Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
Scientists turn DNA into a memory device that uses 100x less power
Researchers combined synthetic DNA with a semiconductor to create an ultra-low-power memory device capable of storing and processing information in the…
Police bust cybercrime ring accused of stealing €30 million in four-day spree
German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting…
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
A seller claims 1.7M McDonald’s employee records were stolen from Azure. An 8,000-row sample appears genuine, but its age and full size remain…
Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware
A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering…
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
PLUS: HCL, TCS, admit data breaches; South Korea to fine Apple, Google; India bans some rideshare tips; and more!
IT Security News Hourly Summary 2026-08-17 10h : 14 posts
14 posts published in the last hour 07:32Akira Ransomware Uses Safe Mode to Bypass EDR 07:31GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution 07:31Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices…
Akira Ransomware Uses Safe Mode to Bypass EDR
Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate…
GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution
A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under…
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that…
SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach
Max severity SAP Commerce Cloud flaw now targeted in attacks New Mirai variant adds stealth capabilities to botnet code Shell investigates potential…
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300…
A week in security (August 10 – August 16)
A list of topics we covered in the week of August 10 to August 16 of 2026
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to…
Black Hat and DEF CON are AI conferences now, too
On this week’s episode of The Reg’s Kettle podcast, we revisit ‘hacker summer camp,’ where the hottest topic was … sigh… agentic AI
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation,…
ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token
The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm…
Safepal Confirm Hackers Gained Access to Customer Order Information
SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in.…
Weekly Recap! – Top 50 Biggest Cybersecurity Stories of the Week: Apple Spyware, Zoom Zero-Click RCE, VMware vCenter Exploits, Microsoft Patch Day & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.
IT Security News Hourly Summary 2026-08-17 09h : 6 posts
6 posts published in the last hour 06:31Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes 06:02The OWASP LLM Top 10 Was the Warm-Up: What Comes Next 06:0212 KB Backdoor Masquerades as Realtek Software and Hides C2 in…
Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes
A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems,…
The OWASP LLM Top 10 Was the Warm-Up: What Comes Next
When the OWASP Top 10 for LLM Applications arrived, it did the industry a real service. It gave security teams a stable, vendor-neutral vocabulary for a…