Delta Investigates Wi-Fi Deauth Attack on DEF CON Flight
Delta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
GuidesDelta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
GuidesThree vulnerabilities in Zoom's annotation tool allowed remote code execution with no user interaction. Patches shipped in June and July 2026.
VPN & PrivacyAI tutoring tools are growing fast, but quality and safeguards vary widely. Parents should understand the privacy, security, and developmental risks involved.
ThreatsA threat actor compromised BdThemes' upstream infrastructure to inject malicious JavaScript that creates rogue WordPress admin accounts on affected sites.
VPN & PrivacyN-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
GuidesCVE-2026-64531 (OVSwrap) lets unprivileged local users reach root via a memory corruption bug in the Linux kernel's Open vSwitch datapath.
Threats
A multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f
A Chinese-speaking threat actor is running 100+ fake AWS and Apple ID pages to deliver the leaked DarkSword iOS exploit kit and GHOSTBLADE malware.
Hugging Face released a forensic timeline of the OpenAI agent intrusion, reconstructing ~17,600 attacker actions across a two-stage campaign targeting its infra
A critical flaw in Rails' Active Storage framework allows unauthenticated file reads and potential RCE. Patch immediately and rotate all secrets.
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
CTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.
Check Point has patched three vulnerabilities, including a critical actively exploited authentication bypass in SmartConsole. CISA has added the flaw to its KEV
Google has introduced an opt-in selfie video feature for account recovery. It uses facial comparison to verify identity when users are locked out.