The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities…
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known…
Apache NiFi Flaw Enable Security Bypass and Memory Corruption
Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow…
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on…
License plate readers as stalking tools, ExfilSquad dumps UK police data, the ever-shrinking patch window
When license plate readers become stalking tools ExfilSquad dumps UK police contact data China-linked hackers shrink the patch window Get the show notes…
Hackers Breach Police Legal Database, Steal Contact Details
Cyber-criminals breach Police National Legal Database and steal contact information for cops, members of public, after DfE hack
IT Security News Hourly Summary 2026-08-04 09h : 6 posts
6 posts were published in the last hour 7:2 : cPanel Database Privilege Escalation Flaw Enables Full Administrative Access 7:2 : Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System 7:2 : EU begins enforcing AI Act,…
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an…
Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System
Check Point has released security updates for a high-severity authentication-bypass vulnerability (CVE-2026-18574) that could allow attackers to…
EU begins enforcing AI Act, putting AI models under the microscope
Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities…
WhatsApp account takeover scam asks you to “vote for my friend”
Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.
Digital executive protection is a strategic imperative for CEOs
In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the…
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions,…
NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking…
OWASP’s subtractive security project measures the attack paths you erased
An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an…
Apple Removes Telegram From App Store Worldwide
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging…
Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This…
Telegram App Reportedly Vanished from Apple’s App Store Worldwide
Telegram Messenger briefly disappeared from Apple’s App Store across multiple countries late Monday, sparking a wave of confusion and speculation on…
Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials
An analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of…
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Automates bug bounty triage with Sonnet for $58 a month, CSO says Mythos would cost $200k
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by…
Fake IRS letters direct crypto holders to bogus compliance portal
Scammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll…
Cybersecurity jobs available right now: August 4, 2026
Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability…