Endpoint Security

Application Security
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
CVE Vulnerability Alerts
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Cybersecurity
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
CVE Vulnerability Alerts
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the Linux host.
Cybersecurity
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
MIT CSAIL's interrupt injection attack named TONTOU bypasses retpoline and Safe-RET defenses on AMD Zen 2 to leak Linux password hashes from userspace.
Cybersecurity
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
Huntress discovered a Go-based macOS infostealer delivered through ClickFix attacks that steals crypto assets and redirects a percentage of each transaction.
Cybersecurity
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.