Update your Mac: Screen Sharing vulnerability exploited in the wild | Malware
The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers….
Read moreFake TikTok rewards promise cash you’ll never get | Malware
TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous….
Read moreCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects | Cybersecurity
Swati KhandelwalAug 17, 2026Vulnerability / DevOps GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions,…
Read more⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More | Cybersecurity
Ravie LakshmananAug 17, 2026Cybersecurity / Hacking The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use,…
Read moreShieldBreak bypasses Microsoft’s patch for earlier Defender flaw | Malware
Microsoft Defender’s latest patch bypass shows a familiar problem. A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the…
Read moreHow MCP Servers Can Expose Enterprise Secrets | Cybersecurity
The Hacker NewsAug 17, 2026AI Security / Identity Security MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know…
Read moreWhy Facebook’s war on ad blockers could help scammers | Malware
Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers,…
Read moreSAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch | Cybersecurity
Ravie LakshmananAug 15, 2026Vulnerability / Cloud Security A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the…
Read moreWhatsApp is testing a new warning for scam messages | Malware
Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to…
Read moreApple now uses iPhone alerts for targets of mercenary spyware | Malware
Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device…
Read moreHackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware | Cybersecurity
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given…
Read moreMustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth | Cybersecurity
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and…
Read moreFake popular sites offer a free app, instead take over PCs | Malware
A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with…
Read moreChina-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud | Cybersecurity
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. “Both missions are administered from…
Read moreWatch out for fake TikTok Shops trying to steal your money | Malware
TikTok Shop is a real, functioning e-commerce feature built into the TikTok app, allowing users to buy goods without ever leaving TikTok. As it’s grown in popularity, scammers have begun…
Read moreUnpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE | Cybersecurity
Ravie LakshmananAug 13, 2026Zero-Day / Vulnerability A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE…
Read moreParents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits | Malware
A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battle in court. The lawsuits,…
Read moreNew PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure | Cybersecurity
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis…
Read moreNew Android malware lets criminals use your bank card in real time | Malware
Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it…
Read moreWindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud | Cybersecurity
Ravie LakshmananAug 13, 2026Malware / Mobile Security A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access…
Read moreSexual predators targeting online accounts for intimate images, FBI warns | Malware
The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent….
Read moreAttackers Exploit SharePoint Authentication Bypass After Public PoC Release | Cybersecurity
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which…
Read morePatch Tuesday: Update now to fix 421 flaws, including three zero-days | Malware
Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges….
Read moreLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor | Cybersecurity
Ravie LakshmananAug 12, 2026Vulnerability / Cyber Espionage The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting…
Read more737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One | Cybersecurity
Ravie LakshmananAug 12, 2026Browser Security / Privacy A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services…
Read more“Zoomsday” flaws could let one Zoom participant attack another | Malware
Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data. The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and…
Read moreAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws | Cybersecurity
Ravie LakshmananAug 12, 2026Vulnerability / Web Security Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in…
Read moreSocial media platforms crack down on drone factory recruiting game | Malware
A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stolen passwords. Sometimes it’s about understanding how online platforms are…
Read moreShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access | Cybersecurity
Ravie LakshmananAug 12, 2026Zero-Day / Vulnerability The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft…
Read moreFake CCleaner installs GhostDesk Chrome spyware | Malware
A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the…
Read more