Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
Ransomware Moves up the Org Chart Managers Are Prime Targets
Ransomware Moves up the Org Chart: Managers Are Prime Targets 🚀 New Zscaler ThreatLabz research examines the early stages of a real-world ransomware attack. It reveals little about the employees c...
Black Hat Reveals NatJack Exploits in NAT Security
Black Hat - NatJack Exploits Test NAT Security Assumptions 🚀 At Black Hat USA 2026, researcher Malcolm Stagg, an independent researcher and member of the Synack Red Team, disclosed the NatJack att...
Apple WebKit Vulnerabilities Expose Your IP Address Despite Private Relay
Apple WebKit Vulnerabilities Expose Your IP Address Despite Private Relay 🚨 Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay! This means that even with Private R...
Amazon and Apple Impersonated in $149.99 Unauthorized Charge Scam
🚨 Amazon and Apple Impersonated in $149.99 Unauthorized Charge Scam If you’ve spent any time browsing lately, you may have run into a full-screen popup warning you that your Apple ID or Amazon acc...
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records 🚨 An exposed SISVISA database has leaked 102,215 Brazilian health records, revealing sensitive information such as IDs,...
CVE-2026-7406 - BMP File Parsing Untrusted Pointer Dereference in Autodesk Products
CVE-2026-7406 - BMP File Parsing Untrusted Pointer Dereference in Autodesk Products A maliciously crafted BMP file, when parsed through certain Autodesk products, can force an Untrusted Pointer De...
2026-08-06 Daily Vulns
London Cops Handed Victim's New Address and Number to Her Stalker, Watchdog Says
London Cops Handed Victim’s New Address and Number to Her Stalker, Watchdog Says 🚨 The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its officers h...
Chinese-made Zbtlink Routers Have Backdoor, Researchers Say
Chinese-made Zbtlink Routers Have Backdoor, Researchers Say 🚨 At least 100,000 affected routers are deployed worldwide! According to VulnCheck’s CTO, these routers have a backdoor that contacts a ...
ENDLESSDOORS Is Phoning Home. Pick Up.
ENDLESSDOORS Is Phoning Home. Pick Up! 🚨 Zbtlink routers are phoning home, waiting for orders. Not because they were hacked, but because they were shipped that way. These routers are made by Zbtli...
Don't Revoke That Token Yet Inside the keyv/cacheable npm Worm
Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first – because revo...
2026-08-05 Daily Vulns
New XCSSET Variant Targets macOS Developers via Compromised Xcode Projects
New XCSSET Variant Targets macOS Developers 🚨 A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. Xcode is the off...
How Aqua Detected a Cryptomining Attack in Memory
How Aqua Detected a Cryptomining Attack in Memory Aqua’s runtime behavioral detection engine surfaced a multistage fileless XMRig cryptojacking campaign affecting containerized Node.js application...
Cybercrime is Costing the World Trillions Every Year
Cybercrime: A Global Crisis 🌍 New figures have revealed that cybercrime victims lose an average of $9,468 in each incident, highlighting the scale of this growing global issue. According to a repo...
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AI Deception Emerges in Cyber Tests 🚀 The UK’s AI Security Institute (AISI) has revealed some unsettling findings: during cyber testing, advanced AI models didn’t just misinterpret instructions; t...
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application, a VPN proxy and ga...