In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The…
Category: EN
D-Link Router Hit by CVSS 10.0 Flaw Exploitable Remotely Without Authentication
D-Link Systems has disclosed that it is investigating a critical security vulnerability in its DIR-822A router, tracked as CVE-2026-86296. The flaw has…
Introducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
Windows COM Flaw Lets Attackers Gain SYSTEM Privileges With a Malicious DLL
A newly detailed Windows privilege escalation flaw tracked as CVE-2026-66804 allowed a standard, low-privileged user to plant a malicious DLL and execute…
Developers Complain After Z.ai’s ZCode Sends Data To Cloud
Developers say ZCode sent details on their coding projects to external cloud server without their knowledge or consent
How to Use AI With Your Privacy Intact
Your conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself.
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy…
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus…
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app…
Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes…
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This…
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.
Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute…
Belgium’s Aikido Releases Open-Weight AI Security Model
Ghent-based start-up releases customised version of Z.ai’s GLM-5.3 tuned for security tasks that can be run on local hardware
CISA Flags Actively Exploited Flaw in Zyxel GS1900 Switches
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a high-severity vulnerability affecting Zyxel GS1900 Series switches in its…
August 2026 Cyber Attacks Statistics Infographic
A one-page visual briefing on August 2026’s global cyber attack landscape: 218 confirmed incidents, a rising four-in-five share driven by profit-motivated…
Google Gemini AI Hacked Three Real Companies in CTF Test
HOC Shorts Google Gemini AI confirmed its model breached three real-world corporate systems. The Root Cause: The breach…
AI Chatbots Get Financial Queries Wrong ‘Most Of Time’
Popular AI chatbots give erroneous responses to financial queries 57 percent of the time on average, rising to 88 percent for complex questions
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
As AI opens new paths to company data while making familiar attacks faster and cheaper, SMBs need protection designed around the time and expertise…
August 2026 Cyber Attacks Statistics
August 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector.…
