“Eye” Spy: Cyclops Blink Returns with Extended Capabilities 🚀 In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was disc...
Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-16 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-0170 Google - Android ...
Twitch Extension Exposes Users' OAuth Tokens
Twitch Extension Exposes Users’ OAuth Tokens 🚨 A browser extension called **Twitch Enhanced Viewer JeetBot, available in the official Chrome and Firefox stores, has been found...
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Telegram Desktop Flaw 🚨 A flaw in Telegram Desktop allowed a bot’s message to plant hidden JavaScript inside chats that users exported to HTML files, according to security researchers at ExPatch. ...
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Researchers have disclosed a new hardware attack, called DDrop, that breaks the memory protection in Intel and AMD confidential computing by silen...
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE 🚀 A human attacker has moved from a vulnerable Marimo notebook to an SSH bastion host in just eight seconds using a toolkit built by ha...
Homebrew 7.0.0 Gets Built-in GUI and Better Security Controls
Homebrew 7.0.0 Released 🚀 Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI grap...
CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability
CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability The CVE-2026-90824 vulnerability, concerning a stack-based buffer overflow in GPAC MP4Box, was officially reported on September 14, ...
3BB Attacker Used MeshCentral Backdoor for Root Access
3BB Attacker Used MeshCentral Backdoor for Root Access An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal...
Critical Dell ObjectScale Vulnerabilities Allow Malicious Users to Compromise the Affected System
Critical Dell ObjectScale Vulnerabilities 🚨 Dell Technologies has released a security advisory regarding multiple vulnerabilities affecting Dell ObjectScale and Elastic Cloud Storage (ECS) deploym...
2026-09-13 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-70341 Microsoft - Microsoft ...
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere 🚨 Anthropic has been perhaps more vocal than any other AI company about the ways in which its tools are prone to misuse. It published some...
India's STPI Serves TerminalFix-Style Attack via Fake Cloudflare Check
India’s STPI Serves TerminalFix-Style Attack via Fake Cloudflare Check 🚨 A website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page tha...
Crypto Customers Targeted by Scammers After Email Marketing Provider Breach
Crypto Customers Targeted by Scammers 🚨 An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those...
Countering Misuse of AI - September 2026
Countering Misuse of AI - September 2026 Source: Anthropic Date Published: September 11, 2026 Over the past eight months, our Threat Intelligence team identified and disrupted operations in which...
Surfshark VPN Breach Hackers Access Internal Testing Servers
Surfshark VPN Breach: Hackers Access Internal Testing Servers 🚨 Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. T...
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android Malware Combines Ransomware With Spyware 🚨 MantaxOtax Android malware has combined file encryption with extensive surveillance, allowing attackers to steal messages, credentials...