“Eye” Spy: Cyclops Blink Returns with Extended Capabilities 🚀 In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was disc...
Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-17 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-11984 spacetime - Ad Inserte...
2026-09-16 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-0170 Google - Android ...
Siemens Teamcenter Vulnerability Advisory
Siemens Teamcenter Vulnerability Advisory A reflected cross-site scripting vulnerability has been identified in the authentication redirect flow (/auth/) of Siemens Teamcenter. This vulnerability ...
Iranian Cyber Targeting of Dissidents, Activists and Journalists
Iranian Cyber Targeting of Dissidents, Activists and Journalists Source: UK NCSC Date Published: September 15, 2026 The CHOSEN BRICK malware family has been utilized to target individuals globall...
Multiple Vulnerabilities in Lite-On O-RU Firmware
Multiple Vulnerabilities in Lite-On O-RU Firmware Lite-On Technology Corporation has reported multiple vulnerabilities in their O-RU models “FF-RFI079I4” and “FF-RFI078I4”. These vulnerabilities a...
Most Fraudulent Hires Receive Credentials Before Detection
Most Fraudulent Hires Receive Credentials Before Detection According to a new report by HYPR, most fraudulent hires receive corporate credentials and internal network access before being detected....
Meta AI Builds Detailed Profiles of Children from Years of Family Posts
Meta AI Builds Detailed Profiles of Children from Years of Family Posts At the start of September, Kalie Robins posted a video of her young daughter on Facebook. Under the video of Robins and her ...
Low-quality Casino Sites Conceal Highly Dangerous Threat Actors
Low-quality Casino Sites Conceal Highly Dangerous Threat Actors If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentiall...
HBO Max's Verified Reddit Account Hijacked to Spread Malware
HBO Max’s Verified Reddit Account Hijacked to Spread Malware 🚨 Researchers at Hudson Rock have discovered that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 mali...
Twitch Extension Exposes Users' OAuth Tokens
Twitch Extension Exposes Users’ OAuth Tokens 🚨 A browser extension called **Twitch Enhanced Viewer JeetBot, available in the official Chrome and Firefox stores, has been found...
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Telegram Desktop Flaw 🚨 A flaw in Telegram Desktop allowed a bot’s message to plant hidden JavaScript inside chats that users exported to HTML files, according to security researchers at ExPatch. ...
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Researchers have disclosed a new hardware attack, called DDrop, that breaks the memory protection in Intel and AMD confidential computing by silen...
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE 🚀 A human attacker has moved from a vulnerable Marimo notebook to an SSH bastion host in just eight seconds using a toolkit built by ha...
Homebrew 7.0.0 Gets Built-in GUI and Better Security Controls
Homebrew 7.0.0 Released 🚀 Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI grap...
CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability
CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability The CVE-2026-90824 vulnerability, concerning a stack-based buffer overflow in GPAC MP4Box, was officially reported on September 14, ...
3BB Attacker Used MeshCentral Backdoor for Root Access
3BB Attacker Used MeshCentral Backdoor for Root Access An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal...