| 23.8.26 | Microsoft patches max severity code execution, privilege escalation flaws | Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. | OS | BleepingComputer |
| 23.8.26 | Hackers abuse FTP server banners to deliver new Windows malware | Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. | Virus | BleepingComputer |
| 23.8.26 | SickKids data breach exposes employee and job applicant info | Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) | Incindent | BleepingComputer |
| 23.8.26 | Hackers poison arrayref Rust crate to push infostealer malware | Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. | Virus | BleepingComputer |
| 23.8.26 | Critical Elementor Pro bug exposes WordPress sites to RCE attacks | A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. | Vulnerebility | BleepingComputer |
| 23.8.26 | How MSPs can catch phishing attacks email filters miss | AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. | Phishing | BleepingComputer |
| 23.8.26 | Citrix urges admins to patch new NetScaler flaws as soon as possible | Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. | Vulnerebility | BleepingComputer |
| 23.8.26 | CISA warns of hackers exploiting critical MLflow vulnerability | The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. | Vulnerebility | BleepingComputer |
| 23.8.26 | New Manic Android malware can exfiltrate data through nearby devices | A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. | Virus | BleepingComputer |
| 23.8.26 | Critical Zimbra RCE flaw now actively exploited in attacks | CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). | Vulnerebility | BleepingComputer |
| 23.8.26 | Microsoft says August Windows updates may cause gaming issues | Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. | OS | BleepingComputer |
| 23.8.26 | OpenAI confirms ChatGPT is down as logins and signups fail | ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. | AI | BleepingComputer |
| 23.8.26 | Rogue ransomware affiliate poses as recovery firm to steal payments | A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. | Ransom | BleepingComputer |
| 23.8.26 | Sakura Internet hack exposes data of up to 1.36 million accounts | Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. | Incindent | BleepingComputer |
| 23.8.26 | Healthtech firm CareCloud data breach impacts 3.7 million patients | U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. | Incindent | BleepingComputer |
| 23.8.26 | Hackers compromise 14,500 Dahua web cameras in 35-day campaign | In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. | Incindent | BleepingComputer |
| 23.8.26 | US warns of AI-powered attacks on Siemens PLCs in critical infrastructure | U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. | AI | BleepingComputer |
| 23.8.26 | US charges Iranian hackers over $3.4 billion intellectual property theft | The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. | BigBrothers | BleepingComputer |
| 23.8.26 | TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit | The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit | Social | The Hacker News |
| 22.8.26 | Password spraying attacks surge 155x as hackers exploit MFA gaps | Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. | Security | BleepingComputer |
|
22.8.26 |
Microsoft fixes known issue causing Windows Defender crashes | Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. | OS | BleepingComputer |
|
22.8.26 |
Critical RCE flaw in Windows IKE Extension now actively exploited | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. | Exploit | BleepingComputer |
|
22.8.26 |
Windows 11 24H2 Home and Pro reach end of support in 2 months | Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. | OS | BleepingComputer |
| 22.8.26 | CISA: Medusa ransomware hit over 500 critical infrastructure orgs | The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. | Ransom | BleepingComputer |
|
22.8.26 |
Comcast turns your Xfinity WiFi into a home motion detector | Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. | Security | BleepingComputer |
|
22.8.26 |
Clop created custom web shell for Windchill data theft attacks | A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. | Ransom | BleepingComputer |
| 22.8.26 | Your Controls Block Known Attacks. What About the Behavior? | Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. | Security | BleepingComputer |
|
22.8.26 |
Microsoft tests faster Windows File Explorer, new context menu | Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. | OS | BleepingComputer |
| 22.8.26 | CISA: Windows Task Host flaw now exploited by ransomware gangs | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. | Ransom | BleepingComputer |
|
22.8.26 |
Microsoft confirms outage affecting search in Microsoft 365 apps | Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. | OS | BleepingComputer |
|
22.8.26 |
Microsoft starts removing WMIC tool used by cybercriminals | Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. | CyberCrime | BleepingComputer |
| 22.8.26 | Hacker claims 3.6 million Azure account records stolen from major companies | A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. | Hack | BleepingComputer |
| 22.8.26 | 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 | Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are | Virus | The Hacker News |
|
21.8.26 |
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot | Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows | OS | The Hacker News |
|
21.8.26 |
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet | Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware | Virus | The Hacker News |
|
21.8.26 |
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 | Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued | Vulnerebility | The Hacker News |
|
21.8.26 |
The invisible passenger in your car | Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun head units. | Virus | SECURELIST |
|
21.8.26 |
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure | A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The | Vulnerebility | The Hacker News |
|
21.8.26 |
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution | Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no | Exploit | The Hacker News |
|
21.8.26 |
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads | The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published | Virus | The Hacker News |
|
21.8.26 |
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts | Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293 , UNC7005 , and UNC5976 . | APT | The Hacker News |
|
21.8.26 |
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure | The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial | AI | The Hacker News |
|
20.8.26 |
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data | Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. | Hack | The Hacker News |
|
20.8.26 |
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE | Cybersecurity researchers have disclosed a critical security flaw in isolated-vm , a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines | Vulnerebility | The Hacker News |
|
20.8.26 |
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers | Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical- | Vulnerebility | The Hacker News |
|
20.8.26 |
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution | A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish | Exploit | The Hacker News |
|
20.8.26 |
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments | Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale | Hack | The Hacker News |
|
20.8.26 |
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification | Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert | Attack | The Hacker News |
|
20.8.26 |
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices | A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and | Virus | The Hacker News |
|
20.8.26 |
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands | Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue | Security | The Hacker News |
|
20.8.26 |
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud | Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," | Virus | The Hacker News |
|
20.8.26 |
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets | A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, | Hack | The Hacker News |
|
20.8.26 |
Pokémon Center data breach exposes customer info, cancels some orders | Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. | Incindent | BleepingComputer |
|
20.8.26 |
Microsoft confirms GitHub is down worldwide | GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. | Security | BleepingComputer |
|
20.8.26 |
Windows Server 2022 reaches end of mainstream support in 60 days | Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. | OS | BleepingComputer |
|
20.8.26 |
Philips and GE investigating Clop ransomware data theft claims | Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data | Ransom | BleepingComputer |
|
20.8.26 |
French tax authority data breach affects 678,000 individuals | The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. | Incindent | BleepingComputer |
|
20.8.26 |
Microsoft working on Defender patch for ShieldBreak zero-day | Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. | OS | BleepingComputer |
|
20.8.26 |
SafePal data breach impacts 39,798 customers, stolen info for sale | Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. | Cryptocurrency | BleepingComputer |
|
20.8.26 |
Anthropic confirms Claude is down in major outage affecting multiple services | Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. | AI | BleepingComputer |
|
20.8.26 |
Telegram Applied for .gram: What It Means for the Threat Landscape | Telegram has applied for the .gram top-level domain through ICANN’s 2026 round. If approved, Telegram usernames could become web-addressable domains with AI-generated websites. | Social | SOCRADAR |
|
20.8.26 |
Can NVD Modernization Keep Pace With AI? | AI can help security teams find vulnerabilities faster. That sounds entirely positive until we consider what happens after those vulnerabilities are found. Every new finding still needs to be validated, enriched, prioritized, communicated, and eventually fixed. | Vulnerebility | SOCRADAR |
|
20.8.26 |
Critical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure | vm2’s sandbox denylist forgot two modules: “os” and “dns.” Under the wildcard config vm2’s own docs recommend, that gap lets sandboxed code read the host process owner’s identity and hijack the host’s DNS with a single call — a change that outlives the sandbox run and never notifies the embedder. Patched in 3.11.6. | Vulnerebility | OX |
|
20.8.26 |
Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive | Two flaws in GitLab’s GraphQL API: one lets any user wipe or alter public projects and user data, the other quietly runs changes using a logged-in user’s own permissions. Self-managed instances from 18.2 through 19.2 need to upgrade now. | Vulnerebility | OX |
|
20.8.26 |
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea | The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther VPN”. | Virus | AHNLAB |
|
20.8.26 |
Beware of phishing emails disguised as requests to review quotes (PhantomStealer) | The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the Attachment. | Virus | AHNLAB |
|
20.8.26 |
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code | Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead | Vulnerebility | The Hacker News |
|
20.8.26 |
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second | Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) | Attack | The Hacker News |
|
20.8.26 |
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior | OpenAI on Tuesday revealed that it paused reinforcement learning ( RL ) training for its latest artificial intelligence (AI) models for two weeks while | AI | The Hacker News |
|
19.8.26 |
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect | StopAndProtect is a newly identified operation that combines file encryption with data theft. The criminals abuse thousands of hacked WordPress websites as their infrastructure – using them to spread the malware, control infected machines, and store stolen documents, screenshots, and activity logs (records created by malware to track its actions, progress, or status during execution). | Hack | CHECKPOINT |
|
19.8.26 |
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs | A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The | APT | The Hacker News |
|
19.8.26 |
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P | Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication- | CyberCrime | The Hacker News |
|
19.8.26 |
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data | Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to | Virus | The Hacker News |
|
19.8.26 |
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. | Exploit | The Hacker News |
|
19.8.26 |
Hunting MacSync Stealer infrastructure through behavioral pivots | MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure. | Virus | Microsoft blog |
|
19.8.26 |
StubMaker RubyGems Campaign Delivers a Windows Infostealer | On August 15, 2026, we discovered newly-published RubyGems packages that installs a multi-stage Windows infostealer malware. This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data. | Virus | OPENSOURCE MALWARE |
|
19.8.26 |
Clop Returns with Custom Implant in Mass-Extortion Campaign | “Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no additional tooling required. | Ransom | RELIAQUEST |
|
19.8.26 |
Hunt Malware & Phishing Threats with ANY.RUN for Proactive Enterprise Security | One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context. Data collection is just the first step – but how do you turn it into findings that lead to proactive protection against malware and phishing? | Security | ANYRUN BLOG |
|
19.8.26 |
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US | Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. | Phishing | ANYRUN BLOG |
|
19.8.26 |
PurpleDelta's Fraudulent Employment Operations | Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. | APT | Recorded Futures |
|
19.8.26 |
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia | Disclosure note: The relevant national CERTs were notified on 10 August 2026, and Dahua's PSIRT was notified regarding the issues that affect devices in all countries observed in this campaign. We appreciate Dahua PSIRT's engagement in reviewing parts of this research ahead of publication. Publication was held until 18 August 2026 under TLP:AMBER. | BigBrothers | HUNT.IO |
|
19.8.26 |
943 Patches Rolled Out With Oracle’s August 2026 Security Update | The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. | Vulnerebility | SECURITYWEEK |
|
19.8.26 |
Chrome, Firefox Updates Patch Dozens of Vulnerabilities | The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. | Vulnerebility | SECURITYWEEK |
|
19.8.26 |
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains | Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. | Virus | SECURITYAFFAIRS |
|
19.8.26 |
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure | Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating | Virus | The Hacker News |
|
19.8.26 |
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data | A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically | ICS | The Hacker News |
|
19.8.26 |
Guarding AI memory | AI memory transforms an AI system from a stateless tool into a learning collaborator. That unlocks powerful experiences, but it also increases the attack surface of the AI system. | AI | Microsoft blog |
|
19.8.26 |
Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. | Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. | Ransom | CHECKPOINT |
|
19.8.26 |
Characterizing the Infrastructure and Behavior of Falcon-branded Extortion Operations | Increased attention has been called to a sustained adversary-in-the-middle (AitM) phishing and vishing operation targeting financial services, professional services, energy and technology organizations since at least April 2026. | CyberCrime | GUIDESECURITY |
|
19.8.26 |
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps | Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to | AI | The Hacker News |
|
19.8.26 |
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets | Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / | Exploit | The Hacker News |
|
19.8.26 |
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 | A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete | Ransom | The Hacker News |
|
19.8.26 |
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files | Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one | AI | The Hacker News |
|
18.8.26 |
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets | Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. | Cryptocurrency | The Hacker News |
|
18.8.26 |
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 | A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than | Security | The Hacker News |
|
18.8.26 |
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers | SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone | Incindent | The Hacker News |
|
18.8.26 |
The Gentlemen ransomware: Inside one of the fastest-growing extortion operations | The Gentlemen grew from affiliate roots into a major ransomware brand. The group's operators appear to have leveraged relationships, expertise, and credibility developed as the ArmCorp affiliate team to accelerate growth after launching their own ransomware-as-a-service (RaaS) operation. | Ransom | BARRACUDA |
|
18.8.26 |
Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Exposure | SOCRadar Dark Web Team identified several new underground posts involving alleged initial access sales and large-scale data exposure. The findings include an alleged RDWeb access listing for an Italian cloud and IT services provider, a claimed GBCSA database sale, an alleged BullyPedex customer and payment dataset, a major SCHUFA credit data claim, and an alleged Firebase-related exposure affecting the Korean food-delivery platform FLY. | CyberCrime | SOCRADAR |
|
18.8.26 |
Closing the IT/OT Gap: GreyMatter’s OT Engineer Teammate Is Here | Industrial environments face a security challenge that traditional tools were never built to solve. IT and OT networks are managed by separate teams with competing priorities—IT protects data, OT keeps production running—yet attacks cross between them without friction. | Security | RELIAQUEST |
|
18.8.26 |
The OWASP LLM Top 10 Was the Warm-Up: What Comes Next | When the OWASP Top 10 for LLM Applications arrived, it did the industry a real service. It gave security teams a stable, vendor-neutral vocabulary for a threat surface that was moving too fast to describe. | AI | IMPERVA |
|
18.8.26 |
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 | In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. | Ransom | Zscaler |
|
18.8.26 |
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited | Vulnerebility | The Hacker News |
|
18.8.26 |
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects | GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software | Vulnerebility | The Hacker News |
|
18.8.26 |
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection | Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public | Hack | The Hacker News |
|
18.8.26 |
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads | A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could | Vulnerebility | The Hacker News |
|
18.8.26 |
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic | Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by | Hack | The Hacker News |
|
17.8.26 |
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access | Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the | OS | The Hacker News |
|
17.8.26 |
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from | BotNet | The Hacker News |
|
17.8.26 |
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware | Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China- | APT | The Hacker News |
|
17.8.26 |
Large-scale DDoS attacks disrupted Threema secure messaging service | Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. | Attack | BleepingComputer |
|
17.8.26 |
New AmnesiaStealer macOS malware hijacks browser sessions via remote control | A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. | Virus | BleepingComputer |
|
16.8.26 |
New Evooo1Bot Linux botnet turns routers into traffic relay nodes | A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. | BotNet | BleepingComputer |
|
16.8.26 |
How Anthropic plans to watermark Claude's AI-generated text | How Anthropic plans to watermark Claude's AI-generated text | AI | BleepingComputer |
|
16.8.26 |
Hackers arrested over €30M bank fraud exploiting service provider flaw | Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. | CyberCrime | BleepingComputer |
|
16.8.26 |
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner | The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. | Exploit | BleepingComputer |
|
16.8.26 |
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI | Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. | AI | BleepingComputer |
|
16.8.26 |
Max severity SAP Commerce Cloud flaw now targeted in attacks | A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. | Vulnerebility | BleepingComputer |
|
16.8.26 |
Shell investigates 'potential incident' after Clop data theft claims | Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. | Ransom | BleepingComputer |
|
16.8.26 |
RingCentral data breach exposed info of 1.6 million accounts | The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. | Incindent | BleepingComputer |
|
16.8.26 |
Data analyst sent to prison for stealing data, extorting employer | A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. | Incindent | BleepingComputer |
|
16.8.26 |
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks | You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." | Mobil | BleepingComputer |
|
16.8.26 |
Ukraine shuts down 94 fraudulent call centers, seize millions in cash | Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. | CyberCrime | BleepingComputer |
|
16.8.26 |
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt | An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. | Ransom | BleepingComputer |
|
16.8.26 |
Hackers breach govt webmail while running parallel crypto fraud | The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. | Cryptocurrency | BleepingComputer |
|
16.8.26 |
Microsoft patches LegacyHive Windows zero-day vulnerability | Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. | Vulnerebility | BleepingComputer |
|
16.8.26 |
AI 'watermark removers' flood the web. Almost none can prove they work. | Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. | AI | BleepingComputer |
|
16.8.26 |
Critical VMware vCenter RCE flaw exploited for reverse SSH access | A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. | Vulnerebility | BleepingComputer |
|
16.8.26 |
Trezor discloses data breach affecting nearly 14,000 customers | Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked | Incindent | BleepingComputer |
|
16.8.26 |
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion | AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. | AI | BleepingComputer |
|
16.8.26 |
White House taps security firms for offensive hack-back operations | A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. | BigBrothers | BleepingComputer |
|
16.8.26 |
WhatsApp rolls out new feature that flags potential scam messages | WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. | Social | BleepingComputer |
|
16.8.26 |
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals | An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. | Hack | BleepingComputer |
|
16.8.26 |
Android malware combo takes out loans and relays victims' credit cards | A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. | Virus | BleepingComputer |
|
16.8.26 |
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts | Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. | Exploit | BleepingComputer |
|
16.8.26 |
Hundreds of fake Chrome VPN extensions route traffic through a proxy | More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. | Hack | BleepingComputer |
|
16.8.26 |
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access | Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. | Attack | BleepingComputer |
|
16.8.26 |
Lazarus hackers exploited Windows zero-day to target defense firms | North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. | APT | BleepingComputer |
|
16.8.26 |
FBI: Hackers target online accounts to steal nude photos | The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. | CyberCrime | BleepingComputer |
|
16.8.26 |
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In | Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. | Security | BleepingComputer |
|
16.8.26 |
Hackers leverage new Microsoft SharePoint exploit in attacks | Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. | Exploit | BleepingComputer |
|
16.8.26 |
Signal adds new security feature to thwart man-in-the-middle attacks | Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. | Hack | BleepingComputer |
|
16.8.26 |
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges | Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. | Vulnerebility | BleepingComputer |
|
16.8.26 |
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse | Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. | OS | BleepingComputer |
|
16.8.26 |
DeadLock ransomware uses blockchain to resist infrastructure takedown | The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. | Ransom | BleepingComputer |
|
16.8.26 |
Sandworm hackers target IT pros with trojanized WireGuard VPN client | Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. | APT | BleepingComputer |
|
16.8.26 |
Cisco warns of ASA and FTD VPN flaw exploited to crash devices | Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. | Exploit | BleepingComputer |
|
15.8.26 |
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees | Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. | Incindent | BleepingComputer |
|
15.8.26 |
Microsoft releases Windows 10 KB5120249 extended security update | Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. | OS | BleepingComputer |
|
15.8.26 |
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days | Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. | OS | BleepingComputer |
|
15.8.26 |
Windows 11 KB5121003 & KB5120240 cumulative updates released | Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. | OS | BleepingComputer |
|
15.8.26 |
Wesco confirms security incident after ExfilSquad claims data theft | Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. | Incindent | BleepingComputer |
|
15.8.26 |
Mozilla updates GPG signing key for Firefox releases after exposure | Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. | Security | BleepingComputer |
|
15.8.26 |
Vague Task, Total Access: When AI Delegation Becomes a Security Risk | AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. | AI | BleepingComputer |
|
15.8.26 |
DDoS attacks over 1 Tbps surged fivefold in the second quarter | Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. | Attack | BleepingComputer |
|
15.8.26 |
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. | Exploit | BleepingComputer |
|
15.8.26 |
Cisco warns of high-severity ClamAV flaws with public exploits | Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. | Exploit | BleepingComputer |
|
15.8.26 |
US and South Korea warn of Gunra ransomware targeting govt agencies | U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. | Ransom | BleepingComputer |
|
15.8.26 |
Hackers breached a small Polish energy plant via private APN last year | Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. | Hack | BleepingComputer |
|
15.8.26 |
BdThemes plugins supply-chain hack creates rogue WordPress admins | A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. | Hack | BleepingComputer |
|
15.8.26 |
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch | A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as | Vulnerebility | The Hacker News |
|
15.8.26 |
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner | A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned . | Vulnerebility | The Hacker News |
|
15.8.26 |
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware | Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS | Hack | The Hacker News |
|
14.8.26 |
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth | The threat actor known as HoneyMyte (aka Mustang Panda ) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious | APT | The Hacker News |
|
14.8.26 |
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers | Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google | Hack | The Hacker News |
|
14.8.26 |
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps | Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview | Phishing | The Hacker News |
|
14.8.26 |
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware | Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a | OS | The Hacker News |
|
14.8.26 |
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit | Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts. | APT | SECURELIST |
|
14.8.26 |
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups | A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program | BigBrothers | The Hacker News |
|
14.8.26 |
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud | The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both | APT | The Hacker News |
|
14.8.26 |
Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE | A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform | Exploit | The Hacker News |
|
14.8.26 |
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure | Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that | Virus | The Hacker News |
|
14.8.26 |
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS | Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's | Virus | The Hacker News |
|
13.8.26 |
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs | Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. | Vulnerebility | SECURITYWEEK |
|
13.8.26 |
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager | The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance | Vulnerebility | SECURITYWEEK |
|
13.8.26 |
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit | Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 ( ... | Exploit | SECURITYAFFAIRS |
|
13.8.26 |
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware | Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Stor ... | Ransom | SECURITYAFFAIRS |
|
13.8.26 |
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job | Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave | APT | SECURITYAFFAIRS |
|
13.8.26 |
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan | China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented wh ... | APT | SECURITYAFFAIRS |
|
13.8.26 |
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch | Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclip ... | Exploit | SECURITYAFFAIRS |
|
13.8.26 |
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud | A previously unseen Android near field communication ( NFC ) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless | Virus | The Hacker News |
|
13.8.26 |
North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring | Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass | APT | The Hacker News |
|
13.8.26 |
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages | NUL1DROPPER, aka Flooding Dropper, is a new downloader targeting mobile SDK installs a RAT to Windows, Mac, and Linux with no install script required | AI | Opensourcemalware |
|
13.8.26 |
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit | It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. | Exploit | CHECKPOINT |
|
13.8.26 |
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack | Check Point Research is tracking a long‑running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked Lazarus group and its latest wave focuses on the defense sector in Europe and India. | Exploit | CHECKPOINT |
|
13.8.26 |
Akira Hits Safe Mode: Ransomware Rebooting Around EDR | After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry. | Ransom | Huntress |
|
13.8.26 |
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme | A new NFC relay malware designated as WindRelay, paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out. | Virus | GROUP-IB |
|
13.8.26 |
WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking | Learn how to mitigate risks tied to a legacy Entra ID endpoint that undermines Smart Lockout, allowing attackers to confirm valid passwords even on MFA-protected accounts. | Hack | VARONIS |
|
13.8.26 |
Armored Likho expands its cyber-espionage toolkit | Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims. | APT | SECURELIST |
|
13.8.26 |
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users | OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. | AI | BleepingComputer |
|
13.8.26 |
New StormEncryptor ransomware used by former Medusa affiliate | A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. | Ransom | BleepingComputer |
|
13.8.26 |
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. | Ransom | BleepingComputer |
|
13.8.26 |
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release | Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) | Exploit | The Hacker News |
|
13.8.26 |
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor | The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw | Exploit | The Hacker News |
|
12.8.26 |
Partners have spoken: Barracuda earns four 2026 CRN Annual Report Card (ARC) Awards | Partner feedback earns Barracuda top honors for support, managed services, partnership, and channel success. | Cyber | BARRACUDA |
|
12.8.26 |
Palacký University strengthens cyber resilience and simplifies compliance | How Barracuda helps one of the Czech Republic’s oldest universities protect on-premises data, simplify recovery and support NIS2 readiness. | Cyber | BARRACUDA |
|
12.8.26 |
Phantom Project: A cybercrime toolkit bundle | How a malware-as-a-service platform combines credential theft, obfuscation and remote access to support identity-focused cybercrime operations | CyberCrime | SOCRADAR |
|
12.8.26 |
August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days | Microsoft’s August 2026 Patch Tuesday release addresses 421 vulnerabilities, including three zero-days. One zero-day was exploited in the wild, while two others were publicly disclosed before fixes were available. | Vulnerebility | SOCRADAR |
|
12.8.26 |
SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching | SAP has addressed CVE-2026-58231, a maximum-severity improper authorization vulnerability in the Data Hub Adapter for SAP Commerce Cloud. The flaw carries a CVSS score of 10.0 and may allow an unauthenticated attacker with network access to execute arbitrary code on an affected system. | Vulnerebility | SOCRADAR |
|
12.8.26 |
Cisco ASA and FTD CVE-2026-20349 Exploited | Cisco has confirmed active exploitation of CVE-2026-20349, a High-severity denial-of-service (DoS) vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) Software. | Exploit | SOCRADAR |
|
12.8.26 |
Top 10 Phishing Kits Used by Cybercriminals | Phishing kits have turned credential theft into a scalable service by packaging fake login pages, hosting, traffic filtering, victim management, and technical support into ready-made platforms. | Phishing | SOCRADAR |
|
12.8.26 |
INC Ransom Targeted 24 Law Firms, but Only 10 are Listed | INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. | Ransom | SOCRADAR |
|
12.8.26 |
Critical Metabase Zero-Day Exploited | Metabase has disclosed a critical zero-day SQL injection (SQLi) vulnerability that can allow unauthenticated attackers to gain administrator access to vulnerable instances. The flaw is rated at maximum severity, and the vendor has confirmed active exploitation. | Exploit | SOCRADAR |
|
12.8.26 |
Steam Customer Data Exposed in CEVA Logistics Cyberattack | A cyberattack on CEVA Logistics, the company that distributes Steam hardware in Europe, may have exposed delivery and order information belonging to some Steam customers. Valve said the incident occurred between July 29 and August 1, 2026, and began notifying potentially affected customers on August 10. | CyberCrime | SOCRADAR |
|
12.8.26 |
Brazil Fiscal Leak, US Fullz, Telecom Access, Endesa IBANs, and Mexico Fortinet Access | SOCRadar Dark Web Team identified several new underground posts involving alleged large-scale data exposure and initial access sales. The findings include an alleged leak of 72 million Brazilian fiscal records, a claimed 1 million record U.S. Fullz dataset, unauthorized access to a major Asian telecom provider, an alleged Endesa Spain IBAN database, and Fortinet-related access to a large Mexican network. | CyberCrime | SOCRADAR |
|
12.8.26 |
Is your security stack actually running? | Adversaries love to make life difficult for defenders. One of the best ways for attackers to operate undetected is to disable security tools on a compromised device. | Security | OKTA |
|
12.8.26 |
New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 | OLIGO Security has identified evidence that TeamPCP was responsible for the first known attack in which AI infrastructure was hijacked into a self-propagating botnet during the ShadowRay 2.0 campaign. Our findings also link the group to activity previously attributed to TA-NATALSTATUS dating back to 2020. | Virus | OLIGO |
|
12.8.26 |
Mirai and Its Heirs: A Decade of Structural Neglect in IoT Security | Nearly ten years after its source code was leaked, Mirai’s methodology is still working largely unchanged. The original botnet scanned the Internet for devices running default credentials and unpatched services, then weaponized them at scale. Its descendants do the same thing against the same device categories: consumer routers, DVRs, and IP cameras. | BotNet | CENSYS |
|
12.8.26 |
Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP | 5 days after 440+ npm packages were compromised, 5 malicious repositories remain live in the wild—and the threat is still active | Virus | OX SECURITY |
|
12.8.26 |
FirewallFalcon Manager: Supply-Chain Backdoors in Underground VPN Infrastructure | What if the tool you use to run your criminal infrastructure is itself criminal infrastructure, and you are the target? FirewallFalcon Manager is presented as a free open-source Linux server management tool for VPN and proxy services. But, beneath the well-polished GitHub repo and feature-rich shell menus lies a multi-layered well hidden and sophisticated attack: | Hack | FLARE.IO |
|
12.8.26 |
Plugged In and Exposed: The Growing Cybersecurity Threat to EV Charging Infrastructure | Publicly exposed EV charging infrastructure remains an unresolved cybersecurity problem. Security practitioner Ken Munro has spent years taking apart the machines that charge electric cars. When asked what actually kept him up at night, he did not point to any one broken device. He pointed at all of them at once. | Security | FLARE.IO |
|
12.8.26 |
Cursor CLI ran untrusted repo code | A repository could execute any command it chose on your machine, as you, the moment you started Cursor's CLI agent in it with -w. It ran before the workspace-trust dialog, and fired even for users who had explicitly passed --sandbox enabled. | AI | MANIFOLD |
|
12.8.26 |
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One | A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services | Hack | The Hacker News |
|
12.8.26 |
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning | A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal | AI | The Hacker News |
|
12.8.26 |
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws | Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic | Vulnerebility | The Hacker News |
|
12.8.26 |
CopyEscape: Taking Over Docker Hosts with docker cp | Imperva Red Team uncovered CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp command. Docker later confirmed that the same CVE also affected sbx cp when copying files out of Docker Sandboxes. | Vulnerebility | IMPERVA |
|
12.8.26 |
Imperva Customers Protected Against XSS2Shell (CVE-2026-64638) in WordPress Core | TL;DR: CVE-2026-64638, dubbed XSS2Shell, is a high-severity WordPress Core vulnerability that begins as a pre-authentication reflected XSS on the login screen and can be chained to PHP code execution when a logged-in administrator is successfully targeted. | Vulnerebility | IMPERVA |
|
12.8.26 |
Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction | Threat monitoring serves as the vital connective tissue of modern security operations. It ensures that every function from triage to response operates effectively. To meet evolving threat challenges, SOC teams and MSSPs must transition from simple log collection to a proactive, intelligence-driven framework. | Security | ANYRUN BLOG |
|
12.8.26 |
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup | Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. | APT | ANYRUN BLOG |
|
12.8.26 |
Inside a Russian-Speaking Operator's Toolkit for Compromising Ukrainian IP Cameras | Disclosure note: Hunt.io notified CERT-UA on July 30, 2026, and held publication for the standard 7-day disclosure window. The affected e-commerce operator was notified via CERT-UA. | APT | HUNT.IO |
|
12.8.26 |
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm | On August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-Hulud linked to TeamPCP. ChainDrop anchored its C2 infrastructure in an Ethereum smart contract, allowing the attacker to rotate domains with a single blockchain transaction and rendering domain-based blocklists ineffective. | Virus | Zscaler |
|
12.8.26 |
Abyssos: Technical Analysis of a New Modular RAT | In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. | Virus | Zscaler |
|
12.8.26 |
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness | It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. | AI | Zscaler |
|
12.8.26 |
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials | On July 31, Microsoft Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch. Microsoft attributes this activity to Storm-2945, a sub-cluster of Midnight Blizzard (also known as APT29, Cozy Bear, NOBELIUM, and BlueBravo), a threat group linked to Russia. | APT | Zscaler |
|
12.8.26 |
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access | Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings | Exploit | The Hacker News |
|
12.8.26 |
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations | Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, | Hack | The Hacker News |
|
12.8.26 |
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code | SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in | Vulnerebility | The Hacker News |
|
12.8.26 |
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access | The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof- | Exploit | The Hacker News |
|
12.8.26 |
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS | Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat | Exploit | The Hacker News |
|
12.8.26 |
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack | Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. | OS | The Hacker News |
|
12.8.26 |
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing | Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and | BotNet | The Hacker News |
|
12.8.26 |
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client | Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken | Social | The Hacker News |
|
12.8.26 |
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands | The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by | APT | The Hacker News |
|
11.8.26 |
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE | Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant | AI | The Hacker News |
|
11.8.26 |
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt | The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data | Ransom | The Hacker News |
|
11.8.26 |
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development | OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration | AI | The Hacker News |
|
11.8.26 |
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants | Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server. | APT | SECURELIST |
|
11.8.26 |
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection | Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. | APT | SECURELIST |
|
11.8.26 |
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices | A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle | Mobil | The Hacker News |
|
11.8.26 |
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo | Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was | Security | The Hacker News |
|
11.8.26 |
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers | Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean | Cryptocurrency | The Hacker News |
|
11.8.26 |
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 | Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components | OS | The Hacker News |
|
11.8.26 |
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets | A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer | AI | The Hacker News |
|
11.8.26 |
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks | Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. | Ransom | The Hacker News |
|
11.8.26 |
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine | Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the | ICS | The Hacker News |
|
11.8.26 |
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins | Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily | Hack | The Hacker News |
|
11.8.26 |
Member of The Com sent to prison for blackmail, sextortion | A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. | BigBrothers | BleepingComputer |
|
11.8.26 |
LexisNexis shuts down services after suspicious activity on servers | LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. | Incindent | BleepingComputer |
|
11.8.26 |
Valve notifies Steam hardware customers of a data breach | Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. | Incindent | BleepingComputer |
|
11.8.26 |
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw | Microsoft has disclosed that Storm-1175 , a financially motivated threat actor linked to China, has deployed a previously undocumented | APT | The Hacker News |
|
10.8.26 |
AI-Driven Deepfake-Based Military ID Forgery APT Campaign | Emergence of APT attacks using generative AI "ChatGPT" | AI | GENIANS.KR |
|
10.8.26 |
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM | Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty. | AI | GENIANS.KR |
|
10.8.26 |
DPRK-Related Campaigns with LNK and GitHub C2 | FortiGuard Labs recently detected a series of LNK files targeting users in South Korea. These attacks use a multi-stage scripting process and leverage GitHub as Command and Control (C2) infrastructure to evade detection. | APT | FORTINET BLOG |
|
10.8.26 |
IT threat evolution in Q2 2026. Non-mobile statistics | The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026. | Mobil | SECURELIST |
|
10.8.26 |
IT threat evolution in Q2 2026. Mobile statistics | The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. | Mobil | SECURELIST |
|
10.8.26 |
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development | North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun | APT | The Hacker News |
|
10.8.26 |
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA | Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. | Phishing | The Hacker News |
|
10.8.26 |
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development | AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, | AI | The Hacker News |
|
10.8.26 |
Critical Progress LoadMaster flaw now actively exploited in attacks | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. | Exploit | BleepingComputer |
|
10.8.26 |
Hackers breach TrueConf to trojanize client installers with backdoors | The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. | Virus | BleepingComputer |
|
10.8.26 |
Metabase SQLi zero-day exploited in customer data-theft attacks | A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. | Exploit | BleepingComputer |
|
10.8.26 |
Unlimited Technology Systems breach impacts 3.8 million people | Unlimited Technology Systems breach impacts 3.8 million people | Incindent | BleepingComputer |
|
10.8.26 |
Levi Strauss & Co. says hackers stole corporate data in cyberattack | Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. | Incindent | BleepingComputer |
|
10.8.26 |
Real emails, hijacked payments: Two H1 2026 attack chains | Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. | Spam | BleepingComputer |
|
10.8.26 |
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials | Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. | Cryptocurrency | The Hacker News |
|
10.8.26 |
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause | OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal | AI | The Hacker News |
|
9.8.26 |
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers | Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send | Cyber | The Hacker News |
|
9.8.26 |
North Carolina Ports confirms cyberattack disrupting operations | The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. | Hack | BleepingComputer |
|
9.8.26 |
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it | OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. | AI | BleepingComputer |
|
9.8.26 |
ClickFix attack pushes macOS infostealer for crypto theft attacks | A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. | Virus | BleepingComputer |
|
9.8.26 |
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group | A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. | APT | BleepingComputer |
|
9.8.26 |
Swiss government SharePoint breach compromised 200 accounts | Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. | Incindent | BleepingComputer |
|
9.8.26 |
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes | Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. | Attack | BleepingComputer |
|
9.8.26 |
Meta AI model hacked a company during misconfigured cyber test | Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. | AI | BleepingComputer |
|
9.8.26 |
Ransom Cartel ransomware creator sentenced to 16 years in prison | Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. | Ransom | BleepingComputer |
|
9.8.26 |
Canadian pleads guilty to Snowflake cloud data-theft attacks | A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. | Incindent | BleepingComputer |
|
8.8.26 |
Hackers run khunt post-exploitation toolkit from Oracle database | Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. | Exploit | BleepingComputer |
|
8.8.26 |
COLDCARD security audit phishing attack installs remote access tool | COLDCARD security audit phishing attack installs remote access tool | Phishing | BleepingComputer |
|
8.8.26 |
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws | The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. | Exploit | BleepingComputer |
|
8.8.26 |
Google Blogger locks hundreds of blogs in malware false positive | Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. | Virus | BleepingComputer |
|
8.8.26 |
How AI-powered phishing killed blocklists for good | AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. | AI | BleepingComputer |
|
8.8.26 |
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests | OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. | AI | BleepingComputer |
|
8.8.26 |
TP-Link patches Omada ZTP flaws allowing hackers to breach networks | TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). | Vulnerebility | BleepingComputer |
|
8.8.26 |
Phishing service spoofs RingCentral to steal Microsoft 365 accounts | The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. | Phishing | BleepingComputer |
|
8.8.26 |
New XCSSET variant targets macOS devs via compromised Xcode projects | A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. | Virus | BleepingComputer |
|
8.8.26 |
77 Open VSX extensions found harvesting developer info | 77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. | Virus | BleepingComputer |
|
8.8.26 |
Massive ChainDrop npm supply-chain attack infects hundreds of packages | Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. | Virus | BleepingComputer |
|
8.8.26 |
Varonis Agent IBAC keeps AI agents within their intended boundaries | AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. | AI | BleepingComputer |
|
8.8.26 |
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts | Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. | APT | BleepingComputer |
|
8.8.26 |
New Pass-ta-key attacks let malware hijack Google-synced passkeys | Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. | Hack | BleepingComputer |
|
8.8.26 |
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens | New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. | Hack | The Hacker News |
|
8.8.26 |
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication | Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been | Exploit | The Hacker News |
|
8.8.26 |
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist | N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw | Vulnerebility | The Hacker News |
|
8.8.26 |
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp | Vulnerebility | The Hacker News |
|
8.8.26 |
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer | A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform | Virus | The Hacker News |
|
8.8.26 |
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets | ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored | Cryptocurrency | The Hacker News |
|
8.8.26 |
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data | A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671 . "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. | Phishing | The Hacker News |
|
8.8.26 |
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP | WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content | Vulnerebility | The Hacker News |
|
7.8.26 |
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers | A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since | Vulnerebility | The Hacker News |
|
7.8.26 |
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables | Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) | Attack | The Hacker News |
|
7.8.26 |
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails | Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle | Phishing | The Hacker News |
|
7.8.26 |
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day | PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle , generated and proved new HTTP | AI | The Hacker News |
|
7.8.26 |
Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Tools | Infostealers are a rapidly evolving threat, enabling various adversaries, ranging from ransomware groups and hacktivists to nation-state actors, to exploit stolen credentials for unauthorized access to sensitive resources. In today’s threat landscape, identity is a primary target, with attackers seeking diverse credentials including usernames, passwords, tokens, and seed phrases. | Virus | SOCRADAR |
|
7.8.26 |
Snowflake Hacker Pleads Guilty, Faces 32 Years | Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count tied to the 2024 breaches of Snowflake customer accounts. | CyberCrime | SOCRADAR |
|
7.8.26 |
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) | AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. | Hack | AHNLAB |
|
7.8.26 |
CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions | Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints. | Vulnerebility | OX |
|
7.8.26 |
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access | Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. | Virus | The Hacker News |
|
7.8.26 |
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets | A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's | AI | The Hacker News |
|
7.8.26 |
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign | A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating | Hack | The Hacker News |
|
7.8.26 |
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts | Zapscape , a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM | Vulnerebility | The Hacker News |
|
6.8.26 |
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs | Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of | Vulnerebility | The Hacker News |
|
6.8.26 |
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs | An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel | Hack | The Hacker News |
|
6.8.26 |
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities | Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan | ICS | The Hacker News |
|
6.8.26 |
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps | Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains . Introduced in | Cryptocurrency | The Hacker News |
|
6.8.26 |
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses | Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. | OS | The Hacker News |
|
6.8.26 |
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access | Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post- | Attack | The Hacker News |
|
6.8.26 |
AWS, Google, and Vercel Patch Agent Flaws That Let Tool Calls Skip the Model | Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of | Vulnerebility | The Hacker News |
|
6.8.26 |
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells | Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. | Virus | The Hacker News |
|
6.8.26 |
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service | A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the | Ransom | The Hacker News |
|
6.8.26 |
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild | A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild , according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The | Exploit | The Hacker News |
|
6.8.26 |
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People | Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related | CyberCrime | The Hacker News |
|
6.8.26 |
IBM report sees deep fakes emerging as top AI attack threat | IBM study finds deepfake attacks now account for nearly half of AI-enabled breaches as organizations grapple with rising costs and expanding cyber risks. | AI | BARRACUDA |
|
6.8.26 |
Malware signing: When trust becomes an attack surface | How cybercriminals use stolen, fraudulent, and commercialized code-signing certificates to make malware appear legitimate and bypass traditional trust controls. | Virus | BARRACUDA |
|
6.8.26 |
Dark Web Market: Vortex Market | Vortex Market describes itself as a “classic wallet escrow market,” and that self-description is accurate. It is a general-purpose Dark Web marketplace built around anonymous trade, vendor reputation levels, and cryptocurrency payments held in market-controlled wallets. | CyberCrime | SOCRADAR |
|
6.8.26 |
Formula 1 Phishing Campaign & Kit Analysis | SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets. | Phishing | SOCRADAR |
|
6.8.26 |
Free tokens for sale: How fake signups drive AI fraud | As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. | AI | OKTA |
|
6.8.26 |
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant | Hack | FORTINET BLOG |
|
6.8.26 |
Inside Greatness: Telegram-Distributed M365 AiTM PhaaS | ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. | Phishing | ZEROBEC BLOG |
|
6.8.26 |
Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead | We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. | Phishing | Huntress |
|
6.8.26 |
Toolkit Installation via SQL Injection Shows the Classics Still Hit | Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution | Hack | Huntress |
|
6.8.26 |
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages | Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads. | Virus | ELASTIC |
|
6.8.26 |
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 | An exposed open directory at 193.233.202[.]17 caught an operator tied to The Gentlemen ransomware mid-intrusion, setting up a Windows domain for persistent access, credential theft, and lateral movement. The files left behind trace the full operation, from privileged account creation and LSASS dumping to security-product tampering and reverse tunnels. | Virus | HUNT.IO |
|
6.8.26 |
Targeted Attack on Government Entities in the Middle East | Part 2 | This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. | Virus | Zscaler |
|
6.8.26 |
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures | A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had | Virus | The Hacker News |
|
6.8.26 |
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes | OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide | AI | The Hacker News |
|
5.8.26 |
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt | Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) | AI | The Hacker News |
|
5.8.26 |
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports | Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source | AI | The Hacker News |
|
5.8.26 |
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug | HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider | Vulnerebility | The Hacker News |
|
5.8.26 |
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain | Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the | Virus | The Hacker News |
|
5.8.26 |
77 evil twin Open VSX extensions | Between July 26 and August 1, 2026, our monitoring systems identified 77 Open VSX extensions that beacon to the same newly registered domain. Each one republishes the name, namespace and description of a real, unrelated extension at a low version number, almost always 0.0.1, under an account that does not own the namespace and does not belong to the original author | Hack | MANIFOLD |
|
5.8.26 |
A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads | A massive Shai-Hulud campaign hit npm, affecting over 2 billion monthly downloads of packages, the code contains the classic infostealer logic, and self propagating code. | Virus | OX SECURITY |
|
5.8.26 |
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. | Hack | Microsoft blog |
|
5.8.26 |
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch | A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default- | Vulnerebility | The Hacker News |
|
5.8.26 |
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk | Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled | Phishing | The Hacker News |
|
5.8.26 |
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup | An unauthenticated attacker can read any file the service account can access on Gitea , the self-hosted Git platform, in versions 1.22.1 through | Vulnerebility | The Hacker News |
|
5.8.26 |
Leaked n8n API Tokens Exposed Live Instances to Credential Theft | GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers | Vulnerebility | The Hacker News |
|
5.8.26 |
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data | A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were | Virus | The Hacker News |
|
5.8.26 |
New DOUBLECUP ClickFix service hides malware in browser cache images | A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. | Virus | BleepingComputer |
|
5.8.26 |
Fake Roblox Xeno script launcher pushes infostealer, RAT malware | Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. | Virus | BleepingComputer |
|
5.8.26 |
N-able warns of N-central auth bypass flaw exploited in attacks | N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. | Vulnerebility | BleepingComputer |
|
5.8.26 |
ExfilSquad hackers leak info of over 100,000 UK police officers, staff | A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. | Incindent | BleepingComputer |
|
5.8.26 |
Inside the Underground Business of the Android BTMOB RAT malware | Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. | Virus | BleepingComputer |
|
5.8.26 |
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems | OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. | AI | BleepingComputer |
|
5.8.26 |
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft | A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. | Vulnerebility | BleepingComputer |
|
5.8.26 |
Google Chrome may soon block New Tab hijacker extensions by default | Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. | Hack | BleepingComputer |
|
5.8.26 |
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself | An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber | AI | The Hacker News |
|
5.8.26 |
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited | The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities ( | Exploit | The Hacker News |
|
5.8.26 |
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer | Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. | Virus | The Hacker News |
|
5.8.26 |
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens | The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code | Phishing | The Hacker News |
|
4.8.26 |
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks | A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 | Virus | The Hacker News |
|
4.8.26 |
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access | Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe | Hack | The Hacker News |
|
4.8.26 |
How legitimate cloud platforms enable phishers to bypass MFA | We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. | Phishing | SECURELIST |
|
4.8.26 |
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent | Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue | AI | The Hacker News |
|
4.8.26 |
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root | cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege | Vulnerebility | The Hacker News |
|
4.8.26 |
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT | A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in | Virus | The Hacker News |
|
4.8.26 |
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to | Exploit | The Hacker News |
|
4.8.26 |
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users | Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. | Virus | The Hacker News |
|
3.8.26 |
An analysis of incidents at Brazilian educational institutions | Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe. | Incindent | SECURELIST |
|
3.8.26 |
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts | Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or | Hack | The Hacker News |
|
3.8.26 |
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws | The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure | Ransom | The Hacker News |
|
3.8.26 |
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS | An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. | APT | The Hacker News |
|
3.8.26 |
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web | The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and | BigBrothers | The Hacker News |
|
3.8.26 |
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable | Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered | Vulnerebility | The Hacker News |
|
3.8.26 |
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete | N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems | Exploit | The Hacker News |
|
3.8.26 |
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code | Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily | Vulnerebility | The Hacker News |
|
2.8.26 |
Rails patches critical Active Storage flaw with RCE potential | A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). | Vulnerebility | BleepingComputer |
|
2.8.26 |
Amgen says cloud data breach exposed patient health, proprietary info | Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. | Incindent | BleepingComputer |
|
2.8.26 |
Arch Linux disables AUR package adoption to stop malware flood | Arch Linux disables AUR package adoption to stop malware flood | Virus | BleepingComputer |
|
2.8.26 |
Online ad firm Adform’s script compromised to steal cryptocurrency | Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. | Cryptocurrency | BleepingComputer |
|
2.8.26 |
OpenAI says its new GPT 5.6 models are becoming more cost-efficient | OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. | AI | BleepingComputer |
|
2.8.26 |
Hacker uses DeepSeek AI to autonomously attack vulnerable servers | A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. | AI | BleepingComputer |
|
2.8.26 |
CISA warns of cyberattacks disrupting U.S. water utilities | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. | BigBrothers | BleepingComputer |
|
2.8.26 |
ESET tracks rise in malicious AI skills and adaptable malware | Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software | AI | BleepingComputer |
|
2.8.26 |
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests | One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. | AI | BleepingComputer |
|
2.8.26 |
South Korea fines telco giant KT $39 million for customer data breach | South Korea fines telco giant KT $39 million for customer data breach | Incindent | BleepingComputer |
|
2.8.26 |
Network Anomaly Detection in KATA | Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. | Security | SECURELIST |
|
2.8.26 |
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes | An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy | Cryptocurrency | The Hacker News |
|
2.8.26 |
JetBrains warns of critical TeamCity remote code execution flaw | JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. | Vulnerebility | BleepingComputer |
|
2.8.26 |
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers | Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. | APT | BleepingComputer |
|
2.8.26 |
VMware fixes three critical flaws allowing auth bypass, VM escapes | Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. | Vulnerebility | BleepingComputer |
|
2.8.26 |
Google says AI helped Chrome fix 1,072 security bugs in two releases | Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. | AI | BleepingComputer |
|
2.8.26 |
ShinyHunters claims Brinks Home breach, threatens to leak stolen data | Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. | Incindent | BleepingComputer |
|
2.8.26 |
Microsoft Teams vishing attacks lead to Chaos ransomware attacks | Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. | Ransom | BleepingComputer |
|
2.8.26 |
Analog Devices discloses data breach, says operations unaffected | Analog Devices discloses data breach, says operations unaffected | Incindent | BleepingComputer |
|
2.8.26 |
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access | The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. | APT | BleepingComputer |
|
2.8.26 |
Anthropic confirms Claude is down worldwide | Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. | AI | BleepingComputer |
|
2.8.26 |
Cisco warns of FMC static credential flaw exploited in zero-day attacks | Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. | Vulnerebility | BleepingComputer |
|
2.8.26 |
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare | Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. | CyberCrime | BleepingComputer |
|
1.8.26 |
OpenAI agent used exposed credentials at 4 services in Hugging Face breach | In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. | AI | BleepingComputer |
|
1.8.26 |
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack | The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." | Incindent | BleepingComputer |
|
1.8.26 |
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage | AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. | AI | BleepingComputer |
|
1.8.26 |
Windows 11 KB5101684 update released with 42 changes and fixes | Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. | OS | BleepingComputer |
|
1.8.26 |
These near-mint ASUS Chromebook refurbs are only $145 | Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale. | Security | BleepingComputer |
|
1.8.26 |
CubePilot drone software dev hit by DNS hijacking to intercept traffic | CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. | AI | BleepingComputer |
|
1.8.26 |
OpenAI models used Artifactory zero-days to escape to the internet | JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. | AI | BleepingComputer |
|
1.8.26 |
CISA shares advice on isolating vital systems during cyberattacks | The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. | ICS | BleepingComputer |
|
1.8.26 |
vBulletin fixes critical pre-auth RCE flaw with public exploit | A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. | Vulnerebility | BleepingComputer |
|
1.8.26 |
Is Your SSO Protected Against Modern Credential Attacks? | A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. | Security | BleepingComputer |
|
1.8.26 |
Over 24,000 exposed server BMCs leak password hash via decades-old flaw | More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. | Incindent | BleepingComputer |
|
1.8.26 |
Data breach at medical billing firm MCBS affects 1.26 million people | Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. | Incindent | BleepingComputer |
|
1.8.26 |
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites | Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites | Cryptocurrency | The Hacker News |
|
1.8.26 |
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction | Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing | Vulnerebility | The Hacker News |
|
1.8.26 |
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware | A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake , a remote access trojan (RAT) that can capture webcam | Virus | The Hacker News |
|
1.8.26 |
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk | A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in | APT | The Hacker News |
|
1.8.26 |
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm | Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based | Virus | The Hacker News |
|
1.8.26 |
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies | Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo | Hack | The Hacker News |