VulnerabilityCISA KEV·6 days ago

CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Broadcom VMware vCenter.

VulnerabilityCISA KEV·6 days ago

CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.1 (Critical). Affects Microsoft SharePoint.

VulnerabilityCISA KEV·6 days ago

CVE-2026-65400: Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Apple macOS.

Nation-StateRecorded Future·6 days ago

CopyCop Targets AI Investment in Armenia

The Russian influence network CopyCop is conducting a targeted campaign against Western-backed AI and infrastructure initiatives in Armenia, specifically focusing on the Firebird AI data center. The operation appears designed to obstruct Armenia's shift toward Western alignment by undermining key technology projects in the region.

Nation-StateRecorded Future·6 days ago

PurpleDelta's Fraudulent Employment Operations

North Korean threat actor PurpleDelta conducts fraudulent employment operations by leveraging AI-generated personas and custom ChatGPT assistants to infiltrate target organizations with sophisticated social engineering tradecraft. Security professionals can identify and defend against these campaigns by recognizing specific indicators of compromise and implementing targeted mitigation strategies outlined in Recorded Future's analysis.

VulnerabilityDark Reading·6 days ago

Video Call Exploit Chains Two Flaws in Unisoc Modems

Researchers have discovered an exploit chain combining two separate vulnerabilities in Unisoc modems that allows attackers to compromise Android devices through a simple phone call. The attack requires only that a victim answer the incoming call, after which an attacker can deliver a malicious payload to gain device control.

VulnerabilityThe Hacker News·6 days ago

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

A critical GraphQL vulnerability in GitLab Community and Enterprise editions (CVE-2026-19478, CVSS 9.4) could allow unauthenticated attackers to remotely delete or modify public projects and user data under certain conditions. GitLab has released security updates to address the flaw, which represents a significant risk to instances exposed to untrusted networks.

VulnerabilitySANS Internet Storm Center·6 days ago

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple released updates for iOS/iPadOS and macOS addressing 108 vulnerabilities across the platforms, arriving roughly two weeks after a targeted macOS patch for a screen-sharing flaw. The screen-sharing vulnerability patched in the previous update did not impact iOS/iPadOS devices.

Data BreachDark Reading·6 days ago

Hugging Face Breach Raises Big Questions About AI Security Controls

A breach at Hugging Face has prompted security experts to scrutinize AI platform security practices, with Adam Shostack expressing surprise at details revealed by OpenAI regarding the incident. The attack highlights potential gaps in security controls that protect machine learning platforms and raises broader concerns about how AI companies safeguard sensitive data and systems.

VulnerabilityThe Hacker News·6 days ago

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Wiz researchers discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could allow attackers to execute arbitrary commands through a crafted GitHub issue, potentially exposing internal Jira credentials stored in the affected workflow. The flaw existed in the jira_issue.yml workflow file, which was triggered by GitHub issues, creating an attack vector for credential theft and unauthorized command execution.

VulnerabilityThe Hacker News·6 days ago

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical vulnerability in the widely-deployed Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files and achieve remote code execution on affected sites. Tracked as CVE-2026-15748 with a CVSS score of 9.8, the flaw poses a severe risk to the plugin's 600,000+ active installations. The vulnerability was discovered by a security researcher and demands immediate patching to prevent exploitation.

Nation-StateThe Hacker News·6 days ago

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

VulnerabilityInfosecurity Magazine·6 days ago

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

A vulnerability in UNISOC modems allows attackers to achieve kernel-level code execution by exploiting video call functionality. This remote code execution capability represents a significant risk to devices using UNISOC chipsets, as the attack vector operates at a fundamental system level.

MalwareDark Reading·6 days ago

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

Linux botnet Evooo1Bot extends beyond traditional Mirai-style distributed denial-of-service attacks by incorporating exploitation modules, credential theft capabilities, and reverse SOCKS relays. These additions transform infected devices into versatile persistent infrastructure that attackers can leverage for multiple objectives beyond volumetric attacks. The expanded toolkit represents an evolution in botnet functionality that significantly increases the threat profile of compromised systems.

VulnerabilityCybersecurity Dive·6 days ago

Critical flaw in SAP Commerce Cloud faces initial exploitation attempts

A critical vulnerability with a maximum severity score of 10 has been discovered in SAP Commerce Cloud, with initial exploitation attempts already underway. The flaw's perfect severity rating combined with apparent ease of exploitation presents an immediate risk to organizations running this platform.

RansomwareTenable·6 days ago

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Cybercrime group Storm-0501 has evolved beyond traditional endpoint ransomware to target Azure cloud environments directly, systematically disabling security controls like resource locks and backups to hijack entire cloud tenants. Tenable One Cloud Exposure uses AI-powered threat detection to map Storm-0501's tactics across the attack chain and correlate fragmented Azure activity logs into actionable threat stories for rapid containment. The shift to cloud-native ransomware demands cloud detection and response capabilities that can trace lateral movement, identify initial breach points, and guide immediate defensive actions like credential revocation and policy restoration.

OtherGraham Cluley·6 days ago

An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

A cybersecurity researcher has demonstrated how machine learning-generated patterns can effectively evade detection by Flock surveillance cameras, the AI-powered licence plate readers increasingly deployed across American streets. The technique uses computer-generated adversarial patterns to render vehicles invisible to these automated detection systems, raising significant concerns about the security and reliability of widespread surveillance infrastructure. This research highlights a potential vulnerability in licence plate reader technology that could have implications for law enforcement and public safety applications.

VulnerabilityWiz Blog·6 days ago

Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw in a GitHub Copilot–Assisted PR

Wiz Red Agent autonomously identified and exploited a GitHub Actions injection vulnerability that bypassed GitHub's Advanced Security controls, gaining access to Snowflake's internal Jira and sensitive data within five days of the flaw going live. The vulnerability originated in a pull request assisted by GitHub Copilot, highlighting gaps in automated security detection. The red team agent independently assessed the breach's potential impact without requiring human direction.

Load more