] The Mad Hacker [

online
mad hacker

Collecting all the news about Cybersecurity, computer security, cracking, hacking, infosec, netsec, & security vunerabilities in one convenient place

Whitehat, greyhat, blackhat, tinker, tailor, solider, spy
We trawl the web so you don't have to
Since 2000

the mad hacker overlay

Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors

(Friday August 14, 2026)

President Trump has signed a national security presidential memorandum allowing federal law enforcement agencies to partner with private technology companies to execute offensive cyber operations against foreign criminal groups and international adversaries. Under the directive, vetted private sector tech firms will be permitted to work under direct federal supervision to propose, coordinate, and execute targeted […]

The post

Data analyst sent to prison for stealing data, extorting employer

(Friday August 14, 2026)
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]

Meet Huntress at International Cyber Expo 2026

(Friday August 14, 2026)

Huntress will be heading to International Cyber Expo 2026, where visitors can meet the team on Stand K94 and discover how the company is helping organisations tackle increasingly complex cyber threats with fewer resources. One of the biggest challenges Huntress is seeing is the growing attack surface. Security teams are expected to protect endpoints, identities, […]

The post

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

(Friday August 14, 2026)
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]

Software

(Friday August 14, 2026)
Click the link for more details on Software

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

(Thursday August 13, 2026)
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

(Thursday August 13, 2026)
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]

Get printer model without bonjour

(Thursday August 13, 2026)
Enable JavaScript and cookies to continue

Hackers breach govt webmail while running parallel crypto fraud

(Thursday August 13, 2026)
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]

Microsoft patches LegacyHive Windows zero-day vulnerability

(Thursday August 13, 2026)
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]

AI 'watermark removers' flood the web. Almost none can prove they work.

(Thursday August 13, 2026)
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]

Critical VMware vCenter RCE flaw exploited for reverse SSH access

(Thursday August 13, 2026)
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

Trezor discloses data breach affecting nearly 14,000 customers

(Thursday August 13, 2026)
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

(Thursday August 13, 2026)
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]

White House taps security firms for offensive hack-back operations

(Thursday August 13, 2026)
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]

Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam

(Thursday August 13, 2026)

Security researchers have identified a phishing campaign that abuses Shopify’s own Shop app to deliver fake order and refund notifications directly to victims’ phones, marking a notable evolution of the classic “fake refund” scam. According to research from cybersecurity firm Huntress, attackers are creating fraudulent Shopify seller accounts, or hijacking legitimate ones, to generate bogus...

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

(Thursday August 13, 2026)

An affiliate of the Akira ransomware operation attempted a novel technique to blind endpoint defences during a recent intrusion, rebooting a compromised server into Windows Safe Mode to knock out both an EDR agent and Microsoft Defender in one move, only for the same stripped-down environment to cause the ransomware payload itself to crash before […]

The post

Is AI entering the SOC at the right stage?

(Thursday August 13, 2026)

By Simon Phillips, CTO, CybaVerse Alert fatigue is an issue that has plagued Security Operations Centres for years. As organisations’ digital estates grow, there is more architecture to secure and more architecture for threat actors to attack, which has ultimately led to more alerts. Today, on average a SOC will face thousands of alerts every […]

The post

WhatsApp rolls out new feature that flags potential scam messages

(Thursday August 13, 2026)
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]

Separating AI’s Technological Problems from Its Capitalism Problems

(Thursday August 13, 2026)
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press. AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technologies like the steam engine provided a quantum leap in our ability to do mechanical work outside of our bodies at scale. If AI’s...

Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks

(Thursday August 13, 2026)

Forescout has launched a new Rapid Insight Assessment designed to help organisations uncover hidden assets, network blind spots, and security exposures as artificial intelligence accelerates vulnerability discovery. The new assessment combines external analysis with passive network monitoring to give security teams a clearer picture of their attack surface. Forescout says the service can deliver actionable […]

The post

UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

(Thursday August 13, 2026)

UK organisations were hit by an average of 1,597 cyber attacks per week each in July 2026, a 26% increase year-on-year, according to new data from Check Point Research, the threat intelligence arm of Check Point Software Technologies. The growth rate outpaced the 16% year-on-year rise recorded globally, even though UK attack volumes remained below […]

The post

Imperva API Security Token & Authentication Risk Report: Nearly 40% of APIs Face Multiple Authentication Risks

(Thursday August 13, 2026)

Every year, the security industry publishes benchmark reports built more or less the same way: pick a handful of common vulnerabilities, measure how often they show up, publish the percentages, and move on. We just finished our second year running one of those reports — and the most important thing we found wasn’t a percentage. […]

The post

Ongoing phishing, targeting financial institutions and using Telegram as their C2

(Thursday August 13, 2026)
Click the link for more details on Ongoing phishing, targeting financial institutions and using Telegram as their C2

Platforms failed to stop death threats against activists, report says

(Thursday August 13, 2026)
Advocates against the sexualisation of girls in media detail the abuse and threats of violence they received after petitioning for the removal of video games featuring gendered violence.

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

(Thursday August 13, 2026)
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

Where in the kernel is my "Failed to setup vendor infoframe on connector HDMI-A-2: -22" dmesg coming from?

(Thursday August 13, 2026)
Enable JavaScript and cookies to continue

Globbing episode numbers every quintuplet

(Thursday August 13, 2026)
Enable JavaScript and cookies to continue

Smashing Security podcast #480: This is the AI service you should never sign up to

(Wednesday August 12, 2026)
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft...

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

(Wednesday August 12, 2026)
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

Android malware combo takes out loans and relays victims' credit cards

(Wednesday August 12, 2026)
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

(Wednesday August 12, 2026)
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]

Connecting end of life Mac OS to the internet - mitigate the risk

(Wednesday August 12, 2026)
Enable JavaScript and cookies to continue

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

(Wednesday August 12, 2026)
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution

(Wednesday August 12, 2026)

Multiple vulnerabilities have been discovered in SonicWall Global Management System (GMS), the most severe of which could allow for remote code execution. The SonicWall Global Management System (GMS) is a centralized management interface used to deploy and centrally manage SonicWall firewall, wireless, email security, secure remote access and Dell X-Series solutions...

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

(Wednesday August 12, 2026)

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create...

A Vulnerability in Zoom Clients Could Allow for Remote Code Execution

(Wednesday August 12, 2026)

A vulnerability has been discovered in Zoom Clients that could allow for remote code execution. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and install malware.

Editing an invoice

(Wednesday August 12, 2026)
Click the link for more details on Editing an invoice

This Coin-Sized Device Can Hack a Boeing 737

(Wednesday August 12, 2026)
Click the link for more details on This Coin-Sized Device Can Hack a Boeing 737

Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense

(Wednesday August 12, 2026)

Vega, the pioneer of Agentic Cyber Defense, today launched Detection Skills: an open standard that redefines security operations for the AI era. The standard captures a team’s expert judgment as a self-improving agentic loop across detection, triage, and investigation. Available to the community as an open standard, or natively within the best-in-class Vega platform, they […]

The post

Find common part of filenames and group those files together in new directory

(Wednesday August 12, 2026)
Enable JavaScript and cookies to continue

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

(Wednesday August 12, 2026)
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66

Dieharder test 102 print empty rows

(Wednesday August 12, 2026)
Enable JavaScript and cookies to continue

Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Data from the breach is now available

(Wednesday August 12, 2026)
Click the link for more details on Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Data from the breach is now available

Interactively finding last line with match using ed; understanding ";" when addressing lines

(Wednesday August 12, 2026)
Enable JavaScript and cookies to continue

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

(Wednesday August 12, 2026)
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,

Enterprise Defenses Recovered at the Edge and Collapsed Inside

(Wednesday August 12, 2026)
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

(Wednesday August 12, 2026)
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could

Prompt Injections for Defense

(Wednesday August 12, 2026)
This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking...

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

(Wednesday August 12, 2026)
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were

Weekly Update 516: Live From Vietnam

(Wednesday August 12, 2026)

Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

(Wednesday August 12, 2026)
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

(Wednesday August 12, 2026)
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an

How many passes of MemTest86+ are recommended for a RAM test?

(Wednesday August 12, 2026)
Enable JavaScript and cookies to continue

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

(Wednesday August 12, 2026)
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

(Wednesday August 12, 2026)
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger

Microsoft Plugs Nearly 400 Security Holes

(Tuesday August 11, 2026)
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

(Tuesday August 11, 2026)
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

(Tuesday August 11, 2026)
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

(Tuesday August 11, 2026)
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

(Tuesday August 11, 2026)
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

Critical Patches Issued for Microsoft Products, August 11, 2026

(Tuesday August 11, 2026)

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create...

How Trail of Bits helps verify the integrity of your Signal chats

(Tuesday August 11, 2026)

Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt messages to an attacker rather than the intended recipient.

Until now, the only way to detect such malfeasance was to verify safety...

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

(Tuesday August 11, 2026)

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

  • Adobe ColdFusion is a commercial rapid web application development platform and application server.
  • Adobe Commerce is an enterprise-level e-commerce platform built on the proven technology of Magento.
  • Adobe Lightroom is a popular cloud-based image...

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

(Tuesday August 11, 2026)
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

(Tuesday August 11, 2026)
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White

(Tuesday August 11, 2026)

Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage.  Geoff White is an award-winning investigative journalist whose reporting has taken him inside global […]

The post

AI Genie in the Wild

(Tuesday August 11, 2026)
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened. The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible. Andrew, who was sitting fourth on a waitlist for a...

How to know virtual disk size using VMware Workstation Pro CLI?

(Tuesday August 11, 2026)
Enable JavaScript and cookies to continue

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

(Tuesday August 11, 2026)
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

(Tuesday August 11, 2026)
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

(Tuesday August 11, 2026)
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for

How do you prove a dependency doesn't need to be updated?

(Tuesday August 11, 2026)
Enable JavaScript and cookies to continue

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

(Tuesday August 11, 2026)
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The

AI for Military Support

(Tuesday August 11, 2026)
Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting. After reconstructing the interface and functionality of...

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

(Tuesday August 11, 2026)
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

(Tuesday August 11, 2026)
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

(Tuesday August 11, 2026)
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

(Tuesday August 11, 2026)
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

(Tuesday August 11, 2026)
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

CopyEscape: Taking Over Docker Hosts with docker cp

(Tuesday August 11, 2026)

Imperva Red Team uncovered CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp command. Docker later confirmed that the same CVE also affected sbx cp when copying files out of Docker Sandboxes. A malicious container or sandbox could exploit the copy process to create or overwrite files outside the destination selected by the user, […]

The post

Embedded Broadcast Storm Protection on Linux?

(Tuesday August 11, 2026)
Enable JavaScript and cookies to continue

Imperva Customers Protected Against XSS2Shell (CVE-2026-64638) in WordPress Core

(Monday August 10, 2026)

TL;DR: CVE-2026-64638, dubbed XSS2Shell, is a high-severity WordPress Core vulnerability that begins as a pre-authentication reflected XSS on the login screen and can be chained to PHP code execution when a logged-in administrator is successfully targeted. WordPress fixed the issue in 7.0.3 and backported the fix through maintained branches. Imperva Cloud WAF and On-Prem WAF […]

The post

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

(Monday August 10, 2026)
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

(Monday August 10, 2026)
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise 

(Monday August 10, 2026)

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise.

The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the...

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

(Monday August 10, 2026)
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

(Monday August 10, 2026)

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.

The post

Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive

(Monday August 10, 2026)

Margarita Howard has spent two decades running a company in a government contracting market where the rules rarely hold still. HX5, the defense and aerospace services firm she founded in 2004 and still leads, supports Department of Defense and NASA missions and has employed over 1,000 people across 34 states and 90 government locations over […]

The post

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

(Monday August 10, 2026)
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

(Monday August 10, 2026)
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a 

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

(Monday August 10, 2026)
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain

Python Now Has a Post-Quantum Encryption Library

(Monday August 10, 2026)
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography. Remember, the reason to do this now is because there’s no emergency. And because you will make your...

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

(Monday August 10, 2026)
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

(Monday August 10, 2026)
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated

How to Audit Your Own Digital Footprint: A Step-by-Step Guide to Evaluate Your Online Presence

(Sunday August 09, 2026)

In an increasingly digital world, understanding personal online presence has become essential. Many individuals overlook the importance of assessing their digital footprint, which can affect privacy, reputation, and security. Auditing one’s digital footprint involves evaluating online accounts, social media activities, and search results to gain insights into what information is publicly accessible. By taking the […]

The post

LMTP Delivery to public mailbox

(Sunday August 09, 2026)
Enable JavaScript and cookies to continue

What SecureIQLab Cloud WAAP 5.0 means for your application security

(Sunday August 09, 2026)

You cannot verify a vendor’s security claims from their own datasheet, including ours. That is why independent validation matters. In our recent guide to the best WAAP solutions (Best WAAP Solutions 2026: Enterprise Buyer Guide), we argued that every serious shortlist should include independent third-party testing across both web and API threats. SecureIQ Lab’s Cloud […]

The post