Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Valve: Steam Hardware Shipping Data Exposed in CEVA Logistics Attack
Valve notified European Steam hardware customers on August 7, 2026 that their shipping data was compromised in a cyberattack on logist…

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability
Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282
CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago
Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

China Launches Security Review of Palo Alto Networks: Self-Censorship Failed to Work
The Cyberspace Administration of China (CAC) opened a national security review of Palo Alto Networks products on August 6, 2026. The m…

Backdoored LiteLLM on PyPI: Malware Triggers on Python Startup Alone
On March 24, 2026, two malicious LiteLLM versions exfiltrated credentials from over 50 categories via a .pth mechanism. The compromise…

Barracuda Zero-Day: Mandiant Attributes CVE-2023-2868 to Chinese Espionage
Mandiant links the zero-day vulnerability in Barracuda Email Security Gateway to threat actor UNC4841 with high confidence, describing…

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft
A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

Phoenix Contact CHARX: Credentials in Logs Open EV Charging Stations to Attack
The ZDI-26-506 vulnerability in the Phoenix Contact CHARX SEC-3150 industrial charger exposes credentials in log files. A network-adja…

TrueConf Becomes Strategic Chokepoint: Compromised Servers Infect Clients
At least three distinct attack campaigns — attributed to Ukrainian hacktivists and Chinese threat actors — have compromised on-premise…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

Guangdong Chanming: The Ghost Vendor Behind PLA Botnets
Chinese firm Guangdong Chanming, which has no website or known commercial clients, sold anonymized relay infrastructure to the PLA and…