Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Passkey Bypass: Three Studies Shatter FIDO2's 'Anti-Phishing' Promise
On August 3, 2026, researchers from SpecterOps, Palo Alto Networks Unit 42, and independent researcher Dirk-jan Mollema published dist…

fTPM 2.0 Compromised: AMD and Intel Forced to Patch the Root of Trust
Two critical vulnerabilities in the shared fTPM 2.0 firmware used by AMD and Intel expose cryptographic secrets and enable key forgery…

PAX Q80: Unpatchable Zero-Day RCE Exposes Payment POS Terminals
The PAX Technology Q80 payment terminal contains a zero-day RCE vulnerability exploitable via local network. The vendor declared the f…

Wesco Confirms Cloud CRM Incident: ExfilSquad Claims Theft of 2.6 Million Records
Fortune 500 industrial distributor Wesco confirmed on August 11, 2026, that it is investigating a security incident in its cloud CRM e…

Apple Patches Decade-Old Zero-Day in iOS Core: dyld Exposed for 10+ Years
CVE-2026-20700 affects the dyld dynamic linker, a fundamental component present for over a decade. Apple confirms targeted exploitatio…

TeamPCP Compromises LiteLLM: 434,000 Pipelines Exposed in 40 Minutes
TeamPCP injected malicious LiteLLM packages onto PyPI for 40 minutes. CloudSEK estimates 2,500+ organizations exposed. Stolen credenti…

Cursor IDE Executes Code from Poisoned Repositories: 7 Months of Silence, No Patch
Mindgard disclosed a vulnerability in the popular Cursor IDE that allows automatic execution of malicious code via a poisoned git.exe…

ChainDrop: The npm Worm That Broke Cryptographic Trust in Four Hours
The ChainDrop worm infected 444 npm packages using valid SLSA provenance. The failure of automated trust in modern software.

Cisco ISE Authenticated RCE Escalates to Root: The 9.9 CVSS Behind the Method
A critical vulnerability in Cisco Identity Services Engine enables authenticated remote code execution with privilege escalation to ro…

Norton Utilities Ultimate: Local Privilege Escalation to SYSTEM via Symlink, CVE-2024-13962
The ZDI-26-567 vulnerability in the NortonUtilitiesSvc service enables local privilege escalation to SYSTEM through a symlink attack.…

BlackBerry QNX: RCE in KEV Parser, Patch Available for SDP 7.x-8.0
CVE-2026-40272 strikes the trace file parser in QNX. Analysis of malicious .kev logs can execute arbitrary code. BlackBerry has releas…

CISA Cracks Down on LoadMaster: 792 Exploit Attempts and Mandatory Patching
Progress Kemp LoadMaster lands in CISA's KEV catalog with CVE-2026-8037 and a 9.6 CVSS. U.S. federal agencies have three days to patch…