Black Hat 2026 Vendor Profile — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series — Cyber Defense Magazine. Part…
Dangerous Apple Bug Lets Images Execute Malicious Code
The Vulnerability Apple fixed a major security vulnerability in their image handling framework for both desktop and mobile devices on August 18, 2026. The…
Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)
Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the…
Black Hat 2026: The Supply-Chain Trust Series
Black Hat 2026 Series Introduction — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series. This is the series home.…
MacSync Stealer Hides Behind 30+ Domains While Stealing Passwords and Sensitive Mac Data
MacSync Stealer is expanding the risk facing Mac users by turning everyday web browsing and Terminal activity into a route for password theft. The…
Chainguard: Structurally Deleting a Whole Category of Attack
Black Hat 2026 Vendor Profile — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series — Cyber Defense Magazine. Part…
Cyber Briefing: 2026.08.19
Unauthenticated flaw exploitation, state-backed academic espionage, and misconfigured autoscaling policies are actively driving severe system compromises,…
Black Hat Rewind: Most Creative Booths Part 1
Exhibitor booths are a major part of the Black Hat experience, giving companies a chance to bring their technology to life and make a lasting impression.…
Ransomware Hackers Pose as Recovery Firm and Demand Up to $60,000
Ransomware victims are facing a new kind of pressure campaign. Instead of receiving another demand from the attackers who stole their data, some companies…
ActiveState: Rebuilding Open Source From Source, With a Cool-Down and a Clock
Black Hat 2026 Vendor Profile — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series — Cyber Defense Magazine. Part…
Hundreds of Leaked Stripe Merchant Keys Expose Payment and Payout Capabilities
Hundreds of leaked Stripe merchant keys have exposed a serious risk for online businesses and their customers. The collection contains active credentials…
Attackers Are Moving At Machine Speed. Federal Remediation Still Isn’t.
As AI accelerates the scale, sophistication, and speed of cyberattacks, the window between vulnerability discovery and exploitation is narrowing. Recent…
Windows Defender Update for 0-day Vulnerability Breaks Virus Scans
Microsoft Defender has been aborting Quick, Full, and Offline virus scans after a cluster of Security Intelligence updates reached Windows PCs on August…
Microsoft at Black Hat 2026: When the Attacker Comes Through the Front Door You Trust
Black Hat 2026 Keynote Report — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series — Cyber Defense Magazine. Part…
Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service Vulnerability in the Wild
Hackers are actively abusing a flaw in macOS Screen Sharing to take root-level control of a small number of devices. The attacks turn a built-in…
NetRise: Reading the Thing That Actually Runs — and Vetting Who Wrote It
Black Hat 2026 Vendor Profile — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series — Cyber Defense Magazine. Part…
Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks
A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their…
Critical GitLab Code Injection Flaw CVE-2026-19478
GitLab has released emergency security patches addressing a critical code injection vulnerability that enables unauthenticated attackers to modify or…
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based…
Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built,…
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and…
Intezer adds native response automation without separate SOAR
Intezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly…
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in…