⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text.
20 articles
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text.
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland...
NCSC warns unapproved AI tools can expose corporate data and create new security risks
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as...
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIG...
A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation...
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after bre...
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees...
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S.
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvid...
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Ko...
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach....
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affec...
The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans
A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly perso...
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero...
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) so...
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysi...
OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect critica...