#News


⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

Aug 10, 2026 // 18:40

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting […]

Critical Progress LoadMaster flaw now actively exploited in attacks

Aug 10, 2026 // 18:22

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a […]

Valve notifies Steam hardware customers of a data breach

Aug 10, 2026 // 18:22

Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, […]

LexisNexis shuts down services after suspicious activity on servers

Aug 10, 2026 // 18:22

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an […]

Member of The Com sent to prison for blackmail, sextortion

Aug 10, 2026 // 18:21

A member of “The Com,” a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail […]

When Credentials Are No Longer Enough: Device Trust in the AI Era

Aug 10, 2026 // 18:21

Identity security is under growing strain. The passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation and browser characteristics organizations have traditionally used to judge whether […]

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

Aug 10, 2026 // 18:21

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. ​SMA1000 is […]

Hackers breach TrueConf to trojanize client installers with backdoors

Aug 8, 2026 // 21:17

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. The […]

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Aug 8, 2026 // 01:08

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim’s Windows Hello for Business key […]

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

Aug 8, 2026 // 01:08

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate […]

Previous 1 52 53 54 55 56 353 Next