LIVE · cybersecurity feed
Live wire
CVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide Probes

News Archive

1926 stories · page 40 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

linuxhigh

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

A race condition vulnerability has been discovered in the Linux Kernel's XFRM subsystem, allowing local attackers to escalate privileges. The flaw stems from improper locking during operations on skb objects, enabling an attacker with existing high-privileged code execution to gain kernel-level code execution. A fix has been released by Linux.

trend microhigh

ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been discovered in Trend Micro VPN's OpenSSL configuration. Attackers with low-privileged code execution can exploit this by leveraging an unsecured configuration file location to escalate privileges and run arbitrary code as SYSTEM. Trend Micro has released an update to address this issue.

ddos

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-layer attacks to disrupt online services across multiple industries. L3/4 attack-size distribution (bitrate), H1 2026 (Source:

ai

Product showcase: Is this image real? Slop or Not investigates

Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to distinguish authentic content from AI-generated material, up from 66% a year earlier. Half of respondents reported encount

vulnerability

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Catapult DCT2000, Gammu DCT3, 3gpp phone logs, TTX Logger, and, on Windows only, Ixia IxVeriWave and Vector Informatik BLF.

breach

Chinese Loongson processors have leaky caches, researchers find

Attackers could extract data, even working from inside a guest VM

security

ISC Stormcast For Thursday, August 13th, 2026 (Thu, Aug 13th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

malware

Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)

In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to com

malwarehigh

Malware Crypting Services Aid Threat Actors in Evading Detection

Malware crypting services are evolving beyond simple payload modification to offer comprehensive malware enablement. These services help threat actors bypass security software, complicate analysis, and maintain malware functionality even after detection. A competitive market exists, primarily focused on Windows payloads, with providers advertising on various underground and social platforms.

phishing

Smashing Security podcast #480: This is the AI service you should never sign up to

Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your passwo

breach

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

malware

Android malware combo takes out loans and relays victims' credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]

ai

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

Some say the world will end in fire, some say an agentic swarm

security

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

CVE-2026-71362critical

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]

security

CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments

CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight warehouses, and the company is still working to restore impacted services. CEVA Logistics operates in more than […]

security

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Eight years on, we're still paying to hide the future glimpsed during speculative execution

vulnerability

Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation

Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require them. It evaluates each finding in context by correlating posture data with vulnerabilities, asset […]

security

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]

aihigh

China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

Cybersecurity firm Dream has documented what appears to be the first fully autonomous, end-to-end AI hacking operation targeting a government network. Suspected China-linked hackers reportedly used up to eight AI agents to map systems, find vulnerabilities, and steal data from a Taiwanese government network with minimal human intervention. The operation compromised over 85 accounts and 2,500 personnel records, highlighting a significant advancement in AI-driven cyber warfare.

CVE-2026-68820high

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Lazarus Group, a North Korean state-sponsored hacking collective, has been linked to a sophisticated cyber espionage campaign dubbed Operation Dream Job. This campaign leverages a recently patched Windows zero-day vulnerability (CVE-2026-68820) to escalate privileges and deploy a new backdoor named Troy. The group targets defense and aerospace companies in France, Germany, Brazil, and India by impersonating recruiters on platforms like LinkedIn and offering fake job opportunities.

breach

FBI: Hackers using social engineering to breach accounts and steal explicit content

Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.

nation-state

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

Israeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along. The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop.

purple teaming

Walmart's "Trusted Agent" Approach to Purple Teaming

Walmart has adopted a "Trusted Agent" approach to its purple teaming exercises, a strategy that involves co-locating its red and blue security teams. This method aims to foster trust and enhance collaboration between offensive and defensive security personnel, ultimately improving the company's overall security posture.