Archive
All articles, newest first. Page 15.

Qualcomm BootROM Bug Lets Attackers Bypass Secure Boot in Minutes
Kaspersky ICS CERT disclosed CVE-2026-25262, a Write-What-Where condition in the BootROM of seven Qualcomm chipset series. Physical US…

Oracle Denies Breach, But Researchers and Customers Confirm: The Data Is Real
On March 20, 2025, a hacker using the alias _rose87168_ posted on BreachForums offering more than 6 million records stolen from over 1…

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks
The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

Lazarus Hits Windows Kernel: Zero-Day CVSS 7.0 with APT Impact
North Korea's Lazarus Group actively exploited CVE-2026-68820, a zero-day in the Windows AFD.sys driver, for over five weeks to gain S…

Zimbra SNMP RCE Under Active Exploitation, CVSS 8.9, Over 12,000 Servers at Risk
CVE-2026-73570 enables unauthenticated RCE via Zimbra's optional SNMP component. CERT Polska confirms active exploitation; patch avail…

SonicWall SMA 1000 Under Attack: CVE-2026-15409 CVSS 10.0 and TOTP Seed Theft
CVE-2026-15409 and CVE-2026-15410 exposed SonicWall SMA 1000 appliances to unauthenticated root compromise. The theft of MFA seeds ren…

Cl0p Exploits PTC Windchill Zero-Day to Steal 100+ GB from Shell and Philips
The Cl0p ransomware group claims theft of over 100 GB of industrial data from Shell and Philips by exploiting CVE-2026-12569. The camp…

iVerify Uncovers DarkSword, iOS Exploit Framework That Bypasses Safari Without Persistence
iVerify published a technical analysis of DarkSword, a sophisticated multi-stage iOS exploit framework that leverages JavaScriptCore J…

Exposed Directory Reveals Autonomous AI Fleet for Industrial-Scale Crypto Theft
A Chinese-speaking operator orchestrated entire offensive campaigns using multi-vendor AI agents in full-auto mode. A misconfiguration…

Intel Researchers Found Two Flaws in AMD TPM Firmware — The Patch Was Already Ready
AMD confirmed two TPM 2.0 vulnerabilities across its processor lineup on August 11, 2026 via security bulletin AMD-SB-7064. The flaws,…

Trend Micro VPN: Local Privilege Escalation Flaw Allows SYSTEM Takeover
A local privilege escalation vulnerability in Trend Micro VPN, tracked as ZDI-26-577 and CVE-2026-67212, lets an attacker with low-pri…

NGINX DAV: Pre-Auth RCE Discovered by Calif.io in Collaboration with
CVE-2026-27654 in the NGINX HTTP DAV module: an integer underflow triggered by an alias in a prefix location enables unauthenticated r…

Notepad++: Institutional Alert Arrives Four Months After the Fix
Singapore's Cyber Security Agency published an advisory on CVE-2026-3008, a string injection flaw in Notepad++ 8.9.3 with a CVSS 6.6 s…

Ransom Busters: The Double-Cross Undermining the RaaS Model From Within
A ransomware affiliate operates as a fake recovery firm, contacting victims before attacks are published. GuidePoint Security GRIT doc…

Cisco ISE: Patch Available for Directory Traversal CVE-2026-20148
A path traversal vulnerability in Cisco Identity Services Engine allows an authenticated remote attacker to read arbitrary files. A pa…

Private APN Emerges as New OT Attack Vector: Polish Cogeneration Plant Compromised
CERT Polska has documented the first real-world case of a private APN being used as an attack vector against operational technology. A…

Akira in Safe Mode: Blind EDR and the Ransomware That Collapsed From Memory Starvation
An Akira affiliate disabled EDR by forcing a reboot into Safe Mode with Networking, but the ransomware payload crashed with "Out of Vi…

TeamPCP/UNC6780: Six Enterprise Breaches From Trivy to LiteLLM
The TeamPCP/UNC6780 campaign compromised Trivy to poison LiteLLM on PyPI. According to Hudson Rock, six enterprise breaches resulted w…

Digital Garbage Hits the Cloud Core: Indiscriminate Scanning
SANS Dean of Research Johannes Ullrich documented widespread, untargeted scanning against the Cloud Metadata Service address 169.254.1…

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours
Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…

GeoServer Zero-Day Under Fire: Hundreds of Exploit Attempts in Hours, Patches Released
A zero-day SQL injection in GeoServer was massively probed within hours of disclosure. The flaw is a regression of a 2023 vulnerabilit…

DecryptAds Exposes the Invisible: The Ad Supply Chain Under the Microscope
DecryptAds parses ads.txt and sellers.json files, revealing hidden links between mainstream sites, data brokers, and geopolitical acto…

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data
The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…

NFV and 5G: The Paradox of European Digital Sovereignty
An intelligence report highlights systemic privilege-escalation vectors in European 5G SA networks. The MANO orchestration plane has b…