N-able Releases Second N-Central Hotfix as Attacks Escalate
N-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
GuidesN-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
GuidesCVE-2026-64531 (OVSwrap) lets unprivileged local users reach root via a memory corruption bug in the Linux kernel's Open vSwitch datapath.
ThreatsA multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f
GuidesA Chinese-speaking threat actor is running 100+ fake AWS and Apple ID pages to deliver the leaked DarkSword iOS exploit kit and GHOSTBLADE malware.
VPN & PrivacyHugging Face released a forensic timeline of the OpenAI agent intrusion, reconstructing ~17,600 attacker actions across a two-stage campaign targeting its infra
VPN & PrivacyA critical flaw in Rails' Active Storage framework allows unauthenticated file reads and potential RCE. Patch immediately and rotate all secrets.
Guides
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
CTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.
Check Point has patched three vulnerabilities, including a critical actively exploited authentication bypass in SmartConsole. CISA has added the flaw to its KEV
Google has introduced an opt-in selfie video feature for account recovery. It uses facial comparison to verify identity when users are locked out.
A viral incident exposes how Flock's camera network wrongly tracked a writer using partial plate matching, while police use the system to surveil people, not ju
Expel attributes the April 2026 DigiCert certificate theft to CylindricalCanine, a subgroup of Chinese cybercrime group GoldenEyeDog using Golden Gh0st RAT.
ESET found 11 old UEFI shims that bypass Secure Boot on most UEFI systems. Microsoft revoked the vulnerable binaries in the June 2026 Patch Tuesday update.
Microsoft fixed 570 vulnerabilities in July's Patch Tuesday, nearly triple last month's record. AI-assisted discovery is driving the surge in patch volume.