Cyber Security
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Gabby Lee
August 5, 2026
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
Andrew Doyle
August 5, 2026
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
Application Security
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
Gabby Lee
August 5, 2026
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Andrew Doyle
August 5, 2026
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Cybersecurity
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Gabby Lee
August 5, 2026
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Application Security
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
Mitchell Langley
August 5, 2026
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Application Security
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
Gabby Lee
August 5, 2026
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
Application Security
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
Andrew Doyle
August 5, 2026
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
CVE Vulnerability Alerts
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Gabby Lee
August 5, 2026
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Cybersecurity
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
Andrew Doyle
August 5, 2026
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
Application Security
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Gabby Lee
August 5, 2026
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
Application Security
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
Gabby Lee
August 5, 2026
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
Cybersecurity
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Mitchell Langley
August 5, 2026
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Gabby Lee
August 4, 2026
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Application Security
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Andrew Doyle
August 4, 2026
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Andrew Doyle
August 4, 2026
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Cybersecurity
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
Gabby Lee
August 4, 2026
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
Cybersecurity
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
Mitchell Langley
August 4, 2026
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
Cybersecurity
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
Mitchell Langley
August 4, 2026
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Cybersecurity
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Andrew Doyle
August 4, 2026
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Gabby Lee
August 5, 2026
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
Andrew Doyle
August 5, 2026
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Gabby Lee
August 3, 2026
TOP CYBERSECURITY HEADLINES
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Application Security
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
Application Security
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
This Week’s Security Spotlight
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Andrew Doyle
July 31, 2026
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
August 5, 2026
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
August 5, 2026
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
August 5, 2026
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
August 5, 2026
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
August 5, 2026
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
August 5, 2026
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
August 5, 2026
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
August 5, 2026
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
August 5, 2026
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
US Water Sector Attacks Hit 12 States, Georgia Confirmed
August 5, 2026
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
August 4, 2026
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
August 4, 2026
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
August 4, 2026
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
August 4, 2026
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
August 4, 2026
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
August 4, 2026
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
August 4, 2026
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Liechtenstein Register Breach Exposes Data of 31,000 People
August 4, 2026
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
UKGI Left Officials’ Contact Details Exposed for 40 Hours
August 4, 2026
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
August 3, 2026
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.


























