The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it… Read More "TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore"
Ransomware Attacks Targeting Universities on the Rise
Universities have found themselves in the firing line of cybercriminals, as ransomware attacks against higher education institutions have increased, analysis of recent incidents has revealed. According to the Comparitech’s Education Ransomware Roundup for the first half of 2026, the number… Read More "Ransomware Attacks Targeting Universities on the Rise"
Metabase Patches Vulnerability Exploited as Zero-Day
Data analytics solutions provider Metabase has released urgent patches for a critical-severity SQL injection vulnerability that has been exploited in the wild as a zero-day. The security defect allows remote, unauthenticated attackers to inject arbitrary SQL queries into the Metabase… Read More "Metabase Patches Vulnerability Exploited as Zero-Day"
Network Forensics: Techniques, Tools & Best Practices
Cyber forensics or digital forensics is the process of the collection and analysis of digital evidence from computers, phones, and networks. It aims to reveal the source, nature, scope, and damage caused by cyberattacks. Network forensics is a subset of… Read More "Network Forensics: Techniques, Tools & Best Practices"
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Ravie LakshmananAug 10, 2026Cybersecurity / Hacking A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this… Read More "⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors"
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks
Open AI’s ChatGPT entered the top 10 of the most impersonated brands in phishing attacks for the first time in the second quarter of 2026, according to a Check Point study. This included a fake “ChatGPT Plus payment failed” email… Read More "ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks"
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions. The Israeli cybersecurity startup, which emerged from stealth mode in June to protect organizations from… Read More "‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad"
Fidelis XDR for AI Risk Management Across Key Layers
No. Network, Endpoint, and Deception watch the infrastructure around AI systems, traffic, endpoint behavior, attacker reconnaissance, not the math inside a model. Interpretability and AI-native security are different disciplines from what Fidelis provides. Source link Read More "Fidelis XDR for AI Risk Management Across Key Layers"
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Ravie LakshmananAug 10, 2026Ransomware / Cybercrime Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary’s previous use… Read More "China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw"
Outdated Cybercrime Laws Put Security Researchers at Risk
DEF CON 34 – Las Vegas – Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn’t distinguish between malicious hackers and those working in good faith. But change may finally be coming.… Read More "Outdated Cybercrime Laws Put Security Researchers at Risk"