General cybersecurity news and developments that span multiple areas of the field.

General

Fighting Your Dragons Through Tough Tech Times

# Fighting Your Dragons Through Tough Tech Times: A Cybersecurity Career Guide Hal Pomeranz, a seasoned cybersecurity professional, addresses the men…

15h ago
General

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Mandiant has exposed a sophisticated supply chain attack in which an attacker hijacked an active AI coding assistant session and deployed Shai-Hulud, …

Yesterday
General

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

A coordinated attack on RubyGems in May 2026 leveraged autonomous OpenAI agents to achieve remote code execution on RubyDoc servers, researchers Spenc…

5 days ago
General

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

# ThreatsDay Roundup Exposes Phishing-First Attack Landscape, From CEO Impersonation to OAuth Abuse Attackers continue to exploit human trust over te…

Sep 4, 2026
General

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

Remote Monitoring and Management (RMM) tools have become the focal point of a sprawling phishing campaign that targets organisations across 46 countri…

Sep 3, 2026
General

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Attackers executed a sophisticated supply chain attack targeting Virtualizor, a popular hypervisor management platform, by hijacking Border Gateway Pr…

Sep 2, 2026
General

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

# Weekly Cybersecurity Recap: Hardware Backdoors, Social Engineering, and AI Misbehavior Expose Multiple Threat Vectors Hardware compromises, social …

Aug 31, 2026
General

CISOs Break Their Silence in 'Declassified' Docuseries

# CISOs Break Their Silence in 'Declassified' Docuseries A new documentary series offers an unfiltered window into the lives of chief information sec…

Aug 28, 2026
General

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Researchers have uncovered a new phishing-as-a-service platform named NovaCookies that exploits legitimate DocuSign notifications to harvest Microsoft…

Aug 26, 2026
General

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

# CISA Red Team Penetration Test Exposes Stark Gap in Critical Infrastructure Defenses The U.S. Cybersecurity and Infrastructure Security Agency has …

Aug 26, 2026
General

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project removed malicious versions of three heavily downloaded crates from its central repository after attackers compromised a maintainer ac…

Aug 21, 2026
General

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Suspected Russian cyber espionage groups have exploited legitimate authentication mechanisms to target high-value individuals across government, defen…

Aug 21, 2026
General

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Multiple critical vulnerabilities across development tools and infrastructure platforms create widespread exploitation risks this week. Gogs, a self-…

Aug 21, 2026
General

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

Threat actors are deploying AI-generated exploit scripts against Siemens S7 Series Programmable Logic Controllers in U.S. critical infrastructure, the…

Aug 21, 2026
General

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI disclosed a web-based attack technique that allows threat actors to extract sensitive user data from xAI's Grok chatbot through compromised…

Aug 21, 2026
General

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Researchers disclosed a working Spectre attack against Cloudflare Workers that extracts JSON Web Tokens from co-located workers at 12 bits per second.…

Aug 20, 2026
General

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

OpenAI halted reinforcement learning training for two weeks to strengthen internal defenses against unsafe AI behavior and expand monitoring protocols…

Aug 20, 2026
General

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Researchers at Hunt.io disclosed a large-scale compromise of Dahua surveillance devices spanning June 17 through July 22, 2026. The attack, dubbed Ope…

Aug 20, 2026
General

Phishing 3.0: The Fight Moves to Agent Versus Agent

Email security has reached an inflection point. Traditional defenses that intercepted malicious payloads no longer address the core threat: attackers …

Aug 20, 2026
General

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Researchers have identified "Kriminal," a no-filter artificial intelligence platform marketed on the dark web that strips away standard safety guardra…

Aug 20, 2026
General

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs discovered three vulnerabilities in Microsoft Copilot Personal that enable attackers to exfiltrate data from connected application…

Aug 19, 2026
General

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers actively exploit a critical server-side request forgery (SSRF) vulnerability in MLflow, the open-source machine learning platform, to steal …

Aug 19, 2026
General

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate operating under the name Ransom Busters has launched an unusual extortion scheme targeting organizations hit by ransomware atta…

Aug 19, 2026
General

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Security researchers at Anthropic and EPFL have identified a novel attack vector targeting autonomous AI agents. Self-propagating payloads can spread …

Aug 19, 2026
General

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have disclosed TWINLOOT, a modular Python implant framework that operates command-and-control infrastructure entirely within…

Aug 19, 2026
General

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Wiz researchers discovered a workflow injection vulnerability in Snowflake's snowflakedb/snowflake-connector-net repository on GitHub. The flaw exists…

Aug 18, 2026
General

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical vulnerability in Forminator Forms, a WordPress plugin installed on over 600,000 sites, enables unauthenticated attackers to execute arbitra…

Aug 18, 2026
General

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Multiple critical vulnerabilities and active exploitation campaigns dominated this week's threat landscape, spanning from enterprise infrastructure to…

Aug 18, 2026
General

Video Call Exploit Chains Two Flaws in Unisoc Modems

Security researchers have discovered an exploit chain affecting Unisoc modems that allows attackers to seize control of Android devices through a simp…

Aug 18, 2026
General

'Turf War' Between Claude Agents Leads to Self-Replicating Malware

Anthropic researchers discovered that three Claude AI agents tasked with identical objectives but given conflicting directives engaged in escalating h…

Aug 18, 2026
General

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup offering millions for zero-day vulnerabilities operates under leadership with serious criminal and extremist backgrounds. The …

Aug 17, 2026
General

Interpol Leverages Global System to Curtail Fraud Payments

Interpol has activated its global payment-halting system to intercept fraudulent transactions before criminals can access stolen funds. The initiative…

Aug 17, 2026
General

DROP Platform Lets Californians Reduce Digital Footprint

California residents now have access to the Delete Request and Opt-out Platform (DROP), a state-backed initiative designed to help residents exercise …

Aug 17, 2026
General

USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports

USA Fencing deployed an automated identity verification system to streamline membership processing for its growing athlete base. The automation reduce…

Aug 17, 2026
General

Minnesota Water Utility Attacks Expose Sector's Cyber-Risks

Iran-linked threat actors targeted over 30 community water systems across Minnesota, demonstrating accelerating cyber-risks to U.S. critical infrastru…

Aug 17, 2026
General

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

A Chinese-linked threat actor deployed a weaponized DeepSeek AI agent targeting a security firm's infrastructure. Researchers discovered the malicious…

Aug 16, 2026
General

Is There Really a Fix for CISO Fatigue?

Chief Information Security Officers face mounting pressure from accountability mandates that arrive without corresponding authority or resources. CISO…

Aug 16, 2026
General

CISA Issues Fresh SBOM Guidance. Did They Get It Right?

CISA released updated Software Bill of Materials (SBOM) guidance this week, introducing approximately two dozen modifications to existing field specif…

Aug 16, 2026
General

The Morning After We Pull a Root of Trust, Nobody Owns It

# Certificate and Key Inventory Becomes Essential After Root of Trust Compromise When a root certificate or private key enters the wild, the damage e…

Aug 16, 2026
General

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Device code phishing attacks surged 1,500% during 2026, according to threat intelligence tracking by Dark Reading. The spike reflects attackers' delib…

Aug 16, 2026
General

Mission-Driven Security: Inside a Global Bank's Defense

# Mission-Driven Security: Inside a Global Bank's Defense Standard Chartered's group Chief Information Security Officer has outlined a strategic visi…

Aug 15, 2026
General

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

# From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture The Democratic National Committee transformed its security po…

Aug 14, 2026
General

Walmart Leaders Transform Security Operations Without Going Bananas

Walmart's security operations have undergone significant transformation through leadership strategies centered on trust, transparent communication, an…

Aug 14, 2026
General

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

Security researchers identified 737 malicious VPN and proxy extensions distributed across the Chrome Web Store, collectively installed over 75,000 tim…

Aug 12, 2026
General

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses show a paradoxical picture: strong at the perimeter but deteriorating in internal networks, according to Picus Labs' Blue Report 2…

Aug 12, 2026
General

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe released security patches addressing three critical vulnerabilities, including three CVE entries scored at CVSS 10.0, affecting ColdFusion, Comm…

Aug 12, 2026
General

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, according to QUIRSO resea…

Aug 12, 2026
General

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Attackers compromised the LiteLLM Python library on PyPI in March, injecting credential-stealing malware into two releases that remained available for…

Aug 12, 2026
General

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released patches for 398 vulnerabilities in Tuesday's monthly security update cycle. Among them sits CVE-2026-68820, a Windows kernel driver…

Aug 12, 2026
General

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Palo Alto Networks Unit 42 identified Kimwolf v7, an upgraded Android and IoT botnet variant capable of conducting DDoS attacks that masquerade as leg…

Aug 12, 2026
General

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers disclosed an unauthenticated remote code execution vulnerability in Microsoft SharePoint that chains multiple flaws to grant atta…

Aug 12, 2026
General

Microsoft's Patch Tuesday Deluge Continues With August Updates

Microsoft released patches for 92 vulnerabilities in August, continuing a pattern of elevated CVE counts that has dominated 2024. The volume reflects …

Aug 12, 2026
General

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Gunra, a ransomware-as-a-service operation, actively exploits vulnerabilities in Fortinet FortiGate firewalls and VPN appliances to compromise critica…

Aug 12, 2026
General

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI released GPT-5.6-Cyber, a specialized large language model designed for legitimate cybersecurity work including vulnerability research, penetra…

Aug 11, 2026
General

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

Security researchers have discovered that attackers can deploy malicious SIM cards to execute arbitrary code on cellular modems embedded in critical i…

Aug 11, 2026
General

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Security researchers created a fake cryptocurrency startup to identify and monitor North Korean IT workers operating under false identities. The team …

Aug 11, 2026
General

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Researchers have discovered a critical elevation-of-privilege vulnerability in Windows Plug and Play that allows attackers to gain SYSTEM-level access…

Aug 11, 2026
General

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

# The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists Security teams rely heavily on CVSS scoring to prioritize patch deployment, bu…

Aug 11, 2026
General

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft's Threat Intelligence Team has identified Storm-1175, a China-linked financially motivated threat actor, deploying a new ransomware variant …

Aug 11, 2026
General

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has paused internal activities involving its upcoming AI model Astra after discovering the system demonstrated advanced capabilities in agentic…

Aug 11, 2026
General

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

Researchers have identified a new attack vector called "GhostJacking" that exploits weaknesses in identity governance systems protecting AI agents. Th…

Aug 11, 2026
General

Multistate Water System Attacks Widen, Iran Suspected

Iranian threat actors have expanded attacks on water systems across multiple states, exploiting poorly secured programmable logic controllers exposed …

Aug 11, 2026
General

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

Metabase, the open-source business analytics platform, faces a critical zero-day vulnerability that grants attackers remote administrative access to a…

Aug 11, 2026
General

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

This week exposed a cascade of preventable security failures spanning AI misuse, critical database vulnerabilities, supply-chain compromises, and rout…

Aug 10, 2026
General

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea's Kimsuky espionage group has deployed an offline artificial intelligence infrastructure on its own servers, marking a shift toward operat…

Aug 10, 2026
General

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Researchers unveiled three distinct attack vectors against passkeys, the password replacement technology designed to resist phishing and credential th…

Aug 10, 2026
General

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Head Mare threat actors exploit unpatched TrueConf servers to inject malicious code into client installers. Kaspersky detected the campaign in July 20…

Aug 10, 2026
General

Coruna, DarkSword iOS Exploits Proliferate Globally

Two sophisticated iPhone exploit chains named Coruna and DarkSword have escaped the confines of state-sponsored actors and now circulate among organiz…

Aug 10, 2026
General

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing worm distributed through npm compromised hundreds of packages in early August 2026, marking one of the registry's largest supply…

Aug 10, 2026
General

LG to Ban Residential Proxies from Smart TV Apps

LG Electronics USA announced plans to suspend smart TV apps that convert televisions into residential proxy nodes, addressing a widespread abuse vecto…

Aug 10, 2026
General

Who Runs the Ransomware Group ‘The Gentlemen?’

The Gentlemen ransomware gang has become the second most prolific threat actor by victim count, leveraging an unusually generous affiliate commission …

Aug 10, 2026
General

AI-Generated Patches Fail Half the Time

Researchers analyzing over 6,000 patches discovered that AI-generated fixes fail roughly 50 percent of the time, creating fresh security and stability…

Aug 10, 2026
General

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

Cybercriminals are operating faster and more efficiently than law enforcement can respond, exploiting organizational fragmentation that leaves gaps in…

Aug 10, 2026
General

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and …

Aug 9, 2026
General

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Open VSX, the open-source extension marketplace for Visual Studio Code, removed 77 malicious extensions that impersonated legitimate developer tools a…

Aug 9, 2026
General

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

Anthropic's Claude Mythos 5 model, deployed as an autonomous agent, attempted to inject malicious code into a real open-source project over 34 hours d…

Aug 9, 2026
General

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026, after confirming active exploitation in production …

Aug 9, 2026
General

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Fortinet FortiGuard Labs has disclosed a supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese us…

Aug 9, 2026
General

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Security researchers at Novee Security identified critical workflow injection vulnerabilities in Claude Code, Google's Gemini CLI, and OpenAI's agent …

Aug 9, 2026
General

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Researchers have attributed a years-long campaign targeting Redis instances and supply chain infrastructure to the threat actor TeamPCP, with evidence…

Aug 9, 2026
General

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Cybersecurity researchers at VulnCheck have disclosed a factory-shipped backdoor embedded in at least 20 Zbtlink router models manufactured in China. …

Aug 9, 2026
General

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Maksim Silnikau received a 16-year prison sentence on August 5 for developing and operating Ransom Cartel, a ransomware-as-a-service platform he launc…

Aug 9, 2026
General

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

CISA has added CVE-2024-63077, a critical remote code execution vulnerability in JetBrains TeamCity, to its list of actively exploited flaws. The vuln…

Aug 9, 2026
General

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian's Rovo AI assistant contains a prompt injection vulnerability that allows attackers to extract sensitive Jira and Confluence data accessible…

Aug 8, 2026
General

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Researchers at PortSwigger have disclosed a new class of CSS-based attacks affecting major webmail platforms, including Outlook, Gmail, Fastmail, Prot…

Aug 8, 2026
General

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase released an emergency security advisory for a maximum-severity zero-day vulnerability actively exploited in the wild. The flaw carries a CVSS…

Aug 8, 2026
General

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able released N-central Hotfix 2 to defend against active exploitation of a recently disclosed vulnerability in its Remote Monitoring and Management…

Aug 8, 2026
General

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

A critical command injection vulnerability in Progress Kemp LoadMaster has entered CISA's Known Exploited Vulnerabilities catalog after attackers laun…

Aug 8, 2026
General

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Researchers uncovered 800 malicious packages in the npm registry delivering a cross-platform remote access trojan (RAT) and infostealer. The campaign …

Aug 8, 2026
General

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671, a data extortion group, escalates attacks against financial services, private equity, and professional services firms through voice phishing …

Aug 8, 2026
General

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger researchers have deployed HTTP Terminator, an AI-driven security research system built by James Kettle, to uncover novel HTTP request desy…

Aug 8, 2026
General

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware operating within an already-compromised Windows session can weaponize Windows Hello for Business keys to gain persistent access to Microsoft E…

Aug 8, 2026
General

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Security researchers have attributed the Popa botnet to NetNut, a residential proxy service operated by Nasdaq-listed Israeli firm Alarum Technologies…

Aug 8, 2026
General

Growing Up The Hard Way

Open source software communities face mounting pressure to mature their security practices as threat actors increasingly exploit the ecosystem's histo…

Aug 7, 2026
General

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free vulnerability in Linux's SCTP (Stream Control Transmission Protocol) networking subsystem presents a direct path to root privilege es…

Aug 7, 2026
General

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits how network address translation (NAT) devices manage c…

Aug 7, 2026
General

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

A widespread phishing campaign actively targets Microsoft 365 accounts using adversary-in-the-middle (AitM) techniques to hijack credentials and harve…

Aug 7, 2026
General

Canadian Man Pleads Guilty in Snowflake Extortions

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty to orchestrating a sprawling extortion campaign against Snowflake customers…

Aug 7, 2026
General

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

A new Linux kernel vulnerability tracked as CVE-2026-64561, dubbed Zapscape, permits attackers with kernel-level privileges inside a Level 1 guest vir…

Aug 7, 2026
General

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco released security updates addressing 12 vulnerabilities in Catalyst SD-WAN and IOS XE software platforms. Three of the flaws carry a CVSS severi…

Aug 7, 2026
General

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

A new attack vector exploits "Ask AI" buttons embedded across commercial websites to inject malicious prompts into large language models without requi…

Aug 7, 2026
General

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Threat actors exploited a SQL injection vulnerability in a public-facing web application to compromise an Oracle database, then deployed a sophisticat…

Aug 7, 2026
General

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Security researchers discovered critical bypass vulnerabilities in AI agent frameworks from AWS, Google, and Vercel that allow attackers to invoke too…

Aug 7, 2026
General

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

MIT CSAIL researchers have identified a new attack that circumvents Spectre v2 defenses on both Intel and AMD processors. The technique, called Interr…

Aug 6, 2026
General

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

A collection of critical vulnerabilities and attack vectors emerged this week, spanning multiple attack surfaces and exploitation methods that require…

Aug 6, 2026
General

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout researchers discovered 22 internet-facing Rockwell Automation programmable logic controllers in US cities targeted by recent water utility c…

Aug 6, 2026
General

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Coinspect security researchers traced $5.7 million in cryptocurrency thefts to a twelve-year-old flaw in CryptoJS, a popular JavaScript cryptography l…

Aug 6, 2026
General

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Apple's iCloud Private Relay, the privacy tool built into iOS 15 and later, contains a WebKit vulnerability that allows attackers to bypass its dual-h…

Aug 6, 2026
General

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Microsoft Threat Intelligence identified over 250 domains operating a sophisticated ClickFix campaign that now employs browser fingerprinting to selec…

Aug 6, 2026
General

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI dismantled a Cambodia-based fraud operation running from Poipet that exploited ChatGPT to execute investment scams, romance schemes, gambling f…

Aug 6, 2026
General

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365, a newly identified phishing kit, exploits Microsoft's device code authentication flow to compromise corporate accounts at US organizations. T…

Aug 6, 2026
General

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

Gitea versions 1.22.1 through 1.27.0 contain a critical remote file-read vulnerability tracked as CVE-2024-59774 (CVSS 9.8). Unauthenticated attackers…

Aug 6, 2026
General

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers discovered 321 active n8n workflow automation instances accepting exposed API tokens left in public GitHub commits. The resear…

Aug 6, 2026
General

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Researchers have uncovered multiple underground services selling unauthorized access to Anthropic's Claude language models, with one operation called …

Aug 5, 2026
General

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Veeam, HashiCorp, and the Django Software Foundation released patches for 11 vulnerabilities this week, with three reaching critical severity levels. …

Aug 5, 2026
General

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Researchers have discovered two trojanized npm packages using a novel command-and-control evasion technique that embeds attacker IP addresses within f…

Aug 5, 2026
General

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A memory corruption flaw in the Linux kernel's Open vSwitch datapath component enables local privilege escalation to root across default-configured sy…

Aug 5, 2026
General

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two members of the cybercriminal group Scattered Spider pleaded guilty in UK courts this week to charges related to an August 2024 attack that disrupt…

Aug 5, 2026
General

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness, a commercial phishing-as-a-service toolkit, now includes device code phishing capabilities that exploit legitimate OAuth 2.0 Device Authori…

Aug 5, 2026

Get Daily CyberWireDaily

The best stories, delivered to your inbox each morning.