Cybersecurity
Curated coverage and analysis in this editorial area.

Parallels RAS Client: Local Vulnerability Allows Escalation to SYSTEM
CVE-2026-18263 affects the RAS RDP Backend Service with a CVSS 7.8 score. An exposed dangerous function allows low-privilege code to e…

SilkParasite Exposes the Line Between AI-Assisted and AI-Generated Malware
Bitdefender uncovered SilkParasite, a cyber-espionage campaign using seven RAT families and AI-assisted development to target governme…

Noodlophile Stealer: Malware Rides the AI Hype Wave Through Fake Video-Generation Platforms
Threat actors are distributing the previously undocumented Noodlophile Stealer via bogus AI video-generation sites, luring victims to…

GitLab's 'Future Field' Security Feature Turns Weapon: Emergency Patches for CVE-2026-19478
GitLab released critical patches on August 17, 2026 for CVE-2026-19478, a GraphQL code injection vulnerability with a CVSS 9.4 score t…

CVE-2026-59310: vCenter Exploited in 5 Days, 360+ IPs Compromised
A critical VMware vCenter vulnerability went from patch to in-the-wild exploitation in just five days. Over 360 IP addresses across 47…

DeadLock Leverages Polygon and Session for Takedown-Resistant Ransomware Infrastructure
Microsoft Threat Intelligence dissects DeadLock, a Rust-based ransomware that has compromised over 80 organizations since July 2025, w…

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks
The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

iVerify Uncovers DarkSword, iOS Exploit Framework That Bypasses Safari Without Persistence
iVerify published a technical analysis of DarkSword, a sophisticated multi-stage iOS exploit framework that leverages JavaScriptCore J…

Exposed Directory Reveals Autonomous AI Fleet for Industrial-Scale Crypto Theft
A Chinese-speaking operator orchestrated entire offensive campaigns using multi-vendor AI agents in full-auto mode. A misconfiguration…

Notepad++: Institutional Alert Arrives Four Months After the Fix
Singapore's Cyber Security Agency published an advisory on CVE-2026-3008, a string injection flaw in Notepad++ 8.9.3 with a CVSS 6.6 s…

Ransom Busters: The Double-Cross Undermining the RaaS Model From Within
A ransomware affiliate operates as a fake recovery firm, contacting victims before attacks are published. GuidePoint Security GRIT doc…

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours
Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…