Update your Mac: Screen Sharing vulnerability exploited in the wild | Malware

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers….

Read more

Fake TikTok rewards promise cash you’ll never get | Malware

TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous….

Read more

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects | Cybersecurity

Swati KhandelwalAug 17, 2026Vulnerability / DevOps GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions,…

Read more

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More | Cybersecurity

Ravie LakshmananAug 17, 2026Cybersecurity / Hacking The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use,…

Read more

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw | Malware

Microsoft Defender’s latest patch bypass shows a familiar problem. A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the…

Read more

How MCP Servers Can Expose Enterprise Secrets | Cybersecurity

The Hacker NewsAug 17, 2026AI Security / Identity Security MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know…

Read more

Why Facebook’s war on ad blockers could help scammers | Malware

Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers,…

Read more

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch | Cybersecurity

Ravie LakshmananAug 15, 2026Vulnerability / Cloud Security A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the…

Read more

WhatsApp is testing a new warning for scam messages | Malware

Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to…

Read more

Apple now uses iPhone alerts for targets of mercenary spyware | Malware

Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device…

Read more

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware | Cybersecurity

Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given…

Read more

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth | Cybersecurity

The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and…

Read more

Fake popular sites offer a free app, instead take over PCs | Malware

A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with…

Read more

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud | Cybersecurity

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. “Both missions are administered from…

Read more

Watch out for fake TikTok Shops trying to steal your money | Malware

TikTok Shop is a real, functioning e-commerce feature built into the TikTok app, allowing users to buy goods without ever leaving TikTok. As it’s grown in popularity, scammers have begun…

Read more

Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE | Cybersecurity

Ravie LakshmananAug 13, 2026Zero-Day / Vulnerability A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE…

Read more

Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits | Malware

A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battle in court. The lawsuits,…

Read more

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure | Cybersecurity

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis…

Read more

New Android malware lets criminals use your bank card in real time | Malware

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it…

Read more

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud | Cybersecurity

Ravie LakshmananAug 13, 2026Malware / Mobile Security A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access…

Read more

Sexual predators targeting online accounts for intimate images, FBI warns | Malware

The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent….

Read more

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release | Cybersecurity

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which…

Read more

Patch Tuesday: Update now to fix 421 flaws, including three zero-days | Malware

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges….

Read more

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor | Cybersecurity

Ravie LakshmananAug 12, 2026Vulnerability / Cyber Espionage The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting…

Read more

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One | Cybersecurity

Ravie LakshmananAug 12, 2026Browser Security / Privacy A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services…

Read more

“Zoomsday” flaws could let one Zoom participant attack another | Malware

Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data. The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and…

Read more

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws | Cybersecurity

Ravie LakshmananAug 12, 2026Vulnerability / Web Security Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in…

Read more

Social media platforms crack down on drone factory recruiting game | Malware

A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stolen passwords. Sometimes it’s about understanding how online platforms are…

Read more

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access | Cybersecurity

Ravie LakshmananAug 12, 2026Zero-Day / Vulnerability The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft…

Read more

Fake CCleaner installs GhostDesk Chrome spyware  | Malware

A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the…

Read more
Update cookies preferences