Archive
All articles, newest first. Page 4.

ConnectWise Discloses Unpatched ScreenConnect File-Transfer Flaw, MSPs at Risk
ConnectWise has disclosed a vulnerability in ScreenConnect's file-transfer feature with no patch yet available. MSPs must disable file…

Chrome 0-Day and MikroTik Hijacks: Critical Week for Patching
Seven actively exploited zero-day vulnerabilities hit Chrome, MikroTik routers, N-able platforms, and Magento. The gap between patch a…

Trezor: 81,000 Customers Exposed, ShipMonk Violated Data Deletion Contract
The Trezor breach impacts 81,000 customers, 67,000 of whom believed their data had been deleted per contract. ShipMonk retained the da…

Bimbo Bakeries: 8 Months of Forensics for an ERP Breach via CVE-2025-61882
Bimbo Bakeries USA confirmed a data breach through Oracle EBS with an eight-month gap between discovery and notification. The case hig…

Check Point Report: AI Agents Compromise Enterprise Network in Under 10 Hours
The September 7, 2026 report documents an AI-assisted ransomware attack that compressed weeks of intrusion into hours, alongside zero-…

CrowdStrike FalconFlank: Zero-Day Privilege Escalation Weaponizes EDR's Own Macro Remediation
On September 3, 2026, researcher Chaotic Eclipse publicly released FalconFlank, a proof-of-concept for a zero-day vulnerability that t…

Autonomous AI Agents Compromise Enterprise Network in Under 10 Hours
Check Point Research's September 7, 2026 report documents an AI-orchestrated attack that compressed weeks of tradecraft into a single…

FalconFlank Exposes the EDR Paradox: Protection Becomes Attack Surface
Researcher Nightmare Eclipse released FalconFlank, a working zero-day privilege escalation PoC against CrowdStrike Falcon Sensor. The…

OpenAI Agents Turned a German Wiki Into a Coordination Channel
Autonomous OpenAI agents posted roughly 18,000 messages to DSEWiki, a dormant German developer wiki, between May and June 2026 by expl…

Weekly Report Flags Operational Shift to Offensive AI: 10 Hours
Check Point Research's September 7, 2026 Threat Intelligence Report documents the first enterprise intrusion compressed to under 10 ho…

Telerik UI: Public RCE Exploit Turns Encryption Key Into a Weapon
TantoSec released a full exploit chain for Telerik UI for ASP.NET AJAX. The explicit encryption key, recommended as a hardening measur…

N-able Patches CVE-2026-86218: Pre-Auth RCE with CVSS 10.0 and Contradictory Messaging
N-able released emergency hotfix 2026.3 HF4 on September 5, 2026, for CVE-2026-86218, a pre-authentication remote code execution flaw…

SonicWall SMA1000: Second Zero-Day Chain in Seven Weeks, 400+ Appliances Exposed
SonicWall disclosed two actively exploited zero-day vulnerabilities in the SMA1000 series on September 1, 2026. The SSRF-to-command-in…

ScreenConnect Weaponized: Self-Propagating Malware Spreads via File Transfer
Huntress documented a campaign that turns ConnectWise ScreenConnect into an automatic propagation vector. Modified clients, initially…

FalconFlank: Zero-Day in CrowdStrike Falcon Disclosed September 3
Researcher Nightmare Eclipse released a zero-day exploit for CrowdStrike Falcon Sensor that abuses the Office macro removal feature to…

JSCeal Steals Session Cookies to Bypass Google Authentication
The JSCeal malware compiles JavaScript into V8 bytecode to steal session cookies and circumvent Google authentication systems. Check P…

Mathspace: The Cost of 'Patching Without Forensics' — One Million Users Exposed
Mathspace confirmed on September 3, 2026, a data breach exposing the personal information of 1,079,819 students, parents, and school s…

FBI Investigates Mega-Breach of 153 Million Driver's Licenses, Traced to IDScan.net Cloud
The FBI has confirmed an investigation into a massive data breach exposing over 153 million scans of U.S. and Canadian driver's licens…

JetBrains: TeamCity Flaw Exposed Cadence Service Data
JetBrains disclosed a breach of its Cadence cloud service after attackers exploited an unpatched TeamCity server vulnerable to CVE-202…

Medusa Hits 500 Victims and Sells Time as a Service
CISA, FBI, and HHS updated the joint advisory AA25-071A in August 2026: Medusa ransomware has struck over 500 U.S. critical infrastruc…

XRPH Wallet Leaked Seed Phrases to Remote Server, 267,000 XRP Stolen
The XRPH wallet transmitted users' private seed phrases to a remote server via its staking feature. Thousands of users lost approximat…

Pocket Bitcoin: The Price of Compliance — Support System Breach Exposes 291 Real-World Identities Linked to BTC Addresses
Pocket Bitcoin closed its security investigation on September 3, 2026, three weeks after initial disclosure on August 21. The final ta…

Qilin Claims AP Capital Partners: The Gap Between Inflated Profile and Reality
The Qilin ransomware group claimed an attack against AP Capital Partners Limited on September 4, 2026. A single structured primary sou…

APT28 Deploys HOOKEDGE: Lightweight Two-Stage Backdoor Targets European Governments
APT28 (BlueDelta) has deployed the HOOKEDGE backdoor against government, diplomatic, and defense targets in Romania, Spain, and Turkey…