Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing a Web of Deceit: The Alleged Backdoor Scandal Rocking the Networking Industry


A Chinese router vendor has been accused of including a backdoor feature in its firmware, sparking concerns about the security and integrity of connected devices. Despite initial denials, Zbtlink has since paused downloads of its firmware and announced plans to develop secured patched versions. The incident highlights the need for greater transparency and cooperation between vendors, researchers, and regulators in the face of emerging threats.

Published: Thu Aug 6 00:26:13 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Snowflake Hacker Pleads Guilty to Computer Fraud, Wire Fraud, Aggravated Identity Theft, and Conspiracy


Swati Khandelwal has pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 breaches of Snowflake customer accounts that affected at least 100 million people. The breach resulted in actual losses exceeding $9.5 million for victim companies. Moucka took advantage of old passwords and had previously extorted at least one victim, threatening further disclosure using stolen data.

Published: Thu Aug 6 01:35:22 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Widespread Reign of Terror: A Tale of Cybercrime and Accountability


In a shocking turn of events, Connor Riley Moucka has pleaded guilty to breaching 165 organizations and stealing billions of records. His crimes, which began in February 2024, resulted in significant financial losses for affected companies and exposed data linked to over 100 million individuals. As the case against him continues to unfold, it remains to be seen whether he will ultimately receive a prison sentence. However, his guilty plea serves as a stark reminder of the importance of accountability in our response to cybercrime.

Published: Thu Aug 6 01:42:03 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Hidden Threat Lurking Within Chinese-Made Routers: A Grave Vulnerability Exposed

The discovery of a factory-shipped backdoor in at least 20 Chinese-made router models from Zbtlink has raised significant concerns among cybersecurity experts and users worldwide. The vulnerability, codenamed "ENDLESSDOORS," allows attackers to gain control over routers without having to be reachable from the internet.

Published: Thu Aug 6 03:53:45 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Ransom Cartel Creator Silnikau Sentenced to 16 Years in Prison for Operating Ransomware-as-a-Service Operation


A federal judge has sentenced Maksim Silnikau, the creator of Ransom Cartel, a notorious ransomware-as-a-service operation. Silnikau was convicted of 16 years in prison for his role in conducting numerous cyber attacks against companies worldwide between 2021 and 2023.

Published: Thu Aug 6 04:00:03 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

CISA Warns of Critical TeamCity Flaw: Deserialization Vulnerability Allows Remote Code Execution


A critical vulnerability in JetBrains TeamCity has been identified as CVE-2026-63077, allowing remote code execution via deserialization of untrusted data. CISA warns that federal agencies must apply patches by August 8, 2026, to mitigate the risk. Stay up-to-date with the latest security news and expert insights from The Hacker News.

Published: Thu Aug 6 04:08:17 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Critical TeamCity Vulnerability: A Security Alert for Organizations



U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog, categorizing it as a high-severity vulnerability (CVSS score of 9.8). The identified bug allows attackers to bypass authentication checks and execute arbitrary operating system commands. Organizations are advised to upgrade their TeamCity versions to mitigate the risk associated with this vulnerability.

Published: Thu Aug 6 04:13:37 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Exploiting Oracle's Embedded Java Virtual Machine: A Post-Exploitation Toolkit Allows for System-Level Access

Attackers Compiles khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access, highlighting the need for regular vulnerability assessments and patching of software.

Published: Thu Aug 6 05:21:38 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Global AI-Powered Vulnerability: The Convergence of Security Threats Across AWS, Google, and Vercel



A recent global AI-powered vulnerability has emerged in the agent infrastructure of AWS, Google, and Vercel, which can be exploited by attackers to trigger tools without running the model. This convergence of security threats poses significant implications for organizations and individuals alike who must now confront the possibility that their AI systems may be compromised. As experts continue to identify new vulnerabilities, it is essential to take proactive measures to patch these issues before they become a major concern.

Published: Thu Aug 6 05:28:49 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Lurking Threats of Unsecured AI Models: A Growing Concern for Cybersecurity


A recent incident highlights the growing concern of unsecured AI models posing a significant threat to cybersecurity. With three disclosed AI lab breaches in weeks, Meta's AI model breach marks the latest in a series of incidents that underscore the need for more stringent security measures when testing AI models.

Published: Thu Aug 6 05:36:59 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Exposing Security Vulnerabilities: A Cautionary Tale of IT Department Negligence

Exposing Security Vulnerabilities: A Cautionary Tale of IT Department Negligence

Published: Thu Aug 6 07:46:00 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

CryptoJS Vulnerability Exposed: Five Crypto Wallet Apps Affected by Weak Random Number Generator

Five cryptocurrency wallet apps, including RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo, have been found vulnerable to a CryptoJS Weak RNG that exposed users to $5.7 million in drains. Coinspect has identified the vulnerability and advised affected users to update their wallets for security patches.

Published: Thu Aug 6 07:54:37 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Exposing Real IPs Through WebKit Proxy Bypasses: A Security Threat in Apple's iCloud Private Relay

Security researchers have disclosed a serious vulnerability in Apple’s iCloud Private Relay tool, which exposes users' real IP addresses to websites that bypass the relay's security mechanism. Researchers Talal Haj Bakry and Tommy Mysk revealed this issue through WebKit features DNS prefetching, WebAuthn Related Origin Requests, and WebTransport, which enables leak of user IP address without requiring any interaction or using passkeys.

Published: Thu Aug 6 08:00:57 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

AI Recommendation Poisoning: The Silent Threat to AI-Generated Content



A growing concern in the world of artificial intelligence (AI), AI recommendation poisoning is a new threat that exploits pre-filled deep links to manipulate AI assistants' memory. This phenomenon has been observed on commercial websites, including those selling consent management software and web security tools. Security teams must be vigilant to detect this silent threat and take measures for remediation to protect themselves against biased results.

Published: Thu Aug 6 08:13:00 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Great Rockwell PLC Exposure: A Cautionary Tale of Cybersecurity Neglect

The recent exposure of over 4,400 Rockwell PLCs online has sent shockwaves through the cybersecurity community, highlighting the alarming rate at which industrial control systems are being exploited by malicious actors. Learn more about this critical incident and its implications for public safety and national security.

Published: Thu Aug 6 09:19:40 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Unraveling of Trust: A Deluge of Cybersecurity Threats Exposed in the Latest Threatsday Bulletin



The world of cybersecurity is under siege from an unprecedented array of threats, each with its unique characteristics and implications. From AI-powered attacks to vulnerabilities affecting major device manufacturers, the Threatsday bulletin brings forth a comprehensive overview of the most pressing security concerns at present. This article provides an in-depth exploration of these threats, delving into their nature, impact, and the lessons they impart on security professionals. With timely patching, strict permission management, and awareness campaigns being essential tools in the fight against such threats, it is crucial that organizations take immediate action to fortify their defenses.

Published: Thu Aug 6 11:39:35 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Ransom Cartel Leader Sentenced to 16 Years in U.S.: A Case Study on Ransomware-as-a-Service Operations


Ransom Cartel leader Maksim Silnikau has been sentenced to 16 years in prison for his role in running a sophisticated ransomware-as-a-service operation. The case highlights the growing threat of these operations, which have become increasingly lucrative and sophisticated. Despite being arrested and charged earlier, this sentence marks one of the first times a US court has taken into account the scale and sophistication of these types of operations.

Published: Thu Aug 6 11:46:05 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Threat Actor Expansion: The Continuing Evolution of UNC6671's Extortion Scheme

Threat Actor Expansion: The Continuing Evolution of UNC6671's Extortion Scheme

Published: Thu Aug 6 13:14:07 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Canadian Cybercrime Ring Foiled: The Rise and Fall of Connor Riley Moucka

A Canadian man has pleaded guilty to a string of cybercrime offenses, including stealing call and text history records from over 100 million AT&T customers and extorting multiple companies through stolen login credentials. Connor Riley Moucka faces a maximum penalty of 30 years in prison for his role in the Snowflake data thefts.

Published: Thu Aug 6 13:20:05 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

We May Finally Know Who's Playing Ganondorf in 'The Legend of Zelda': The Latest Update on Sony's Anticipated Adaptation

The casting of Uli Latukefu as Ganondorf in Sony's adaptation of 'The Legend of Zelda' confirms a talented actor to bring one of gaming's most iconic villains to life. The highly anticipated film is set to release on April 30, 2027.

Published: Thu Aug 6 13:25:34 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

GTA VI ‘Extended Look’ on Netflix: A Strategic Move by Rockstar Games

Rockstar Games has announced that its upcoming title, Grand Theft Auto VI, will premiere an extended look on Netflix at the end of August, marking a strategic move away from traditional console-centric releases and towards more hybrid models.

Published: Thu Aug 6 13:31:01 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Human Ineffectiveness: The Surprising Truth About AI Coding Agent Requests

According to a recent study, humans in the loop are failing to detect dangerous AI coding agent requests approximately one-third of the time, highlighting the need for greater awareness about AI-powered coding agents and proactive measures to address potential vulnerabilities.

Published: Thu Aug 6 13:37:26 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts: A Critical Security Alert


New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts: A Critical Security Alert
A recent vulnerability was uncovered in the Linux kernel's Virtual Machine (KVM) system, allowing an attacker with kernel privileges inside an L1 guest virtual machine to escape KVM isolation and execute code on the host. This critical security alert highlights the importance of staying vigilant and proactive when it comes to protecting against new vulnerabilities and exploits.


Published: Thu Aug 6 13:45:41 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Cisco Addresses Multiple Critical Security Vulnerabilities in SD-WAN and IOS XE Software


Cisco has addressed 12 significant security vulnerabilities in its Catalyst SD-WAN software and IOS XE software. These include three severe flaws with a CVSS score of 9.8 or higher, as well as seven others that have been fixed in the latest versions of the respective software.

Published: Thu Aug 6 14:08:15 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New Breakthrough in CPU Security: Researchers Unveil a Novel Attack that Can Bypass Spectre v2 Defenses

Researchers have discovered a novel attack that can bypass Spectre v2 defenses on Intel and AMD CPUs by exploiting a critical weakness in interrupt handling mechanisms. The vulnerability, dubbed "Interrupt Injection," allows an unprivileged Linux program to leak arbitrary kernel memory and potentially read sensitive information from the system's password hashes.

Published: Thu Aug 6 14:18:46 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The SISVISA Data Breach: A Critical Exposure of Brazilian Health Surveillance Records


Brazil's Health Surveillance Information System, SISVISA, recently suffered a catastrophic data breach that exposed 102,215 sensitive records. The breach, discovered by researcher Jeremiah Fowler, has significant implications for the security and integrity of SISVISA's systems and the individuals whose personal data was compromised. To protect against potential identity theft, it is recommended that affected individuals monitor their financial accounts more closely and turn on multi-factor authentication wherever possible.

Published: Thu Aug 6 14:25:02 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Hacked: The Vulnerabilities in GPS-Enabled Smartwatches and Their Implications for Consumer Safety

Security researchers have exposed the vulnerabilities in GPS-enabled smartwatches, which can be easily exploited by hackers. A recent study found that more than 30 brands use the same backend servers as a Chinese company with multiple security flaws.

Published: Thu Aug 6 16:43:56 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Uncharted Frontiers of Artificial Intelligence in the Realm of Security Conferences: A Cautionary Tale of Managing the Flood of Papers


The 35th USENIX Security Symposium recently witnessed an unprecedented surge in paper submissions, prompting concerns about the potential impact of artificial intelligence on the integrity of scientific work. The conference organizers have implemented measures to address these concerns while acknowledging the growing presence of AI in research.

Published: Thu Aug 6 19:04:34 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Cybersecurity Crackdown: China Launches Mysterious Probe into Palo Alto Networks' Products


China has launched a mysterious probe into the security of Palo Alto Networks' products, sparking concerns about the country's intentions and the potential implications for the global cybersecurity landscape. The probe was initiated by Beijing's Cyberspace Administration (CAC) in an effort to ensure the safe and stable operation of critical information infrastructure and prevent cybersecurity risks and vulnerabilities. With no clear explanation or rationale provided for its actions, this latest development serves as a reminder that China's growing cybersecurity capabilities pose a significant challenge for Western tech companies operating in the country.

Published: Fri Aug 7 00:19:56 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A New Form of Cyber Scam: AI Deepfakes Used to Impersonate OnlyFans Creators


A new form of cyber scam is emerging, utilizing AI-generated deepfakes to impersonate popular OnlyFans creators. Scammers are using social media platforms like TikTok and Snapchat to lure fans into sending money, often through Cash App. Experts stress the importance of detecting such scams by recognizing distinct features of AI-generated content and verifying the authenticity of online creators before proceeding with any financial transactions.

Published: Fri Aug 7 02:34:09 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Unveiling the Shadowy Operations of TeamPCP: A Complex Web of Cybercrime and Supply Chain Attacks


A new analysis has uncovered evidence that suggests TeamPCP has been operating since at least 2020. The threat actor, known for its supply chain attacks and cryptocurrency mining campaigns, continues to evolve its tactics with updates to its malware arsenal and operational methods.

Published: Fri Aug 7 03:45:46 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Cisco Addresses Multiple Critical Security Vulnerabilities in SD-WAN and IOS XE Software

Cisco has released patches to address multiple critical security vulnerabilities in its Catalyst SD-WAN software and IOS XE software. The patches aim to prevent exploitation of known vulnerabilities affecting both software systems. Customers are advised to install the latest updates for optimal protection. Stay ahead of emerging threats with the latest news, expert insights, exclusive resources, and strategies from industry leaders. Get the latest news in your inbox.

Published: Fri Aug 7 03:56:13 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

A new attack class called NatJack has been discovered, which manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. To mitigate this vulnerability, organizations should apply available Windows and Linux updates, encrypt traffic, and implement Internet Protocol Source Guard where applicable.

Published: Fri Aug 7 05:07:05 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Malware Exploits Windows Hello for Business Keys to Achieve Persistent Entrida ID Access

Malware Can Abuse Windows Hello for Business Keys to Achieve Persistent Entrida ID Access

Published: Fri Aug 7 05:13:19 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Critical Vulnerabilities Exposed: The Severity of the Claude Code and Gemini CLI Flaws


The recent discovery of critical vulnerabilities in the Claude Code and Gemini CLI has raised concerns among security experts about the risk of data breaches and unauthorized access. By understanding these issues and taking necessary precautions, organizations can minimize their exposure to these threats.

Published: Fri Aug 7 05:19:19 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Sentience Paradox: Asimov's Predictions Proven Correct by Ex-US Cyber Director

Former US National Cyber Director Chris Inglis warns that humans will get the AI models they deserve if they are not designed with proper safeguards in place. The ex-US cyber director emphasizes the need for more effective safety protocols and human accountability to prevent catastrophic failures.

Published: Fri Aug 7 06:31:34 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New Microsoft 365 AitM Phishing Campaign Hijacks Accounts to Collect Payroll and Finance Emails


A recent Microsoft 365 AitM phishing campaign has been detected, compromising accounts to collect payroll and finance emails. The attackers use residential proxies to disguise malicious sign-ins and maintain stolen sessions through automated activity. Organizations are advised to stay vigilant against email security threats and take proactive measures to protect their systems and data.

Published: Fri Aug 7 06:38:29 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Novel Approach to HTTP Desynchronization: PortSwigger's Breakthrough Discovery

PortSwigger's AI-assisted research system, HTTP Terminator, has made a groundbreaking discovery by generating novel HTTP desynchronization techniques, including a reliable response queue poisoning solution and an exposed zero-day vulnerability in Apache Traffic Server. This breakthrough highlights the potential of AI-assisted systems to advance web security testing.

Published: Fri Aug 7 06:45:31 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Routers Exposed: The Zbtlink Backdoor Saga


Researchers from VulnCheck have discovered a hidden backdoor in 20 different router models produced by Chinese manufacturer Shenzhen Zhibotong Electronics, also known as Zbtlink. This backdoor allows remote servers to execute commands as root, putting affected devices at risk of takeover. The vulnerability was triggered when the implant reaches a server, sending a fixed hello: a class label padded with nulls, then its LAN MAC address. Once connected, anything the command server sends gets executed as root through a basic system call, no allow-list, no sandbox, nothing filtering what commands are acceptable.

Published: Fri Aug 7 06:51:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Phishing Scam Leaves US Defense Supplier's Microsoft 365 Account Vulnerable to Exploitation

Phishing Scam Leaves US Defense Supplier's Microsoft 365 Account Vulnerable to Exploitation; An attacker impersonated a prospective business contact, sent the employee a fake Microsoft sharing link, and harvested their M365 credentials, leaving the company's account exposed to potential exploitation.

Published: Fri Aug 7 08:00:14 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Evolution of Open Source: A New Era of Accountability

The world of open-source software is undergoing a significant transformation, driven by the rapid evolution of technology and the increasing complexity of cyber threats. Read more to learn about the new era of accountability that is emerging.

Published: Fri Aug 7 08:10:20 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Critical Flaw in Linux's SCTP Network Code: A Potential Nightmare for System Administrators


A recently identified flaw in Linux's SCTP network code poses significant risks to system administrators and users alike. The identified vulnerability, CVE-2026-64564, allows local users to gain root access with relative ease, provided the necessary conditions are met.

Published: Fri Aug 7 08:18:40 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Meta Faces Unprecedented Child Safety Lawsuits: $567 Million Fines Imposed Over Harmful Platform Effects

Meta has been ordered to pay $567 million over child safety failures in New Mexico, as part of an unprecedented legal battle that could set a new precedent for regulating social media companies. The fine is the latest blow to Meta's reputation and highlights growing concerns over the impact of social media on children's mental health and well-being.

Published: Fri Aug 7 08:25:14 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Mitigating Spectre-Style Attacks: The Emerging Threat of TONTOU


MIT researchers have discovered a new class of attack known as TONTOU that targets Intel and AMD CPUs' Spectre defenses, allowing unprivileged code to exploit vulnerabilities in the post-neutralization window. Their findings highlight the ongoing need for robust mitigations against Spectre-style exploits and underscore the importance of collaborative efforts between industry leaders, security professionals, and researchers.

Published: Fri Aug 7 09:39:49 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

NHS Tayside Data Breach: A Critical Examination of Medical Record Security

The Scottish NHS trust, NHS Tayside, is investigating a data breach that allegedly involved the unauthorized access to medical records of a 9-year-old girl who tragically passed away earlier this week. The incident has raised serious concerns about the security and confidentiality of sensitive patient information within the healthcare sector.

Published: Fri Aug 7 09:47:41 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New Vulnerability Discovered in WordPress Login Screen Could Allow Remote Code Execution

Researchers at pwn.ai have identified a critical pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress that affects every version of the CMS and could potentially lead to remote code execution. The issue was patched on August 6, but older versions of the software remain vulnerable until updates are applied.

Published: Fri Aug 7 09:53:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

N-able God Mode Flaw: A Critical Vulnerability Exposed, Leaving Customer Networks at Risk

N-able God Mode Flaw: A Critical Vulnerability Exposed, Leaving Customer Networks at Risk
A critical zero-day vulnerability in N-central has been exposed, allowing attackers to breach customer networks. The vendor has released a hotfix to address the issue, but concerns remain regarding its adequacy and transparency.

Published: Fri Aug 7 11:01:33 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Ransomware Attacks on the Rise as AI Distracts from Cybersecurity



Ransomware attacks have surged in recent months, with a notable spike in July, according to UK-based firm Comparitech. The US was the most-targeted country, with 322 incidents recorded last month. Experts warn that old-school threats are not going away and urge individuals and organizations to take proactive measures to protect themselves from ransomware attacks.

Published: Fri Aug 7 12:10:22 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

WordPress XSS2Shell Flaw: A Critical Vulnerability Exploited for Full Server Takeover

WordPress has recently been hit with a critical XSS2Shell flaw that can be exploited for full server takeover. The vulnerability, which was discovered by researchers at Pwn, is based on a simple login bug and allows attackers to inject malicious HTML code into error messages. With this exploit, attackers can gain control over WordPress servers, making it crucial to update to the latest version as soon as possible.

Published: Fri Aug 7 12:16:09 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Hackers' Sophisticated Ploy: Exploiting Trust to Steal from Leading Financial Companies

Hackers impersonate IT support to breach leading financial companies, stealing sensitive data and extorting ransoms from victims. The attackers' sophisticated tactics highlight the importance of robust security measures and employee education in preventing such breaches.

Published: Fri Aug 7 12:21:26 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Navigating the Interstellar Frontier: NASA's Voyager 1 Power Diversion Plan

NASA is on the cusp of an extraordinary achievement by executing a daring power-saving hack on its Voyager 1 spacecraft, enabling it to continue sending back data from interstellar space for several more years. The innovative strategy exploits waste heat from natural radioactive decay and carefully switches on and off critical components, showcasing humanity's determination to explore the farthest reaches of our solar system.

Published: Fri Aug 7 14:40:24 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer in Sophisticated Software Supply Chain Attack


A recent attack on the npm registry has exposed nearly 800 malicious packages that deliver cross-platform malware targeting Windows, Mac, and Linux systems. The attack appears to be a masterclass in social engineering and supply chain attacks, with the malicious packages using AI-slopped typo squats or randomly generated package names that appear legitimate. To stay ahead of this evolving threat landscape, it's essential for developers and organizations to prioritize software security and take proactive steps to protect themselves against such sophisticated attacks.

Published: Fri Aug 7 15:06:04 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware that can steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The malware can drain crypto wallet contents into accounts under the threat actor's control.

Published: Fri Aug 7 15:18:45 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Evolution of UNC6671: A Comprehensive Analysis of a Highly Sophisticated Phishing Operation

UNC6671, a highly sophisticated phishing operation, has been targeting enterprise employees using voice phishing (vishing) to steal SaaS data. The group's use of social engineering tactics and diversified operations across multiple extortion brands make it a significant threat to organizations worldwide.

Published: Fri Aug 7 15:27:37 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Astra Controversy: Understanding OpenAI's Decision to Halt Development of Its Most Advanced AI Model

OpenAI has halted the development of its most advanced AI model, Astra, due to concerns over its potential for critical cybersecurity capabilities. The move comes as a result of recent high-profile breaches involving rival companies' AI models.

Published: Fri Aug 7 16:34:23 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Internet Incompatibility of Water System Controllers: A Call for Cybersecurity Vigilance Amidst Suspected Iranian Attacks



The recent surge in cyberattacks on US water systems has raised concerns about the nation's cybersecurity posture, particularly with regards to the internet connectivity of water system controllers. With at least 12 US states' water systems having been targeted by suspected Iranian cyberattacks, retired General Paul Nakasone emphasizes the need for higher standards in cybersecurity and calls for partnerships between government agencies, academia, and private sector security experts to defend these critical infrastructure against attacks.

Published: Fri Aug 7 16:39:37 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

OpenAI's Astra Security Measures: Balancing Risk and Protection in the Era of Advanced AI

OpenAI has pledged to add robust security measures to its Astra model release, amid growing concerns about the risks associated with advanced AI capabilities. The move follows Anthropic's decision to relax Fable's security restrictions, raising questions about the balance between model performance and safety in AI development.

Published: Fri Aug 7 18:49:30 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Metabase Zero-Day Exploited in Wild: A Critical Security Flaw Exposed

Metabase Zero-Day Exploited in Wild: A Critical Security Flaw Exposed, allowing unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database, granting them administrator access to the instance. Update your systems now.

Published: Sat Aug 8 03:09:10 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able Issues Hotfix 2 as Attackers Breach Managed Systems and Persist; Organizations Must Stay Vigilant Against Evolving Cyber Threats

Published: Sat Aug 8 03:19:28 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Critical Security Flaw Exposed: The Progress Kemp LoadMaster Vulnerability and its Implications


A critical-severity security flaw has been identified in the Progress Kemp LoadMaster, leaving devices vulnerable to arbitrary code execution and command injection attacks. CISA urges Federal Civilian Executive Branch (FCEB) agencies to apply patches by August 10, 2026, and device owners are advised to take proactive measures to protect their networks.

Published: Sat Aug 8 03:24:53 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Data Breach Alert: Unlimited Technology Systems Compromised by Hackers Exposing 3.8 Million Healthcare Patients' Data

Unlimited Technology Systems has announced that 3.8 million healthcare patients' personal and medical information have been exposed due to a recent data breach at one of its commercial data centers between October 5th and 10th, 2025.

Published: Sat Aug 8 03:29:50 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Crucial Vulnerability Revealed: How Atlassian's Rovo Assistant Can Be Exploited by Attackers

A recently discovered vulnerability in Atlassian's Rovo assistant allows attackers to trick the tool into sending sensitive Jira and Confluence data to attacker-controlled servers. Organizations must review their settings and tighten permissions to mitigate this risk.

Published: Sat Aug 8 04:39:55 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New CSS Attacks Can Break Webmail Defenses: A Growing Threat to User Security


New research has uncovered a growing threat in the form of CSS attacks that can compromise webmail interfaces and steal user credentials. The study reveals how attackers are using sophisticated techniques such as label-jacking, paste races, and click-based exfiltration to bypass security measures and exploit vulnerabilities within popular webmail services. As such, it is essential that users remain vigilant and take steps to protect themselves from these threats.

Published: Sat Aug 8 04:45:27 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Surveillance State: The Expanding Reach of Flock, Uber, Lyft, and ICE


In a rapidly expanding surveillance state, companies like Flock, Uber, Lyft, and Immigration and Customs Enforcement (ICE) are being linked together to monitor citizens. From the collection of DNA from migrants to the use of laser weapons in urban surveillance, this article explores the various ways these entities are working together to gather data on individuals without their consent.

Published: Sat Aug 8 06:21:45 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Sensitive Information Continues to Find Its Way to Unsuspecting Researchers: A Growing Concern for Corporate Data Security

Researchers Cory Solovewicz and Mike Sheward have been unwittingly receiving thousands of unwanted emails from companies sending sensitive information to placeholder domains like "noreply.us" and "noreply.net". As they work to alert affected organizations, these security experts urge companies to audit their systems and adopt better communication protocols to prevent data breaches.

Published: Sat Aug 8 06:29:26 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Progress LoadMaster Vulnerability: A Critical Security Alert from CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog, categorizing it as an OS Command Injection Remote Code Execution issue with a CVSS score of 9.6. This critical alert underscores the urgency for organizations to address the vulnerability by applying relevant security patches and reinforces the importance of proactive cybersecurity measures in safeguarding against data breaches and system compromises.

Published: Sat Aug 8 06:35:06 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Deadly Zero-Day Exploit in Metabase: Exposing Admin Access and Sensitive Data



A deadly zero-day exploit in Metabase exposed admin access and sensitive data of its customers, revealing a grim reminder of the importance of patching vulnerabilities promptly and regularly updating software. According to Metabase, an unauthenticated attacker was able to inject arbitrary SQL into the platform's application database, granting access to administrator rights over the entire instance.

The vulnerability affected versions 1.58 to 63, with a specific patched point release for each. This exploit highlights the urgency of addressing zero-day vulnerabilities and emphasizes the need for prompt patching and regular software updates.



Published: Sat Aug 8 07:42:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

AI Coding Tools: A Looming Threat to Developer Security and Privacy


Recent research has revealed a disturbing trend in the development community: numerous security and privacy issues with AI-powered coding tools. The study, which analyzed 1.1 million Reddit posts, sheds light on the problems facing developers who use these tools. From unauthorized file operations to operational safety concerns, the risks are real. Experts recommend that LIDE makers prioritize security and privacy in their design, implementing measures such as proper controls, verification layers, and integration of sensitive file protection.

Published: Sat Aug 8 08:55:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Palo Alto Networks Under Scrutiny: The Growing Threat of Chinese Cybersecurity Reviews

China has initiated a cybersecurity review of Palo Alto Networks' products sold in China, citing national security concerns. The move is part of Beijing's drive for technological self-reliance and reflects growing tensions between the United States and China over cybersecurity.

Published: Sat Aug 8 10:02:15 2026 by llama3.2 3B Q4_K_M



SecurityWeek

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Black Hat USA 2026 Summary of Vendor Announcements (Part 4)

Microsoft, Apple Release Fresh Security Updates

3.8 Million Impacted by Unlimited Technology Systems Data Breach

Critical Vulnerabilities Patched With Chrome 151 Update

Snowflake Hacker Pleads Guilty in US Court

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

CISA News

CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software

CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making

CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity

CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers

CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers

CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure

New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures

CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities

CISA Blog

Lessons from CISA’s Cyber Incident

Five Eyes Cyber Security Agencies Statement

CISA Offers Vital Resources as Venues Prepare for Key 2026 Events

Patch Smarter, Not Harder

NCSWIC releases additional content in its NCSWIC Video Series

CISA Highlights Vital Resources to Help Event Attendees Stay Safe

Preparing for the World Stage

Securing the American Experience

The End is Just the Beginning of Better Security: Enhanced Vulnerability Management with OpenEoX

Super Bowl LX: Strengthening Preparation, Building Resilience, Fostering Partnerships

All CISA Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CPDLC over ATN-B1 Vulnerabilities

ABB Ability Zenon

Medixant RadiAnt DICOM

Johnson Controls Inc. TL280

CISA Adds One Known Exploited Vulnerability to Catalog

Thermo Fisher Applied Biosystems Genetic Analyzers

CISA Adds Three Known Exploited Vulnerabilities to Catalog

Acrisure KARR BT and DR-100

CISA Adds One Known Exploited Vulnerability to Catalog

MikroTik RouterOS

Open Source Software: Security Principles and Practices

Toptech Systems RCU II+ and Multiload II+

Watchfire Controller Software

Schneider Electric IGSS

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

Mitsubishi Electric CC-Link IE TSN Communication Protocol

MZ Automation GmbH libiec61850

Johnson Controls OpenBlue Employee

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

MZ Automation lib60870

o6 Automation open62541

NASA Core Flight System (cFS) Health & Safety (HS) Application

2026 Minimum Elements for a Software Bill of Materials (SBOM)

CISA Adds One Known Exploited Vulnerability to Catalog

ABB KNX Update Tool

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

Siemens Desigo CC

Siemens SIMATIC S7-PLCSIM Advanced

igloohome Smart Lock Mobile Application

Exploit-DB.com RSS Feed

[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution

[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

[webapps] Langflow 1.9.0 - RCE

[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

[webapps] MCPJam Inspector - Remote Code Execution

[local] ProtonVPN v4.4.1 - Unquoted Service Path

[webapps] Flowise 3.1.3 - arbitrary code execution

[remote] Hydra - Stack Buffer Overflow

[webapps] Discuz! X5.0 - Authentication Bypass

[webapps] Tenable Nessus 10.12.1 - SQL Injection

[webapps] WordPress Bricks Builder Theme - RCE

[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

[webapps] Joomla Extension 4.1.4 - PHP Object injection

[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

[webapps] KeepInMind 0.8.4.2 - Stored XSS

[webapps] KNX visualisering - Broken Access Control

[local] Windows Defender (MsMpEng.exe) - Race Condition

[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

[webapps] OpenEMR 7.0.2 - Arbitrary File Read

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection

[webapps] WordPress OrderConvo 14 - Path Traversal

[remote] Notepad++ 8.9.6 - Arbitrary Code Execution

[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting

[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration

[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection

[remote] Microsoft - NTLMv2 Hash Capture

[webapps] MikroORM 7.0.13 - SQL Injection

[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion

[webapps] Langflow 1.3.0 - Remote Code Execution

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

[local] ZTE Routers - Unauthenticated Denial of Service

[local] ZTE ZXHN H188A V6 - Authentication Bypass

[local] ZTE H298A / H108N - Unauthenticated Credential Exposure

[local] Linux Kernel - Local Privilege Escalation

[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)

[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow

[dos] strongSwan 5.9.13 - DoS

[local] Linux Kernel - Local Privilege Escalation

[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal

[webapps] EspoCRM 9.3.3 - SSRF

[webapps] scramble - Remote Code Execution

[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection

[local] Realtek rtl819x - Local Privilege

[webapps] OpenCATS 0.9.7.4 - SQL Injection

[webapps] Grav CMS 2.0.0-beta.2 - Remote Code Execution

Full Disclosure

Dangling DNS record for bastion.certb.cdp.bethesda.net

CL.0 desync in www.microsoft.com

CVE-2026-15013 miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)

[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability

[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability

[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability

[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability

[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

[SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

[SYSS-2026-048]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

[SYSS-2026-047]: DICOM Toolkit (DCMTK) - Path traversal (CWE-22)

[SYSS-2026-046]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

APPLE-SA-07-27-2026-8 Safari 26.6

APPLE-SA-07-27-2026-7 visionOS 26.6

APPLE-SA-07-27-2026-6 watchOS 26.6

Open Source Security

CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay

CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped

CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters

CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation

CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow

CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage

CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing

CVE-2026-64958: Apache CXF: Denial of service via message header attachments

CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message

CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments

Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape

CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client

CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client








© Ethical Hacking News . All rights reserved.

Privacy | Terms of Use | Contact Us