Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services
The BlueDelta group has used macro-laced Word documents to distribute HOOKEDGE, a batch-script backdoor that leverages webhook.site fo…

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks
The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

Bug in JavaScript Obfuscator Exposes Polymorphic Phishing Campaign
A server-side scope error in an obfuscator triggered infinite loops in 3.6% of variants, revealing a polymorphic evasion mechanism tha…

AI Honeypot: Real Attacks on LiteLLM and MCP Servers Reveal Three Patterns
Wiz Threat Research deployed AI/ML honeypots for 90 days and documented sustained, service-specific attacks. Three distinct patterns t…

Next.js: Two Critical RCE Patches Expose the Managed vs. Self-Hosted Protection Gap
Vercel released critical patches for two unauthenticated RCE vulnerabilities in Next.js on August 25, 2026. The disparity in protectio…

PaperCut: Active Zero-Day Exploitation Confirmed Across All NG and MF Versions
PaperCut Software confirmed on August 27, 2026, that an undisclosed vulnerability affecting all versions of PaperCut NG and PaperCut M…

VCS Blind Spot: Wiz CIRT Publishes DFIR Matrix for GitHub and GitLab
The Wiz CIRT DFIR poster maps VCS audit logs to MITRE ATT&CK but exposes critical gaps: 88% of customers use SaaS with 7-day retention…

CISA Adds Six CVEs to KEV: From Citrix RCE to SQL Server with Seven Years of Attacks
On August 26, 2026, CISA added six vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, triggering Binding Operationa…

ATF Confirms Qilin Breach: Isolated System, No Data Theft Confirmed
The ATF confirmed a major cybersecurity incident on August 26, 2026, involving a standalone system containing investigative target inf…

ShinyHunters Inflates Carhartt Breach with Synthetic Data, but Real Count Is 12.9 Million
ShinyHunters published 50 GB of Carhartt data after the company refused a $3.3 million ransom. Troy Hunt's OpenClaw analysis exposed t…

ICS Isn't Safer — Just More Selective. Biometric Sector Remains Top Target
In Q2 2026, the global share of ICS computers with blocked malicious objects fell to 19.15%, the lowest since 2022. Yet the biometric…

GPUThor Bypasses NVIDIA ECC: Root Escalation in 1.1 Minutes on Workstation GPUs
The new GPUThor Rowhammer attack defeats SECDED ECC protection on NVIDIA Ampere RTX A4000-A6000 workstation cards. No patch is availab…