Cyber Security
Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Andrew Doyle
August 6, 2026
Huntress traced credential-theft alerts to attackers who compiled the khunt toolkit inside Oracle to reach SYSTEM-level code execution on a Windows server.
Cybersecurity
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Gabby Lee
August 6, 2026
VulnCheck disclosed a factory-shipped ENDLESSDOORS backdoor in Zbtlink router firmware that lets a remote attacker open an unauthenticated root shell.
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
Mitchell Langley
August 6, 2026
A federal judge in Virginia sentenced Belarusian Maksim Silnikau, the creator of Ransom Cartel, to 16 years for running a ransomware-as-a-service operation.
Cybersecurity
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
Andrew Doyle
August 6, 2026
Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more than 100 million people.
Application Security
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
Mitchell Langley
August 6, 2026
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Application Security
Meta AI Hacked External Systems During Cybersecurity Testing
Mitchell Langley
August 6, 2026
Meta admitted its Muse Spark 1.1 model escaped a test environment and breached an unnamed third party's systems during evaluations by startup Irregular.
Cybersecurity
Brown Health Medical Group Breach Exposes 311,000 Records
Gabby Lee
August 6, 2026
Brown Health Medical Group of Massachusetts disclosed a historic file-server breach exposing personal, medical, and financial data belonging to 311,760 people.
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Mitchell Langley
August 6, 2026
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without the model.
Cybersecurity
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Mitchell Langley
August 6, 2026
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
CVE Vulnerability Alerts
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Gabby Lee
August 6, 2026
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in a new advisory release.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Gabby Lee
August 5, 2026
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
Andrew Doyle
August 5, 2026
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
Application Security
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
Gabby Lee
August 5, 2026
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Andrew Doyle
August 5, 2026
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Cybersecurity
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Gabby Lee
August 5, 2026
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Application Security
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
Mitchell Langley
August 5, 2026
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Application Security
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
Gabby Lee
August 5, 2026
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
Application Security
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
Andrew Doyle
August 5, 2026
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
CVE Vulnerability Alerts
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Gabby Lee
August 5, 2026
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Cybersecurity
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
Andrew Doyle
August 5, 2026
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Andrew Doyle
August 6, 2026
Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Andrew Doyle
August 6, 2026
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
Mitchell Langley
August 6, 2026
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Gabby Lee
August 3, 2026
TOP CYBERSECURITY HEADLINES
Application Security
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
Application Security
Meta AI Hacked External Systems During Cybersecurity Testing
This Week’s Security Spotlight
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Mitchell Langley
August 6, 2026
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Andrew Doyle
July 31, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
August 6, 2026
Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more than 100 million people.
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
August 6, 2026
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Meta AI Hacked External Systems During Cybersecurity Testing
August 6, 2026
Meta admitted its Muse Spark 1.1 model escaped a test environment and breached an unnamed third party's systems during evaluations by startup Irregular.
Brown Health Medical Group Breach Exposes 311,000 Records
August 6, 2026
Brown Health Medical Group of Massachusetts disclosed a historic file-server breach exposing personal, medical, and financial data belonging to 311,760 people.
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
August 6, 2026
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without the model.
ClickFix Malware Gate Fingerprints macOS Users Before Lures
August 6, 2026
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
August 6, 2026
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in a new advisory release.
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
August 5, 2026
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
August 5, 2026
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
August 5, 2026
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
August 5, 2026
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
August 5, 2026
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
August 5, 2026
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
August 5, 2026
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
August 5, 2026
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
August 5, 2026
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
August 5, 2026
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
August 5, 2026
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
August 5, 2026
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
US Water Sector Attacks Hit 12 States, Georgia Confirmed
August 5, 2026
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.























