New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning…
Inside Astaroth’s New Spambot Component
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Inside Astaroth’s New Spambot Component
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an…
IT Security News Hourly Summary 2026-08-08 11h : 5 posts
5 posts were published in the last hour 9:2 : WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution 9:2 : Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud 9:2 : 18-Year-Old Linux…
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site…
Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the…
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP)…
Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats
Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again
Sophia Antipolis, France, August 7th, 2026, CyberNewswire At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as…
Sunlight creates quantum entanglement once thought to require lasers
Scientists have generated quantum entanglement directly from sunlight, potentially offering a lower-energy alternative to the lasers normally used in…
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems…
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to…
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on…
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw…
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Apple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated…
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited…
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began…
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48…
Meta Ordered to Pay $567M and Overhaul Teen Safety on Facebook, Instagram
Meta must pay $567 million and change Facebook and Instagram protections for minors under a New Mexico court order it plans to appeal.
OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities
OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed…
Coding for Veterans: Cybersecurity Today on the Weekend with David Shipley
Coding for Veterans: From Military Service to Cybersecurity & Generative AI Careers This episode is sponsored by Nordlayer. Contact them at…
OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT for Global Fraud Campaigns
The use of ChatGPT by OpenAI has enabled it to dismantle a coordinated scam operation based in Poipet, Cambodia which used ChatGPT for multiple online…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Inside the Modern SOC: The Identity Front Door
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.