PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon,…
Category: EN
DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack
A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board…
Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit
North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule…
Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices
Zoom has released security updates to address four vulnerabilities that could expose meeting participants to significant attacks, including a zero-click…
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.
338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping…
One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT
A ClickFix prompt can end in a remote-access foothold. CNCMachineRMS, an undocumented x64 RAT deployed at the end of a BabaDeda loader chain that turns a…
Secure Agent Harness Execution: Preventing Escape
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Secure Agent Harness Execution: Preventing Escape
Ready-made $500 kit puts a crypto scam within anyone’s reach
A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets…
Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution
A critical vulnerability in Docker, tracked as CVE-2026-17106 and referred to as “CopyEscape,” allows malicious containers to overwrite files on the host…
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule…
AI deployments are stretching enterprise security to its limits
CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility…
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely
Microsoft has disclosed a new remote code execution flaw in Outlook, tracked as CVE-2026-70329, as part of its August 2026 Patch Tuesday rollout. The…
Black Hat 2026: Key news, takeaways and security trends
Black Hat USA 2026 returns for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and…
ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048,…
DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym
DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent ‘Ghostjacking’ Delta Air Lines is investigating a brief appearance of an unauthorized…
Delta Airlines Investigates Rogue Wi-Fi Attack on Flight Carrying DEF CON Attendees
Delta Airlines is investigating a suspected Wi-Fi deauthentication attack and rogue network aboard Flight 591 carrying DEF CON attendees.
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that…
Signal adds an extra layer of security to make sure you’re actually chatting with the right person
One big caveat, though: You need your contact’s phone number
