Archive
All articles, newest first. Page 21.

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure
The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

INC Ransomware Chains Two SonicWall Zero-Days: Remote Access Becomes the Breach
INC Ransomware has emerged as the dominant threat actor in attacks against SonicWall SMA 1000 VPN appliances, weaponizing a chain of t…

Midnight Blizzard Weaponizes RDP Files in Spear-Phishing Campaign
Starting October 22, 2024, the APT group Midnight Blizzard (APT29, UNC2452, Cozy Bear), attributed to Russia's Foreign Intelligence Se…

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available
CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Battering RAM: $50 Physical Attack Bypasses SGX and SEV-SNP on DDR4 Systems
A sub-$50 DDR4 interposer compromises confidential computing. Vendors classify physical attacks as out of scope. Article based on a si…

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them
In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Valve: Steam Hardware Shipping Data Exposed in CEVA Logistics Attack
Valve notified European Steam hardware customers on August 7, 2026 that their shipping data was compromised in a cyberattack on logist…

The Microsoft 365 Account Takeover That Leaves No Trace
Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Notepad++ Updater Hijacked as Spy Gateway: What Happened
On February 2, 2026, developer Don Ho disclosed the compromise of the notepad-plus-plus.org hosting infrastructure, a sophisticated at…

aeon: RCE via eval() in Python Dataset Loading, Patch Released
ZDI-26-469 discloses a code injection vulnerability in the Python aeon library. The use of eval() during dataset loading allows arbitr…

Amazon Attributes NPM Supply-Chain Campaign to North Korean Groups — Months After Italy Flagged It
Amazon Threat Intelligence confirmed on August 5, 2026 that North Korean-linked hackers are behind recent NPM package compromises. CSI…

Dirty Frag: Linux Kernel LPE Chain with Public PoC and Patches Available
Dirty Frag is a two-vulnerability chain in the Linux kernel that enables root escalation on nearly all distributions. Mainline patches…

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile
NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability
Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Pirated 'The Odyssey' Downloads Hide Lumma Stealer: Windows Users Tricked by Fake Video Files
Cybercriminals are recycling a proven attack pattern to distribute Lumma Stealer through fake pirated copies of Christopher Nolan's Th…

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282
CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago
Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

China Launches Security Review of Palo Alto Networks: Self-Censorship Failed to Work
The Cyberspace Administration of China (CAC) opened a national security review of Palo Alto Networks products on August 6, 2026. The m…

Backdoored LiteLLM on PyPI: Malware Triggers on Python Startup Alone
On March 24, 2026, two malicious LiteLLM versions exfiltrated credentials from over 50 categories via a .pth mechanism. The compromise…

Barracuda Zero-Day: Mandiant Attributes CVE-2023-2868 to Chinese Espionage
Mandiant links the zero-day vulnerability in Barracuda Email Security Gateway to threat actor UNC4841 with high confidence, describing…

Suisun City Shuts Down Entire IT Network After Malware Attack: 911 Offline
A malware attack struck Suisun City at 5:45 a.m. on August 7, 2026, compromising 911, police and fire dispatch systems and forcing a t…

HTTP Terminator Proves AI Can Autonomously Discover Attack Techniques
James Kettle demonstrates that PortSwigger's HTTP Terminator AI system independently generates HTTP desynchronization techniques. The…

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft
A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

Phoenix Contact CHARX: Credentials in Logs Open EV Charging Stations to Attack
The ZDI-26-506 vulnerability in the Phoenix Contact CHARX SEC-3150 industrial charger exposes credentials in log files. A network-adja…