Uncategorized

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets 2026-08-18 at 14:20 By Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part […]

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets Read More »

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers 2026-08-18 at 12:10 By SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Read More »

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects 2026-08-18 at 00:03 By GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects Read More »

Nvidia provides $105B in financing toward OpenAI’s massive Ohio data center — will be one of biggest in world

Nvidia provides $105B in financing toward OpenAI’s massive Ohio data center — will be one of biggest in world 2026-08-17 at 22:05 By Thomas Barrabi OpenAI has inked a 20-year deal for the site, which will ultimately provide about eight gigawatts of computing capacity that will help support products like ChatGPT. In energy terms, a

Nvidia provides $105B in financing toward OpenAI’s massive Ohio data center — will be one of biggest in world Read More »

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection 2026-08-17 at 21:44 By Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Read More »

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads 2026-08-17 at 21:22 By A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads Read More »

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic 2026-08-17 at 20:41 By Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Read More »

Mark Zuckerberg’s Meta could face ‘astronomical’ damages as historic teen mental health case heads to trial

Mark Zuckerberg’s Meta could face ‘astronomical’ damages as historic teen mental health case heads to trial 2026-08-17 at 19:46 By Thomas Barrabi The Instagram parent claims it could face $1.4 trillion in damages – nearly the size of its entire market cap – based on how a coalition of state attorneys general argue that penalties

Mark Zuckerberg’s Meta could face ‘astronomical’ damages as historic teen mental health case heads to trial Read More »

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection 2026-08-17 at 19:00 By The converging landscape has shifted executive protection from a reactionary and operational pursuit to an intelligence-driven mission.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection Read More »

New California law could change how kids consume social media forever

New California law could change how kids consume social media forever 2026-08-17 at 18:46 By Nina Joudeh The proposals, AB 1709 and AB 2, cleared the State Senate Appropriations Committee this week and could reach Gov. Gavin Newsom’s desk before the legislative session ends Aug. 31. This article is an excerpt from Latest Technology News

New California law could change how kids consume social media forever Read More »

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More 2026-08-17 at 16:23 By The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Read More »

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access 2026-08-17 at 15:50 By Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Read More »

How MCP Servers Can Expose Enterprise Secrets

How MCP Servers Can Expose Enterprise Secrets 2026-08-17 at 15:50 By MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP

How MCP Servers Can Expose Enterprise Secrets Read More »

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner 2026-08-17 at 14:25 By A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score:

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner Read More »

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch 2026-08-17 at 14:25 By A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. “SAP Commerce

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Read More »

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware 2026-08-17 at 14:25 By Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Read More »

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies 2026-08-17 at 12:29 By Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. “While the malware reuses the

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies Read More »

Scroll to Top