The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. The post U.S., South Korean government agencies caution to be on lookout for Gunra...
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own...
What wouldst thou ask of the monkey's paw?
Qualcomm security advisory (AV26-795)
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and...
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed....
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to...
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation,...
How MCP turns PAM into an AI-ready source for faster reporting and compliance visibility
Cisco security advisory (AV26-794)
Crims talked their way onto three employee PCs before trousering corporate data
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
Roundcube security advisory (AV26-793)
Pub chain says turn off the cameras, reminds punters not to blare sound from phone vids either
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information,...
Stored Cross-Site Scripting vulnerability (CVE-2026-18478) has been found in Magnolia CMS software.
No, no nasties to see here, guv...
HashiCorp security advisory (AV26-791)
WordPress security advisory (AV26-792)
WebPros security advisory (AV26-790)
IBM security advisory (AV26-789)
This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn't expect.
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority...
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
Repairable hardware is little comfort when personal details escape
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and...
Heap-based buffer overflow vulnerability (CVE-2026-18370) has been found in eradman entr software.
Dell security advisory (AV26-788)
Walk away and hope the classifier catches anything irreversible or destructive