The archive
391 dispatches · newest first · page 2 of 7
- 2026-08-18🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and RussiaKEVCVE-2021-33044
- 2026-08-18[KEV] CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabiliKEVCVE-2026-33824
- 2026-08-18One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
- 2026-08-18Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
- 2026-08-18GitLab Patches Critical Code Injection Vulnerability
- 2026-08-18CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
- 2026-08-18Apple Patches iOS and macOS, (Mon, Aug 17th)
- 2026-08-18CVE-2026-19478: GitLab GraphQL Flaw ExploitedCVE-2026-19478
- 2026-08-18LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
- 2026-08-18Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP UploadsCVE-2026-15748
- 2026-08-17Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
- 2026-08-17CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 DaysCVE-2026-69414
- 2026-08-17[KEV] CVE-2025-62593: Ray-Project Ray Code Injection VulnerabilityKEVCVE-2025-62593
- 2026-08-17Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes
- 2026-08-17Six major security incidents traced from the initial Litellm and Trivy pipeline compromises all the way to ransomware/breaches
- 2026-08-17Weekly exposure digest — Azerbaijan (2026-W34)
- 2026-08-17Ransomware: qilin → Coface
- 2026-08-16Vulnerability giving attackers full control of Macs is under active exploitation
- 2026-08-16Mustang Panda Upgrades CoolClient With a Kernel Rootkit
- 2026-08-16CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export HandlingCVE-2026-6837
- 2026-08-15[KEV] CVE-2026-65400: Apple macOS Improper Authentication VulnerabilityKEVCVE-2026-65400
- 2026-08-15ChainDrop worm crawls into npm supply chain, evades standard defenses
- 2026-08-15GeoServer Zero-Day Is Already Being Probed. That’s the Problem
- 2026-08-15I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies
- 2026-08-14Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
- 2026-08-14Trivy, Not LiteLLM Behind the 2,500 Org Compromise
- 2026-08-14Hackers Exploiting Unpatched GeoServer Zero-Day
- 2026-08-14Multi-Functional Linux Botnet “Evooo1Bot”
- 2026-08-14Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
- 2026-08-13Microsoft patches LegacyHive Windows zero-day vulnerability
- 2026-08-13vCenter Flaw Exploited Just Five Days After Disclosure
- 2026-08-13Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
- 2026-08-13North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
- 2026-08-13Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
- 2026-08-13153GB of stolen credentials surface after LiteLLM supply chain attack
- 2026-08-13Hundreds of fake Chrome VPN extensions route traffic through a proxy
- 2026-08-13“Zoomsday” flaws could let one Zoom participant attack another
- 2026-08-13China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
- 2026-08-12Adobe Commerce Bug Targeted Immediately After DisclosureCVE-2026-71362
- 2026-08-12Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
- 2026-08-12737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
- 2026-08-12Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
- 2026-08-12SharePoint Vulnerability Exploited Shortly After PoC Release
- 2026-08-12Patch Tuesday: Update now to fix 421 flaws, including three zero-days
- 2026-08-12CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
- 2026-08-12New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
- 2026-08-12Lazarus hackers pair fake job offers with Windows zero-day exploit
- 2026-08-12Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
- 2026-08-12[KEV] CVE-2026-59310: Broadcom VMware vCenter Path Traversal VulnerabilityKEVCVE-2026-59310
- 2026-08-12Ivanti EPM Update Patches Remotely Exploitable Flaws
- 2026-08-12Microsoft Plugs Nearly 400 Security Holes
- 2026-08-12CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
- 2026-08-12SAP Commerce Cloud CVE-2026-58231 Requires Urgent PatchingCVE-2026-58231
- 2026-08-12Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
- 2026-08-12ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessCVE-2026-50656
- 2026-08-12Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
- 2026-08-12Cisco warns of ASA and FTD VPN flaw exploited to crash devices
- 2026-08-11CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires NowKEVCVE-2026-68820
- 2026-08-11Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10
- 2026-08-11[KEV] CVE-2026-72898: Metabase SQL Injection VulnerabilityKEVCVE-2026-72898