Two vulnerabilities affecting Fortinet’s malware analysis and detection FortiSandbox have been exploited in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS)… Read More "CISA Mandates Urgent Patch for Actively Exploited Fortinet Flaws"
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a… Read More "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner"
23andMe Faces New Security Mandates in $18m Data Breach Settlement
A settlement of $18m has been reached between a coalition of 42 US attorneys general and genetic testing firm 23andMe following the 2023 data breach. New York Attorney General Letitia James and the bipartisan coalition has also ensured new data protection… Read More "23andMe Faces New Security Mandates in $18m Data Breach Settlement"
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
Ravie LakshmananAug 15, 2026Vulnerability / Cloud Security A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient… Read More "SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch"
OpenAI president’s blog pushing agentic AI most notable for what it did not say
“Give your security team an agent,” he wrote. “Start using Codex, the Codex Security plugin, or another capable agentic coding and security tool. Give it approved access to the codebases, infrastructure configurations, and technical documentation your security team needs to… Read More "OpenAI president’s blog pushing agentic AI most notable for what it did not say"
Government Agencies Falling Victim to Ransomware Daily, Warns Study
The number of ransomware attacks which target government departments and agencies has risen to the extent that one has its services restricted by encryption every single day. The figure comes from analysis by researchers at Comparitech, who studied ransomware incidents… Read More "Government Agencies Falling Victim to Ransomware Daily, Warns Study"
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since… Read More "Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic"
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain
A single prompt is enough to encourage OpenAI’s ChatGPT-5.5 large language model (LLM) to conduct full-scale offensive cyber-attacks, complete with the ability to gain domain-level access to a network in under 40 minutes, according to tests conducted by cybersecurity researchers. Threat… Read More "Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain"
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Ravie LakshmananAug 17, 2026Vulnerability / Website Security A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability,… Read More "Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads"
Phishing Campaign Hides Lua Loader as TrueType Font File
A large-scale phishing operation has been observed disguising a malicious script as a TrueType font file (.tff). Using the fake .ttf extension, a Lua-based loader is slipped onto Windows systems and a rotating cast of remote access trojans and infostealers is deployed. According… Read More "Phishing Campaign Hides Lua Loader as TrueType Font File"