Archive
All articles, newest first. Page 14.

Stripe: 1,033 Vendor API Keys Exposed, Satanic Claims ~20,000 Total
Threat actor Satanic published data from 669 Stripe vendors containing over 1,000 live API keys. Hudson Rock found no infostealer infe…

CISA Orders September Patches: Two Critical TrueConf Flaws Actively Exploited
CISA added two critical TrueConf Server vulnerabilities to the KEV catalog, already exploited by the Head Mare group to deploy Phantom…

wp2shell: 45 Million Exploit Attempts in 7 Days — Vulnerability Management Hits a Breaking Point
The wp2shell campaign generated 45 million exploit attempts in one week. The data proves traditional vulnerability management is no lo…

Coldcard: 2021 Seed Bug Drains 1,778 BTC; Firmware Fix Released August 20
Coinkite issued corrective firmware on August 20, 2026, after an entropy bug present since March 2021 enabled the theft of over 1,778…

Cisco Patches Firewall Zero-Day: DoS via VPN Actively Exploited
CVE-2026-20349 hits Cisco ASA/FTD firewalls with unauthenticated remote DoS. CISA mandates patching by August 14 for U.S. federal agen…

Five US Agencies: Generative AI Is Accelerating Attacks on Siemens S7 PLCs
NSA, CISA, FBI, DOE, and EPA issued a joint advisory on August 19, 2026, warning that unidentified threat actors are using generative…

Google Mandiant Unveils AVDH Architecture: AI Agents vs. Vulnerabilities
Google's Threat Intelligence Group has disclosed the Agentic Vulnerability Discovery Harness (AVDH), a multi-agent system built on lar…

Amazon Smart Plug: OTA Certificate Bypass Allows Malicious Firmware
The ZDI-26-558 vulnerability in the Amazon Smart Plug's Over-The-Air update process lets a network-adjacent attacker bypass TLS certif…

HollowGraph: APT Malware Turns M365 Calendars into Covert C2 Channel
HollowGraph exploits the Microsoft Graph API to transform compromised account calendars into bidirectional command-and-control channel…

Windows ShieldBreak Zero-Day: Researcher Publishes Exploit Targeting Defender
Nightmare Eclipse released ShieldBreak, a zero-day exploit that weaponizes Windows Defender for local privilege escalation. The exploi…

NVIDIA Transformers4Rec: RCE with CVSS 4.3 — The Risk Scoring Gap
A deserialization flaw in NVIDIA Transformers4Rec enables remote code execution, yet the official CVE record rates it 4.3 MEDIUM with…

GitLab's 'Future Field' Security Feature Turns Weapon: Emergency Patches for CVE-2026-19478
GitLab released critical patches on August 17, 2026 for CVE-2026-19478, a GraphQL code injection vulnerability with a CVSS 9.4 score t…

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited
Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

CVE-2026-59310: vCenter Exploited in 5 Days, 360+ IPs Compromised
A critical VMware vCenter vulnerability went from patch to in-the-wild exploitation in just five days. Over 360 IP addresses across 47…

CISA Adds Apple Zero-Day CVE-2025-43300 to KEV Catalog: CVSS 10, September 11 Deadline
CISA has cataloged CVE-2025-43300, an out-of-bounds write in Apple ImageIO rated CVSS 10.0 CRITICAL. Federal civilian agencies must pa…

CopyEscape: How docker cp Turns a Routine Log Copy into Host Root
On August 12, 2026, Imperva Research disclosed CVE-2026-17106, a flaw in the docker cp command that lets a malicious container overwri…

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request
A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

DeadLock Leverages Polygon and Session for Takedown-Resistant Ransomware Infrastructure
Microsoft Threat Intelligence dissects DeadLock, a Rust-based ransomware that has compromised over 80 organizations since July 2025, w…

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams
Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

Android Malware in Car Head Units: Vehicles Become Gig-Economy Nodes
Kaspersky discovered in June 2026 a new Android malware family that infects DoFun automotive head units through their built-in TWCore…

Linux Kernel CVSS 9.1 Bug: KSMBD Exposes Sensitive Memory Remotely Without Authentication
On August 13, 2026, the Trend Micro Zero Day Initiative published advisory ZDI-26-573, a critical vulnerability in the Linux kernel's…

isolated-vm: C++ Binding Layer Bug Enables Sandbox Escape to Host RCE
A TOCTOU vulnerability in the Node.js isolated-vm library allows guest-to-host escape with potential RCE. Versions 6.2.0 and 7.0.1 pat…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts from 65 IPs in 41 Days
On August 7, 2026, CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog. The flaw in Progress Kemp LoadMaster, rate…

Megalodon: 5,561 GitHub Repositories Compromised in 6 Hours
The Megalodon campaign injected malicious workflows into thousands of GitHub repositories, exfiltrating CI/CD tokens. The Tiledesk cas…