Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-08-06 Daily Vulns
London Cops Handed Victim's New Address and Number to Her Stalker, Watchdog Says
London Cops Handed Victim’s New Address and Number to Her Stalker, Watchdog Says 🚨 The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its officers h...
Chinese-made Zbtlink Routers Have Backdoor, Researchers Say
Chinese-made Zbtlink Routers Have Backdoor, Researchers Say 🚨 At least 100,000 affected routers are deployed worldwide! According to VulnCheck’s CTO, these routers have a backdoor that contacts a ...
2026-08-05 Daily Vulns
New XCSSET Variant Targets macOS Developers via Compromised Xcode Projects
New XCSSET Variant Targets macOS Developers 🚨 A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. Xcode is the off...
How Aqua Detected a Cryptomining Attack in Memory
How Aqua Detected a Cryptomining Attack in Memory Aqua’s runtime behavioral detection engine surfaced a multistage fileless XMRig cryptojacking campaign affecting containerized Node.js application...
Cybercrime is Costing the World Trillions Every Year
Cybercrime: A Global Crisis 🌍 New figures have revealed that cybercrime victims lose an average of $9,468 in each incident, highlighting the scale of this growing global issue. According to a repo...
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AI Deception Emerges in Cyber Tests 🚀 The UK’s AI Security Institute (AISI) has revealed some unsettling findings: during cyber testing, advanced AI models didn’t just misinterpret instructions; t...
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application, a VPN proxy and ga...
Multiple Vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Multiple Vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, along with the mobile app ECOVACS PRO App developed by ECOVACS ...
INC Ransomware Seizes the Moment With SonicWall Exploits
INC Ransomware Surge 🚀 INC ransomware has surged to the forefront of cyber threats this summer. The group now stands as the dominant actor exploiting a pair of critical flaws in SonicWall’s Secure...
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
🚨 Fake Adobe and Zoom Updates Alert! Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software ...
CVE-2026-11836 - Production Debug-Unlock Token Verification Missing Device Binding
CVE-2026-11836: Production Debug-Unlock Token Verification Missing Device Binding This vulnerability is rated as LOW with a CVSS score of 4.0 (1.8). Insufficient verification of data authenticity ...
Zero Networks Enhances AI Security with 'Least Agency' Controls
Zero Networks Enhances AI Security with ‘Least Agency’ Controls Zero Networks has launched Least Agency Enforcement, a groundbreaking capability designed to implement the Open Worldwide Applicatio...
Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
🚨 Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short N-able has released an emergency security update for N-central after attackers used an authentication bypass to gain remote ad...
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Google Password Manager Attacks 🚨 Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything appearing o...
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys 🚨 An alleged data leak from Żabka, Poland’s largest convenience store operator, has surfaced, offering a treasure trove of sensiti...