GitHub already has an EDR. You just have to listen to it
Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.…
At their Black Hat USA 2026 presentation, researchers Yossi Weizman of…
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.…
Three of the vulnerabilities affect all Zoom client applications for a…
6, while the fourth impacts Zoom Workplace VDI Client for Windows and …
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.…
The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-202…
Past vulnerabilities in this component have let an authorized attacker…
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.…
The Metabase vulnerability revealed on August 6, designated CVE-2026-7…
Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted.…
That instinct is increasingly out of date.
A growing body of security research — exploit demonstrations, independ…
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.…
Researchers from Malwarebytes found the campaign distributing a malici…
Attackers created a lookalike CCleaner download site and used it to di…
Microsoft wants you to rethink your approach to cyber defense
Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft.…
David Weston, group manager in the Windows team at Microsoft, told del…
Weston’s keynote — entitled “The End of Rare: Defending When Offense I…
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.…
The researcher, who goes by the name Nightmare Eclipse, has been engag…
Nightmare Eclipse has not provided the further details we requested, h…
It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.…
Enterprises use Microsoft System Center Configuration Manager (SCCM) t…
XM Cyber’s attack can move from an ordinary domain account to code exe…
Trump administration opens door to private-sector cyber offensives
The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime.…
A presidential memorandum issued on August 12 directs the National Coo…
The memorandum says, “any resulting operational action will be exclusi…
AI agents wage near-autonomous cyberattack on Asian government networks
Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.…
The campaign unfolded over four days in early July, during which multi…
“In roughly four days, the agentic attacker produced 1,395 files, 85 c…
Attackers target zero-day vulnerability in geospatial data platform GeoServer
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.…
The software is widely used by organizations in many industries, inclu…
A bug bounty hunter shared the vulnerability Wednesday on X as a zero …
AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week.…
Here are some key takeaways from this year’s hacker summer camp that C…
Reactive patching alone is no longer sufficient Microsoft’s David West…
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled.…
According to Huntress, the technique successfully took both its agent …
This, the researchers said, gave the attacker a window to operate with…