-
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation could allow attackers to run malicious code on affected systems. Released on August 11, 2026, this vul…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that dynamically blends direct HTTPS traffic with Google Apps Script relays. The latest findings show an operator…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access and helps neutralize endpoint visibility. This DPRK-linked threat actor is specifically targetin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Seashell Blizzard. The activity, observed since at least May 2026, begins on job-search platforms…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s August 2026 Patch Tuesday released fixes for hundreds of vulnerabilities across various products, including Windows, Office, SharePoint, Azure, .NET, PowerShell, Visual Studio Code, and other enterprise solutions. A total of 394 distinct fl…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board allegedly disrupted the aircraft’s official internet service and broadcast a fraudulent wireless net…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Zoom has released security updates to address four vulnerabilities that could expose meeting participants to significant attacks, including a zero-click remote code execution flaw dubbed “Zoomsday.” The most severe issue, tracked as CVE-2026-53413, aff…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A ClickFix prompt can end in a remote-access foothold. CNCMachineRMS, an undocumented x64 RAT deployed at the end of a BabaDeda loader chain that turns a user-driven execution event into persistent hands-on-keyboard access. Rather than behaving like a …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Docker, tracked as CVE-2026-17106 and referred to as “CopyEscape,” allows malicious containers to overwrite files on the host system using the widely utilized `docker cp` command. This flaw can lead to code execution as the …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstre…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


