You may have noticed that Flock Safety’s automatic license plate reader cameras—and the cops who misuse them—are getting a lot of coverage lately. This week, WIRED found a particularly wild case: A cop in Alpharetta, Georgia, was accused of searching… Read More "The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn"
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that. According to research from threat exposure management firm Zafran Security… Read More "Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard"
ICO Reprimands Criminal Records Office After 2023 Breach
The UK’s data protection watchdog has issued a reprimand to the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach which impacted over 10,000 people. Between August 2022 and March 2023, a hacker gained unauthorized… Read More "ICO Reprimands Criminal Records Office After 2023 Breach"
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
A ransomware affiliate’s attempt to disable security tools by rebooting a victim’s system into Safe Mode backfired, with the tactic apparently preventing the malware from successfully encrypting the target’s file, according to recent research by Huntress. The managed security specialist… Read More "Akira Affiliate Crashes Ransomware After Attempting EDR Evasion"
Trump Authorizes Private Sector Participation in Offensive Cyber Opera
The White House has authorized federal law enforcement agencies to collaborate with private firms in conducting offensive cyber strikes on foreign threat actors targeting the US. The National Security Presidential Memorandum (NSPM), signed by President Donald Trump on August 12,… Read More "Trump Authorizes Private Sector Participation in Offensive Cyber Opera"
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of… Read More "APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations"
vCenter Flaw Exploited Just Five Days After Disclosure
A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems. The treat research team at German firm Quirso discovered the campaign during… Read More "vCenter Flaw Exploited Just Five Days After Disclosure"
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE… Read More "China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access"
Google Targets 2027 for First Major Post-Quantum Security Milestone
Google Cloud has divided its post-quantum migration into interim deadlines, targeting its first major risk domain for completion by the end of 2027. The roadmap, published on August 12, organized the work into three risk domains drawn from Google’s own… Read More "Google Targets 2027 for First Major Post-Quantum Security Milestone"
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
Swati KhandelwalAug 28, 2026Vulnerability / Cloud Security ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The… Read More "Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL"