Your polite reply to that text is worth $2 on the dark web | Malware
Most wrong-number texts are harmless. Some are the first step in a carefully planned scam. By replying, you may be confirming that your number is active and that you’re willing…
Read more9 million images of people’s faces exposed by reverse lookup service | Malware
Researcher Jeremiah Fowler found a cloud database containing more than 9 million image files accessible without authentication, WIRED reports. The leaky bucket, containing some 450 GB of images, was traced…
Read more14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 | Cybersecurity
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant…
Read moreZombie Card: An expired Visa credit card can be used for purchases | Malware
Did you know there is still a good reason to physically destroy your expired credit card? Scientific research found that the expiration date used by payment terminals on some contactless…
Read moreMicrosoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot | Cybersecurity
Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from…
Read moreMedical records, SSNs, and bank details exposed in CareCloud data breach | Malware
Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this…
Read moreWazuh and AI For Enhanced SOC Workflows | Cybersecurity
Artificial Intelligence (AI) has become one of this decade’s defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns…
Read moreMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution | Cybersecurity
Ravie LakshmananAug 21, 2026Vulnerability / Threat Intelligence Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted…
Read moreYour Mac already has a built-in firewall. Here’s how to get more from it | Malware
Your Mac comes with a built-in firewall, but it’s probably not something you’ve given much thought to. A firewall helps control incoming connections—requests from apps and other devices that want…
Read moreTwitch wants your content for Amazon AI training. Here’s how to opt out | Malware
The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI. Twitch launched as a live-video platform and is currently owned by Amazon….
Read moreRust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads | Cybersecurity
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script…
Read moreChatGPT for Teens tackles risky chats and homework shortcuts | Malware
OpenAI has addressed complaints around teens’ use of its ChatGPT system by introducing ChatGPT for Teens, a version of the AI assistant designed specifically for users aged 13 to 17….
Read moreIsolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE | Cybersecurity
Ravie LakshmananAug 20, 2026Vulnerability / Application Security Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on…
Read moreToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud | Cybersecurity
Ravie LakshmananAug 20, 2026Malware / Mobile Security Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of 167…
Read moreScammers are using fake crypto AML checkers to drain your wallet | Malware
Scammers are creating fake crypto wallet-checking sites that promise to tell you whether a wallet is linked to suspicious activity. Instead, they try to trick you into giving them access…
Read more41 deceptive download sites show a real link, then send you somewhere else | Malware
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike,…
Read moreCloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second | Cybersecurity
Swati KhandelwalAug 19, 2026Cloud Security / Vulnerability Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located…
Read moreOpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior | Cybersecurity
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the…
Read moreSideloading on Android: What it is, why it’s risky, and how to do it more safely | Malware
A Google spokesperson announced on Reddit that it has started rolling out the first version of its Advanced Flow, designed to make installing apps from unverified developers safer. Let us explain…
Read moreSilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs | Cybersecurity
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five…
Read more