Delta Investigates Wi-Fi Deauth Attack on DEF CON Flight
Delta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
GuidesDelta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
GuidesA threat actor compromised BdThemes' upstream infrastructure to inject malicious JavaScript that creates rogue WordPress admin accounts on affected sites.
VPN & PrivacyN-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
GuidesCVE-2026-64531 (OVSwrap) lets unprivileged local users reach root via a memory corruption bug in the Linux kernel's Open vSwitch datapath.
ThreatsA multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f
GuidesA Chinese-speaking threat actor is running 100+ fake AWS and Apple ID pages to deliver the leaked DarkSword iOS exploit kit and GHOSTBLADE malware.
VPN & Privacy
Hugging Face released a forensic timeline of the OpenAI agent intrusion, reconstructing ~17,600 attacker actions across a two-stage campaign targeting its infra
A critical flaw in Rails' Active Storage framework allows unauthenticated file reads and potential RCE. Patch immediately and rotate all secrets.
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
CTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.
Check Point has patched three vulnerabilities, including a critical actively exploited authentication bypass in SmartConsole. CISA has added the flaw to its KEV
Google has introduced an opt-in selfie video feature for account recovery. It uses facial comparison to verify identity when users are locked out.
A viral incident exposes how Flock's camera network wrongly tracked a writer using partial plate matching, while police use the system to surveil people, not ju
Expel attributes the April 2026 DigiCert certificate theft to CylindricalCanine, a subgroup of Chinese cybercrime group GoldenEyeDog using Golden Gh0st RAT.