Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump…
Category: Security Affairs
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on…
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution.…
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers…
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited…
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has…
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage.…
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators.…
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says…
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check…
CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA…
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight.…
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code…
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on…
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution.…
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has…
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption.…
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco…
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage.…
The inconvenient truth about AI pentesting: someone has to check all the work
AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has…