Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-08-27 Daily Vulns
Your Expired Visa Card Could Be 'Zombified' to Make Contactless Payments
Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments 🚨 Attention all Visa cardholders! Did you know that your expired Visa card could potentially be used for contactless paymen...
New GPUThor Attack Defeats NVIDIA ECC Protection for Root Access
New GPUThor Attack Defeats NVIDIA ECC Protection for Root Access A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denia...
Justice Department and FBI Seize Platforms Used by China State-Sponsored Hackers
Major Cybersecurity Action 🚨 The Justice Department and FBI have announced significant court-authorized domain seizures aimed at disrupting malicious cyber activities. Today, they targeted two hac...
CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
CHIRP Kenwood ITM Driver Eval Injection Vulnerability 🚨 An eval injection vulnerability has been discovered in the Kenwood ITM file format driver of CHIRP, an open-source application for programmi...
Beware of Fake Indeed Interview Apps Used to Install Spyware
Beware of Fake Indeed Interview Apps Used to Install Spyware 🚨 From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the In...
Kubernetes 1.37 - New Security Features
Kubernetes 1.37 - New Security Features 🚀 Kubernetes 1.37 has just been released, bringing 67 enhancements! In terms of security, we’ve identified 19 changes with security implications, spanning n...
Half-click Unauthenticated Remote Code Execution on Horde Groupware IMP
Critical Vulnerability Alert 🚨 A critical vulnerability enabling half-click unauthenticated remote code execution (RCE) on Horde Groupware IMP has been detailed, stemming from a stored Cross-Site ...
A GUID is Not a Credential Unauthenticated RCE in Veeam Service Provider Console
A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console 🚨 Critical Vulnerabilities Identified! 🚨 CVE-2026-58073 (CVSS 9.5) and CVE-2026-58072 (CVSS 9.0) are critical vul...
2026-08-26 Daily Vulns
Norway's Digital Government Infrastructure Hit by a New DDoS Attack
Norway’s Digital Government Infrastructure Hit by a New DDoS Attack 🚨 Norway’s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that dis...
LACMA Data Breach Exposed Sensitive Information
LACMA Data Breach Exposed Sensitive Information The Los Angeles County Museum of Art (LACMA) has announced that a data breach last year exposed customer and employee information. 🚨 The museum repo...
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown 🚨 McAfee Labs has released a follow-up report on the WeedHack Malware-as-a-Service campaign, revealing that ten active malicious...
FURUNO FA-50 Class B AIS Transponder Vulnerabilities
FURUNO FA-50 Class B AIS Transponder Vulnerabilities 🚨 Critical Alert! Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of ...
Ebyte NE2-D11 Vulnerabilities Exposed
Ebyte NE2-D11 Vulnerabilities Exposed Published on: August 25, 2026 Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose s...
Critical Vulnerability in PayRange API Disclosed
Critical Vulnerability in PayRange API Disclosed 🚨 A significant vulnerability has been identified in the PayRange API, which could allow both authenticated and unauthenticated attackers to exploi...