Cyber Security
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
Hasbro Data Breach Exposed 436+ Employee Records
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
Judge Rules Pentagon Actions Against Anthropic Unlawful
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Cronos Blockchain Halts Network, Restores State After $74M Exploit
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
Application Security
PaperCut Zero-Days Under Active Exploit Despite Two Patches
CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records
ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.
Cybersecurity
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
Hit casino operator reopened six Slovenian and Bosnian casinos after a three-day cyberattack shutdown, with gaming functions and loyalty systems still offline.
Application Security
Hasbro Data Breach Exposed 436+ Employee Records
Hasbro disclosed breach affecting 436+ Massachusetts employees, exposing names, national IDs, and financial data, tied to late March cyberattack.
Cybersecurity
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.
CVE Vulnerability Alerts
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
Adebola Adekunle and Mudasiru Olawale were extradited from Nigeria on August 31 to face charges in sextortion schemes that killed two U.S. teens.
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
U.S. District Judge Rita Lin ruled Pentagon
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
CVE Vulnerability Alerts
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
Application Security
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Cybersecurity
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Application Security
Cronos Blockchain Halts Network, Restores State After $74M Exploit
Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million in August 31 exploit.
Application Security
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
Application Security
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
CVE Vulnerability Alerts
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS 10.0 globally.
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Application Security
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging enterprises to update.
Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Cybersecurity
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
Cybersecurity
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
Hit casino operator reopened six Slovenian and Bosnian casinos after a three-day cyberattack shutdown, with gaming functions and loyalty systems still offline.
Hasbro Data Breach Exposed 436+ Employee Records
Hasbro disclosed breach affecting 436+ Massachusetts employees, exposing names, national IDs, and financial data, tied to late March cyberattack.
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
Adebola Adekunle and Mudasiru Olawale were extradited from Nigeria on August 31 to face charges in sextortion schemes that killed two U.S. teens.
Judge Rules Pentagon Actions Against Anthropic Unlawful
U.S. District Judge Rita Lin ruled Pentagon
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Cronos Blockchain Halts Network, Restores State After $74M Exploit
Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million in August 31 exploit.
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS 10.0 globally.
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging enterprises to update.
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
A combined heat and power plant in Poland suffered a turbine shutdown and process-water treatment disruption after attackers accessed its cellular ICS network.