A vulnerability in UNISOC modem firmware can allow arbitrary code execution with kernel privileges from the modem context, potentially allowing an attacker to modify Android kernel code. The flaw stems from a lack of isolation between modem memory and kernel… Read More "UNISOC Modem Flaw Enables Remote Code Execution via Video Calls"
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers. The exploited bug, tracked as CVE-2026-65400, is a high-severity authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials.… Read More "Recent macOS Screen Sharing Vulnerability Exploited in Attacks"
Brand Impersonation Takedown: Why Manual Response Fails
Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve — phishing pages and fake executive profiles often do their damage within hours of going live, while manual removal can take days. A managed takedown… Read More "Brand Impersonation Takedown: Why Manual Response Fails"
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Ravie LakshmananAug 17, 2026Cybersecurity / Hacking The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading… Read More "⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More"
Why data quality dictates security operations success
As AI takes on more security operations center (SOC) workflows to automate threat triage, indicator extraction, and incident report generation, security operations leaders face a persistent question: Does SOC performance depend more on the large language model (LLM) deployed or… Read More "Why data quality dictates security operations success"
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
More than 40,000 WordPress sites have been exposed to an authentication bypass flaw in the User Profile Builder plugin that can let unauthenticated attackers access the site’s administrator account. The vulnerability, tracked as CVE-2026-15826 and given a critical CVSS rating… Read More "WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover"
680,000 Impacted by French Tax Authority Data Breach
France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. The incident was disclosed after a threat actor boasted on a hacking forum about accessing DGFiP’s internal systems and exfiltrating data. According to DGFiP,… Read More "680,000 Impacted by French Tax Authority Data Breach"
How MCP Servers Can Expose Enterprise Secrets
The Hacker NewsAug 17, 2026AI Security / Identity Security MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents… Read More "How MCP Servers Can Expose Enterprise Secrets"
Zhipu says new coding AI developed advanced cyber skills faster than expected
“After expert review, screening, and deduplication, the model identified 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues,” the statement added. The findings cover system kernels, operating systems, browser engines, open-source infrastructure, Web applications and network protocols, Zhipu said.… Read More "Zhipu says new coding AI developed advanced cyber skills faster than expected"
Klue Breach Enables Hackers to Compromise Cybersecurity Firms
Several companies have disclosed that they were affected by a breach of business intelligence provider Klue, including a number of cybersecurity firms. Huntress, Recorded Future, Jamf and Tanium have all acknowledged using Klue’s intelligence services and confirmed that the breach enabled… Read More "Klue Breach Enables Hackers to Compromise Cybersecurity Firms"