Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-08-05 Daily Vulns
New XCSSET Variant Targets macOS Developers via Compromised Xcode Projects
New XCSSET Variant Targets macOS Developers 🚨 A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. Xcode is the off...
How Aqua Detected a Cryptomining Attack in Memory
How Aqua Detected a Cryptomining Attack in Memory Aqua’s runtime behavioral detection engine surfaced a multistage fileless XMRig cryptojacking campaign affecting containerized Node.js application...
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application, a VPN proxy and ga...
Multiple Vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Multiple Vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, along with the mobile app ECOVACS PRO App developed by ECOVACS ...
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
🚨 Fake Adobe and Zoom Updates Alert! Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software ...
Zero Networks Enhances AI Security with 'Least Agency' Controls
Zero Networks Enhances AI Security with ‘Least Agency’ Controls Zero Networks has launched Least Agency Enforcement, a groundbreaking capability designed to implement the Open Worldwide Applicatio...
Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
🚨 Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short N-able has released an emergency security update for N-central after attackers used an authentication bypass to gain remote ad...
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Google Password Manager Attacks 🚨 Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything appearing o...
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys 🚨 An alleged data leak from Żabka, Poland’s largest convenience store operator, has surfaced, offering a treasure trove of sensiti...
Google Chrome May Soon Block New Tab Hijacker Extensions by Default
Google Chrome May Soon Block New Tab Hijacker Extensions by Default 🚀 Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page...
SplitVPN Data Breach Exposes 865k Users' Personal Records
SplitVPN Data Breach Exposes 865k Users’ Personal Records 🚨 A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 86...
CVE-2026-10848 - Out-of-bounds Read in Zephyr OCPP 1.6 RPC Message Parser
CVE-2026-10848 - Out-of-bounds Read in Zephyr OCPP 1.6 RPC Message Parser Published Date: August 2, 2026 Source: CVE Feed CVE-2026-10848 describes an out-of-bounds read vulnerability in the Zephy...
2026-08-02 Daily Vulns
Investigation into APT 5 and PLA Troop 61786
Threat Review Journal: Investigation into APT 5 and PLA Troop 61786 I began tracking a subset of what was assessed to be low-level criminal activity, which actually turned out to be a group of six...
Watchfire Controller Software Vulnerability Alert
Watchfire Controller Software Vulnerability Alert 🚨 On July 30, 2026, CISA published an alert regarding a significant vulnerability in the Watchfire Controller Software. This vulnerability, identi...
The 73,000-Server Market Reselling Western Frontier AI into China
The 73,000-Server Market Reselling Western Frontier AI into China Western frontier AI is not sold in mainland China, yet it is utilized daily. This report maps the infrastructure that enables this...