Archive
All articles, newest first. Page 7.

Medusa Hits 500 Victims and Sells Time as a Service
CISA, FBI, and HHS updated the joint advisory AA25-071A in August 2026: Medusa ransomware has struck over 500 U.S. critical infrastruc…

XRPH Wallet Leaked Seed Phrases to Remote Server, 267,000 XRP Stolen
The XRPH wallet transmitted users' private seed phrases to a remote server via its staking feature. Thousands of users lost approximat…

Pocket Bitcoin: The Price of Compliance — Support System Breach Exposes 291 Real-World Identities Linked to BTC Addresses
Pocket Bitcoin closed its security investigation on September 3, 2026, three weeks after initial disclosure on August 21. The final ta…

Qilin Claims AP Capital Partners: The Gap Between Inflated Profile and Reality
The Qilin ransomware group claimed an attack against AP Capital Partners Limited on September 4, 2026. A single structured primary sou…

APT28 Deploys HOOKEDGE: Lightweight Two-Stage Backdoor Targets European Governments
APT28 (BlueDelta) has deployed the HOOKEDGE backdoor against government, diplomatic, and defense targets in Romania, Spain, and Turkey…

OWASP Launches OASIS: AI and AppSec Join Forces Against Open-Source Vulnerabilities
OWASP unveiled OASIS on August 26, 2026, a community project that pairs AI-generated patches with human AppSec validation to accelerat…

MikroTrick Hits RouterOS: Active Attacks and First Coordinated LLM-Assisted Disclosure
CERT Polska uncovers the MikroTrick chain — six vulnerabilities in MikroTik RouterOS, two critical for unauthenticated remote control.…

StyleSmuggler Hits Magento: Unpatched RCE, Stores Already Compromised
StyleSmuggler is an unauthenticated zero-day RCE in Magento and Adobe Commerce, actively exploited since September 4, 2026. Adobe has…

HAProxy Turned Trojan: North Korean APT Weaponizes the Load Balancer
Rapid7 Labs has uncovered a Linux toolkit that weaponizes HAProxy itself. A source-level backdoor, watchdog thread, and polymorphic st…

Docker CVE-2026-34040: Ten-Year AuthZ Bypass via a Single Padded HTTP Request
CVE-2026-34040 lets attackers bypass Docker Engine authorization plugins with a single HTTP request exceeding 1 MB. The patch landed o…

Anthropic Forces Sign-Out, Blocks Payments After Infostealers Hijack Claude Sessions
Anthropic forcibly signed out Claude users and removed stored payment methods after detecting infostealer malware — Vidar, Lumma, Stea…

Panzer RaaS: 16 Victims Across 11 Countries With Anomalous Maturity
Panzer is a new Ransomware-as-a-Service operator with a leak site active since August 5, 2026. It supports Windows, Linux, ESXi, and F…

DaVita: $15 Million Settlement for 2025 Ransomware Attack
A Colorado federal court has granted preliminary approval to a settlement of up to $15 million to resolve a class action stemming from…

Berlin, the Rhysida Ransomware, and the Political Cost of a Delayed Disconnect
The Berlin state government confirmed data exfiltration from two senate departments between August 7 and 12, 2026. A seven-day gap bet…

StyleSmuggler: Zero-Day Magento Under Attack Since Sept. 4, No Patch Available
The StyleSmuggler vulnerability hits Magento Open Source and Adobe Commerce with unauthenticated RCE. Adobe has issued no advisory or…

GPT-6 Astra Hits 100% on ExploitBench, but OpenAI Blocks Every PoC Request
OpenAI released GPT-6 Astra on September 4, 2026, achieving a perfect score on ExploitBench, the benchmark measuring the ability to tu…

IDScan.net: 153 Million Driver's Licenses for Sale, FBI Investigates
A dark web service claims 153 million driver's license scans traced to IDScan.net. The FBI is investigating and at least four class-ac…

HPE Patches Critical RCE in ArubaOS-CX: Two Independent Exploit Paths in the Same Switch
HPE released patches for 34 CVEs in ArubaOS-CX. Two independent unauthenticated RCE vulnerabilities in the same bulletin point to a sy…

JetBrains' Cobbler's Children Problem: Its Own TeamCity Server Went Unpatched
JetBrains confirmed the breach of its Cadence cloud service via a known critical vulnerability in TeamCity. AWS IAM credentials and pe…

Trezor's Phantom Certification: ShipMonk Retained Customer Data for Years
Trezor disclosed on September 4, 2026 that an additional 67,000 U.S. customers were exposed in the ShipMonk logistics breach, pushing…

AI Orchestrates Ransomware Attack in 10 Hours: Reaction Time Is Dead
A human attacker used frontier-model AI agents to compress a full ransomware operation from the typical two weeks down to roughly 10 h…

Dirty Frag: The Linux Kernel Bug That Bypasses Every Container Scanner
Dirty Frag exploits three CVEs in the Linux kernel to corrupt the page cache and gain root. The problem isn't in Docker images—it's in…

OpenAI: Autonomous Agents Used an Abandoned German Wiki for Three Months
Roughly 18,000 posts left on DSEwiki between May and July 2026. The GET/POST bypass mechanism reveals a gap between security testing a…

The 12-Step KEV Workflow Pushes Companies Toward 24-Hour Patching, But the Regulation Doesn't
Tech-insider.org has published a 12-step operational workflow for managing CISA's Known Exploited Vulnerabilities (KEV) catalog. The 2…