CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners | Cybersecurity
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are…
Read moreScammers are getting smarter about where they target you | Malware
Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten…
Read moreGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs | Cybersecurity
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a…
Read moreTech support scams look different now. Here’s what to watch for | Malware
In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then…
Read moreMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code | Cybersecurity
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s…
Read moreTwo critical Chrome flaws put users at risk on malicious websites | Malware
Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to 152.0.7977.75/.76 for…
Read moreGeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends | Cybersecurity
Swati KhandelwalSep 02, 2026Vulnerability / Web Security Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind…
Read moreInfostealers are hijacking Claude accounts at users’ expense | Malware
Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal…
Read moreFake GTA 6 leaked copy drains your crypto wallet | Malware
We’ve seen scam sites built around Grand Theft Auto VI (GTA 6) targeting visitors in three different ways this year. In June, we looked at sites selling GTA 6 “early access” for…
Read moreAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure | Cybersecurity
Ravie LakshmananSep 01, 2026Vulnerability / Supply Chain Attack Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The…
Read moreTerminalFix looks like ClickFix, but delivers a very different payload | Malware
Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A…
Read moreIranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests | Cybersecurity
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to…
Read moreRussia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis | Cybersecurity
Ravie LakshmananSep 01, 2026Malware / Artificial Intelligence Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099 against…
Read moreNorth Korean Job Fraud Expands Beyond IT Into Healthcare and Sales | Cybersecurity
Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent…
Read moreMcKesson confirms cyber incident after ShinyHunters claims patient-data theft | Malware
Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes…
Read moreValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions | Cybersecurity
Swati KhandelwalAug 31, 2026Malware / Endpoint Security The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the…
Read moreThe Missing Context Layer for AI Agents in Large Enterprise Codebases | Cybersecurity
As organizations deploy AI coding agents across large monorepos and microservices environments, a fundamental problem emerges: the model may be capable of making the change, yet still lack the organizational…
Read moreTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor | Cybersecurity
Ravie LakshmananAug 30, 2026Social Engineering / Malware Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows…
Read moreFive Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE | Cybersecurity
Ravie LakshmananAug 29, 2026Vulnerability / Web Security Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could…
Read moreTracking PavinLoader across ClickFix and fake download campaigns | Malware
In our previous analysis of the malicious RenPy campaigns, we identified a multi-stage loader deployed as part of the infection chain. Further threat hunting has since shown that the same…
Read moreToxicPanda 2.0 can take over your Android phone and banking apps | Malware
Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list…
Read moreNew Instagram and Facebook rules set a default two-hour limit for teens | Malware
Meta decided that discretion was the better part of valor on Wednesday, agreeing to settle a landmark child safety case for up to $17 billion. The agreement would introduce a…
Read moreBerlin Refuses to Pay Hackers Who Stole Data From the City’s State Network | Cybersecurity
Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and said it will not meet…
Read moreProtect your WhatsApp account with new passkey and 2FA upgrades | Malware
WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement included two other security upgrades: a stronger two-step…
Read moreAttackers Chain Two PaperCut Flaws to Execute Code Without Authentication | Cybersecurity
Ravie LakshmananAug 28, 2026Vulnerability / Web Security Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the…
Read moreTwo Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth | Cybersecurity
Swati KhandelwalAug 28, 2026Vulnerability / IoT Security Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low…
Read moreThe AI agent swarm that attacked Hugging Face is a warning for the future | Malware
The hacking incident involving OpenAI evaluation agents and Hugging Face offers an unusually concrete look at what advanced AI-assisted intrusion can mean in practice: not a single clever exploit, but…
Read morePaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions | Cybersecurity
Ravie LakshmananAug 28, 2026Vulnerability / Enterprise Security PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
Read moreFake Apple Pay charge brings the classic tech support scam to your phone | Malware
iPhone users are being targeted in a new tech support scam, using a fake Apple Pay notification to trick users. Tech support scams that use fake warnings to push victims…
Read moreOpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face | Cybersecurity
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior…
Read more