threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI is pausing internal development of its AI model Astra due to concerns about its rapidly advancing cyber capabilities. Initial evaluations suggest the model possesses ‘Critical’ cyber capabilities, including the po… The Hacker News · Aug 10, 2026 High aicybersecurityai-safety
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
threat-intel N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands A flaw in N-able’s God mode feature allowed attackers to gain unauthorized access to customer networks. The vendor has confirmed that attackers exploited this vulnerability to compromise systems, and a second hotfix has… The Register · Aug 7, 2026 Critical CVE-2026-18577vulnerabilityremote managementcyberattack
vulnerability Microsoft, Apple Release Fresh Security Updates Microsoft and Apple released a combined set of security updates addressing dozens of vulnerabilities across their products, including critical remote code execution flaws. These updates target a wide range of products, i… SecurityWeek · Aug 7, 2026 Critical CVE-2026-63508CVE-2026-56162CVE-2026-65667vulnerabilityremote code executionpatch
threat-intel IT department put sticky notes on the laptops to help employees log in This article is a collection of security-related news snippets from The Register. It covers a range of topics including a phishing campaign mimicking Signal support, a zero-day exploit targeting on-prem SharePoint, and a… The Register · Aug 6, 2026 Medium CHIRSWphishingzero-dayransomware
threat-intel Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple has implemented strict limits on its bug bounty program to combat a surge of low-quality, AI-generated vulnerability reports. The issue stems from amateur bug hunters using AI to create plausible-but-nonexistent se… Graham Cluley · Aug 6, 2026 High aivulnerabilitybug bounty
vulnerability CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities The CISA has issued a warning about three actively exploited vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities – CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486 – ar… SecurityWeek · Aug 5, 2026 High CVE-2026-9198CVE-2026-18556CVE-2026-18577CHcvepatchremote code execution
vulnerability Feds get 3 days to patch N-able God mode flaw under active exploit A critical vulnerability, actively being exploited, has been discovered in N-able God Mode, a system management tool. Federal agencies have been given a short window to patch the flaw, highlighting a significant risk of… The Register · Aug 4, 2026 Critical CVE-2026-18577CVE-2026-18556zero-daypatchingsystem management
threat-intel AI helps Microsoft bug hunters chase a record $20M payday Microsoft security researchers are experiencing a surge in zero-day attacks targeting on-prem SharePoint, fueled by a new wave of exploits leveraging vulnerabilities in third-party extensions. Simultaneously, Chinese act… The Register · Aug 4, 2026 High CHzero-dayphishingcybersecurity
threat-intel Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Microsoft significantly increased its bug bounty payouts, reaching over $20 million in the past year and rewarding 562 researchers across 64 countries. The company’s programs saw a substantial rise in submissions, partly… SecurityWeek · Aug 4, 2026 Medium bug bountyvulnerabilityresearch
vulnerability INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws The INC Ransomware operation has become the dominant threat actor exploiting a series of zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances. Since the beginning of August 2026, the group has been aggressively… The Hacker News · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410AUU.UAzero-dayvpnransomware
vulnerability Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks The INC Ransomware group has been aggressively exploiting two vulnerabilities in SonicWall’s SMA1000 secure remote access appliances to deploy ransomware, targeting organizations across multiple countries. These vulnerab… SecurityWeek · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410USAUUAvulnerabilityransomwarezero-day
vulnerability ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered vulnerability in a popular PDF reader. Attackers are using this vulnerabil… SANS Internet Storm Center · Jul 31, 2026 Critical pdfphishingvulnerability
threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
vulnerability Cisco Secure FMC Zero-Day Exploited in the Wild A zero-day vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC) is being actively exploited in the wild. Attackers are leveraging default credentials to gain access to sensitive data, and Cisco… SecurityWeek · Jul 30, 2026 High CVE-2026-20316CVE-2026-20079zero-dayvulnerabilitycisco