News

Application Security
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.
Application Security
Telerik UI Padding Oracle Chained to Unauthenticated RCE
TantoSec released a PoC exploit chaining Telerik UI padding oracle to unauthenticated RCE two months after Progress Software shipped a patch.
Application Security
REVSTEALER Modules Disable Windows Defender to Deploy Miner
Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a crypto miner.
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
Application Security
PaperCut Zero-Days Under Active Exploit Despite Two Patches
CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records
ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.