A large-scale phishing operation has been observed disguising a malicious script as a TrueType font file (.tff). Using the fake .ttf extension, a Lua-based loader is slipped onto Windows systems and a rotating cast of remote access trojans and infostealers is deployed. According… Read More "Phishing Campaign Hides Lua Loader as TrueType Font File"
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Swati KhandelwalAug 17, 2026Vulnerability / DevOps GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete… Read More "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects"
Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Anthropic has found evidence that three of its Claude AI models reached the internet from an evaluation environment to hack third-party organizations, in an echo of revelations from OpenAI last week. The AI giant said in a blog post on… Read More "Anthropic Reveals Claude Escaped Testing, Breaching Three Companies"
XDR Deployment Considerations: Privacy, Compliance, and More
Attackers are moving rapidly across endpoints, networks, cloud workloads, and identities. Traditional security tools often operate in isolation, creating visibility gaps that can hinder security teams from detecting and responding to complex attacks. This challenge has driven the adoption of… Read More "XDR Deployment Considerations: Privacy, Compliance, and More"
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Swati KhandelwalAug 17, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in… Read More "Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection"
AWS Blames North Korean Group for npm Supply Chain Attacks
A series of attacks on npm libraries including axios was the work of North Korean actors, AWS has said. The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries… Read More "AWS Blames North Korean Group for npm Supply Chain Attacks"
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the… Read More "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware"
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese threat actor has used large language models (LLMs) from Chinese and Western companies to compromise internet-exposed digital infrastructure in Asia. In particular, they leveraged one of DeepSeek’s AI models, Hermes Agent, an open-source agentic AI framework, to orchestrate… Read More "Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits"
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Swati KhandelwalAug 17, 2026Vulnerability / Mobile Security Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from… Read More "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access"
The Morning After We Pull a Root of Trust, Nobody Owns It
OPINION In June 2024, Google’s Chrome Root Program said it would stop trusting new Transport Layer Security (TLS) certificates from Entrust. Behind the decision, years of compliance failures and a clear technical call. The decision was right. The fallout became… Read More "The Morning After We Pull a Root of Trust, Nobody Owns It"