Archive
All articles, newest first. Page 8.

SonicWall SMA 1000: Two Chained Zero-Days Enable Unauthenticated RCE
SonicWall patched two actively exploited zero-days in SMA 1000 appliances that chain for unauthenticated remote code execution. CISA o…

BOD 26-04: CISA Compresses Patch Deadlines but Recommends, Doesn't Mandate Them
A tech-insider.org operational tutorial outlines a 12-step KEV workflow with a 24-hour deadline. CISA recommends it for federal agenci…

FalconFlank: 0-day PoC Targets CrowdStrike Falcon, Disable Macro Policy
Nightmare Eclipse released FalconFlank, a privilege-escalation proof-of-concept that weaponizes CrowdStrike Falcon's suspicious macro…

ASCII Smuggling: From AI Attack to 2.37 Million Phishing Emails
A technique originally developed for prompt injection against language models has spawned a financial phishing campaign exceeding 2.37…

From AI to Inbox: The 'Invisible' Technique That Flooded Corporate Email
Microsoft detected a campaign sending over 2 million messages per day by embedding invisible Unicode characters inside financial keywo…

HPE Patches Two Critical RCE Flaws in ArubaOS-CX: Structural Technical Debt
HPE released patches on September 1, 2026 for 34 vulnerabilities in the ArubaOS-CX (AOS-CX) platform, the operating system powering en…

G7 and CISA: The Quantum Threat Is Here, Time to Act Is Running Out
The G7 and CISA issued a joint advisory on September 3, 2026, turning post-quantum cryptography migration from a future concern into a…

"ted" Backdoor in HAProxy: Load Balancer Turned Spy in South Korea
Rapid7 Labs uncovered a previously undocumented Linux toolkit that injects the "ted" backdoor into HAProxy 2.8.12 to intercept traffic…

VMware Workstation: Critical Patches for VM Escape with CVSS 9.3
Broadcom has released updates for VMware Workstation and Fusion addressing two vulnerabilities rated CVSS 9.3 and 8.1. With no workaro…

OpenAI Commits $1 Billion to OT Defenders: Private Model Outpaces Federal Funding
OpenAI has pledged $1 billion in subsidized credits for its Daybreak for Frontline Defenders program, targeting under-resourced critic…

WordPress Under Fire: Over 440,000 Exploit Attempts Target Two Critical Plugins in Days
Threat actors have launched more than 440,000 exploit attempts against two unauthenticated arbitrary file upload vulnerabilities in wi…

AI-Driven Attacks in Latin America: Unit 42 Exposes Two Operational Clusters
Palo Alto Networks' Unit 42 has uncovered two ongoing multi-stage intrusion campaigns across Mexico, Ecuador, and Brazil that leverage…

Google Patches Chrome Zero-Day: Urgent Update for 3 Billion Users
Google released Chrome 152.0.7977.82 to fix CVE-2026-85046, an actively exploited zero-day in the V8 engine with a CVSS score of 8.8.…

CNIL Fines French Hospital €500K: 727,000 Profiles Exposed Without MFA or VPN
France's data protection authority fined Hôpital privé de la Loire €500,000 for a 2025 breach that exposed 727,113 individuals. The at…

ShinyHunters Tried to Hit ReliaQuest: Device-Trust Controls Stopped the Escalation
ReliaQuest confirms a contained social-engineering attack on August 22, 2026. Device-trust controls blocked lateral movement despite v…

StreamRat Reached 570,000 Meta Users via Paid Ads: The Malvertising Playbook
A malicious ad campaign distributed the Android malware StreamRat through sponsored ads on Meta and TikTok, exploiting the perceived l…

CVE-2026-20212: Cisco Nexus 9000 with Silicon One ASIC Exposed to Pre-Auth Root RCE
Cisco disclosed a critical vulnerability in Nexus 9000 Series Switches equipped with Silicon One ASIC. CVE-2026-20212 carries a CVSS 9…

BraZetsu: The Brazilian Malware Turning Every PC into a Dark Web Product
The Exilware threat actor's BraZetsu framework automates the compromise of Windows hosts and their resale on an underground marketplac…

Node.js Turns Trojan Horse: Signed Runtime Hides Targeted Malware
Symantec uncovers threat actors abusing node.exe — a legitimate, signed binary — to deliver malicious payloads against government and…

Plex Demands Urgent Update: Patches Before CVEs, Admins Left in the Dark
Plex urged users to immediately update Plex Media Server and Plex Desktop between September 1 and 3, 2026, without publishing the CVE…

Thomson Reuters C-Track Breach Exposes 14 Jurisdictions; Attack Vector Undisclosed
Thomson Reuters disclosed a breach of its C-Track court case-management platform affecting at least 12 U.S. states, the U.S. Virgin Is…

Backup Turned Weapon: How the All-in-One WP Migration Plugin Exposes 3.2 Million Sites
CVE-2026-19949: A second-order SQL injection in the WordPress plugin All-in-One WP Migration enables remote code execution via the res…

Pegasus Hits Serbian Activist: First Confirmed 2026 Infection
On September 2, 2026, Citizen Lab and SHARE Foundation published a forensic analysis of an iPhone belonging to a member of the Serbian…

GitHub Reveals the True Cost of Ingesting Threat Intelligence at Scale
The Dependabot lead details how ingesting 18 malicious packages per day across 30 million repositories demanded more validation engine…