Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-08-27 Daily Vulns
2026-08-26 Daily Vulns
Norway's Digital Government Infrastructure Hit by a New DDoS Attack
Norway’s Digital Government Infrastructure Hit by a New DDoS Attack 🚨 Norway’s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that dis...
LACMA Data Breach Exposed Sensitive Information
LACMA Data Breach Exposed Sensitive Information The Los Angeles County Museum of Art (LACMA) has announced that a data breach last year exposed customer and employee information. 🚨 The museum repo...
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown 🚨 McAfee Labs has released a follow-up report on the WeedHack Malware-as-a-Service campaign, revealing that ten active malicious...
FURUNO FA-50 Class B AIS Transponder Vulnerabilities
FURUNO FA-50 Class B AIS Transponder Vulnerabilities 🚨 Critical Alert! Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of ...
Ebyte NE2-D11 Vulnerabilities Exposed
Ebyte NE2-D11 Vulnerabilities Exposed Published on: August 25, 2026 Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose s...
Critical Vulnerability in PayRange API Disclosed
Critical Vulnerability in PayRange API Disclosed 🚨 A significant vulnerability has been identified in the PayRange API, which could allow both authenticated and unauthenticated attackers to exploi...
2026-08-25 Daily Vulns
TikTok Settles U.S. Child Privacy Case for $400 Million
TikTok Settles U.S. Child Privacy Case for $400 Million 🎉 TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. De...
iAuthFlow v2 The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset The iAuthFlow v2 phishing toolkit utilizes a phished Google session to enroll an attacker-controlled passkey that survi...
Fake Microsoft Security Scans Trick Victims into Uninstalling Their Antivirus
Beware of Fake Security Scans! 🚨 A wave of deceptive websites is posing as Microsoft security scans, misleading victims into uninstalling their antivirus software. These sites, branded as SysScan,...
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens 🚨 A financially motivated threat actor, known as Doubloon Dredger, has been observed exploiting free Notion accounts, malicious PDFs...
AliExpress Caught Using Silent Audio to Fingerprint Visitors' Browsers
AliExpress Caught Using Silent Audio to Fingerprint Visitors’ Browsers AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave ...
ToxicPanda Android Malware Uses VPN Permissions to Block Google Play
ToxicPanda Android Malware Overview 🚨 The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote com...
Iran-linked Hackers Behind Cyber Attack That Shut Down Power Plant
Iran-linked Hackers Behind Cyber Attack That Shut Down Power Plant 🚨 A small power plant in the UK was shut down during a cyber attack. The Telegraph reported that the attack, which took place las...
Zero-Click Grok Chat History Theft Adversa AI Demonstrates Cryptographic Context Injection
Zero-Click Grok Chat History Theft 🚨 Adversa AI researcher Rony Utevsky has devised a groundbreaking attack technique known as Cryptographic Context Injection. This method bypasses AI safety filte...