The archive
391 dispatches · newest first · page 3 of 7
- 2026-08-11[KEV] CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall ThreKEVCVE-2026-20349
- 2026-08-11Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
- 2026-08-11Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
- 2026-08-11Two wars and a World Cup lead to epic DDoS attacks on publishers
- 2026-08-11Social media platforms crack down on drone factory recruiting game
- 2026-08-11US and South Korea warn of Gunra ransomware targeting govt agencies
- 2026-08-11Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
- 2026-08-11BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
- 2026-08-11BdThemes plugins supply-chain hack creates rogue WordPress admins
- 2026-08-11Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
- 2026-08-10Multistate Water System Attacks Widen, Iran Suspected
- 2026-08-10FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
- 2026-08-10Russian military hackers pose as recruiters to target Ukrainian IT workers
- 2026-08-10Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
- 2026-08-10China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
- 2026-08-10CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
- 2026-08-10New Jersey, Alabama Join States Targeted in Water Cyberattacks
- 2026-08-10TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
- 2026-08-10Critical Progress LoadMaster flaw now actively exploited in attacks
- 2026-08-10US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
- 2026-08-10Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
- 2026-08-10Həftəlik exposure digest — Azərbaycan (2026-W33, 10 avqust 2026)
- 2026-08-10Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
- 2026-08-10DEFCON: New Red Team Tactic
- 2026-08-10Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
- 2026-08-08Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
- 2026-08-08Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
- 2026-08-08N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
- 2026-08-08Metabase customers staying silent about the breach
- 2026-08-08tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
- 2026-08-08WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
- 2026-08-08Metabase SQLi zero-day exploited in customer data-theft attacks
- 2026-08-07[KEV] CVE-2026-8037: Progress LoadMaster Command Injection VulnerabilityKEVCVE-2026-8037
- 2026-08-07Ransomware: Helix → Uber
- 2026-08-07New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
- 2026-08-07Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
- 2026-08-07Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
- 2026-08-07Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
- 2026-08-06CVE-2026-20200: A vulnerability in the web-based management interface of Cisco IMC could allow an authentiCVE-2026-20200
- 2026-08-06Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
- 2026-08-06AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
- 2026-08-06Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
- 2026-08-06Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
- 2026-08-06Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
- 2026-08-05IBM's agentic AI platform is under active attack - patch now
- 2026-08-05Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
- 2026-08-05Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
- 2026-08-05OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
- 2026-08-05CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
- 2026-08-05New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchCVE-2026-64531
- 2026-08-05Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode MarkupCVE-2026-59774
- 2026-08-05Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
- 2026-08-05Water Sector Cyberattacks Reportedly Hit at Least 12 States
- 2026-08-05Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
- 2026-08-04New XCSSET variant targets macOS devs via compromised Xcode projects
- 2026-08-04Massive supply-chain attack compromises 440 packages under four hours
- 2026-08-04Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
- 2026-08-04[KEV] CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityKEVCVE-2026-34486
- 2026-08-04[KEV] CVE-2026-9198: IBM Langflow Code Injection VulnerabilityKEVCVE-2026-9198
- 2026-08-04[KEV] CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerKEVCVE-2026-18556