News Archive
1926 stories · page 34 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD, […]

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they […]

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. […]

New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]

NIELIT Launches Cyber Kushti 2026, a National Hackathon That Scores Security Judgment Over Detection Speed
NIELIT has opened free registration for Cyber Kushti 2026, a national cybersecurity and AI hackathon run with the ISAC Foundation under the National Security Database, with CERT-In as knowledge partner. Instead of hunting vulnerabilities, teams must correct a deliberately imperfect AI-generated security assessment, and the finale plays out live at NCCDFI 2026 in New Delhi this October.

ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are actively exploiting a critical vulnerability in macOS's Screen Sharing feature to gain root access and deploy Monero cryptocurrency miners. The flaw, which allows attackers to bypass authentication without valid credentials, is being exploited on Macs with port 5900 exposed to the internet. Apple has released patches for this issue, but exploitation was observed shortly after the fix was deployed.

GeoServer Zero-Day Is Already Being Probed. That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality. Key Takeaways Taiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in

How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]

New York City Lawmakers Push to ‘Ban the Scan’ at MSG
At a press conference outside Madison Square Garden, politicians, musicians, and privacy advocates argued for tighter restrictions on how public venues deploy biometric surveillance.

Metasploit Wrap Up: Lot of summer shells and fit http profiles
Metasploit Framework has released version 6.5, introducing thirteen new modules with a focus on remote code execution (RCE) and local privilege escalation (LPE) vulnerabilities across various platforms and applications. The update also enhances HTTP malleable profiles, adds Linux multi-fetch payloads, and introduces support for Windows on ARM with new AArch64 reverse-TCP shells. Several modules target specific vulnerabilities, including those in WordPress, Joomla, SonicWall, and the Linux kernel.

Friday Squid Blogging: Searching for the Colossal Squid
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching. As usual, you can also u

Investigation of banking hack leads to arrests in Germany, Brazil
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.

Mission-Driven Security: Inside a Global Bank's Defense
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.

Hackers arrested over €30M bank fraud exploiting service provider flaw
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Another one bites the dust

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
The increasing volume of software vulnerabilities, partly fueled by AI-powered discovery tools, has prompted NIST to explore the potential of AI in managing and mitigating these risks. This includes investigating how AI can aid in vulnerability analysis and response.

Apple Warns Hundreds of Targeted Mercenary Spyware Attacks
Apple has issued new threat notifications to hundreds of users across 110 countries, warning them of credible, targeted mercenary spyware attacks. These sophisticated attacks, which are distinct from regular cybercriminal activity, are likely aimed at individuals due to their identity or profession, such as journalists, activists, and politicians. The company is urging affected users to verify their security, implement stronger protections, and seek expert assistance.

Upcoming Speaking Engagements
This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here. I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET. I’m speaking at Elevate Festival in Toronto, Canada. The conference runs September 22–24, 2

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]

ExfilSquad Confirmed to Possess Data From 13 Organizations
Researchers have confirmed that the ExfilSquad extortion group has obtained sensitive data from a minimum of 13 organizations. The group has reportedly published these stolen datasets through torrents.

French tax authority admits data heist after crook touts 2M records
Government disputes claims of continued access as investigators measure damage

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]