Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and…
Tag: EN
StyleSmuggler Flaw Allows Attackers to Exploit Zero Day With Remote Code Execution
Threat actors are exploiting a newly found zero-day flaw in Magento Open Source and Adobe Commerce to install persistent backdoors and compromise online…
Financial Firms Inundated By AI Security Findings, FCA Warns
AI tools finding security flaws in financial services firms’ infrastructure faster than they can be patched, says regulator
OpenAI’s rebel agent swarm died young, but its chilling logs live on
‘The Collective’ learned to communicate, organize, cheat, and apparently sacrifice its own
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management…
Europol and European Labour Authority strengthen cooperation against labour exploitation
The Working Arrangement formalises cooperation that has already demonstrated its value through joint involvement in EMPACT activities. It provides a…
OpenAI Confirms AI Agents Wrote to Multiple Internet Sites in ‘Wiki Incident’
OpenAI has acknowledged that its AI agents posted content on multiple internet sites during an event it has termed the “wiki incident.” The company…
Top 10 Best Network Security Policy Management Tools in 2026
Tufin scores highest in our 2026 evaluation of network security policy management (NSPM) tools, with AlgoSec close behind on application-centric…
Nvidia To Buy Hugging Face For $12.9bn
Leading AI chipmaker to purchase major AI developer platform as Hugging Face chief speaks of ‘turning point’ for open-source AI
Russian Hackers Use New HOOKEDGE Backdoor to Spy on European Organizations
Russian hackers have used a Windows backdoor called HOOKEDGE in espionage operations against diplomatic, government, and defense-related organizations…
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits…
Hackers Actively Exploiting PaperCut Servers Command Execution Vulnerabilities
Two critical vulnerabilities in PaperCut servers, CVE-2026-81578 and CVE-2026-82078, are being actively exploited, allowing attackers to execute commands,…
WRAITH – Browser Hooking and Blind XSS Page Mirroring
WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code on Database Servers
A newly disclosed PostgreSQL vulnerability, tracked as CVE-2026-6471 and nicknamed PostGREShell, could allow attackers with low-level replication access…
Nscale In $3.5bn Compute Deal For Figure Humanoid Robots
Data centre provider Nscale to supply at least $3.5bn of compute to Figure AI, becomes shareholder in humanoid robot maker
OpenAI Confirms ‘wiki Hijack,’ and Says It’s Working on a Framework for Disclosure Details
OpenAI has confirmed that its AI agents wrote to several internet sites during what it calls the “wiki incident,” also described online as the “wiki…
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean…
Berlin Ransomware Leak Exposes State Secrets
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a…
A week in security (August 31 – September 6)
Last week on Malwarebytes Labs: Stay safe!
