SafePal Data Breach Crypto Wallet Customers Exposed
August 17, 2026 Cryptocurrency hardware wallet provider SafePal disclosed a data breach that exposed customer order information for approximately 39,798 users. The incident involves an authorization flaw in the company’s order-tracking system, and…
Threema DDoS Attack Disrupts Secure Messaging Service
August 16, 2026 Large-scale distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service on August 12, 2026. Consequently, users experienced severe communication disruptions for several hours. Threema is a Swiss end-to-end…
Sable Squirrel Spends Million on Expired Domains for Malware
August 16, 2026 A threat actor tracked as Sable Squirrel has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise. Consequently, the group operates illegal sports streaming platforms, online gambling promotions, and…
Mirai Successor Hijacks Routers for SOCKS5 Proxies and DDoS Attacks
August 15, 2026 A new modular Linux botnet named Evooo1Bot is actively exploiting internet-facing gateway devices across multiple regions. Also, it turns compromised routers and IoT hardware into SOCKS5 proxy relays for concealed malicious traffic. What…
SAP Commerce Cloud Unauthenticated RCE Under Active Exploitation Days After Patch
August 15, 2026 Threat actors are actively exploiting a maximum-severity vulnerability in SAP Commerce Cloud that allows unauthenticated remote code execution. Tracked as CVE-2026-58231, this critical flaw carries a CVSS score of 10.0 and was patched on…
macOS Screen Sharing CVE: Active Exploitation Confirmed for Root Access and Crypto Mining
August 14, 2026 The Netherlands’ National Cyber Security Centre (NCSC) has confirmed active exploitation of CVE-2026-65400, a macOS Screen Sharing authentication bypass vulnerability. Attackers with network access to TCP port 5900 can gain root…
Plug and Pwn Attack: Fake USB Devices Hijack Windows Plug and Play for SYSTEM Privileges
August 13, 2026 Researchers have unveiled Plug and Pwn, a new class of attacks that abuses Windows Plug and Play to install vulnerable vendor software and gain SYSTEM privileges with little or no user interaction. First demonstrated at DEF CON 34, the…
Gunra Ransomware: CISA and FBI Warn of Conti-Derived RaaS Targeting Global Critical Infrastructure
August 11, 2026 CISA, the FBI, the NSA, and South Korea’s National Police Agency have issued a joint advisory warning that the Gunra ransomware gang is actively targeting government agencies, critical infrastructure, and healthcare organizations…
Critical Progress LoadMaster CVE Enables Unauthenticated Command Injection
August 11, 2026 CISA has added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities Catalog. Attackers are actively exploiting this flaw to execute arbitrary commands on unpatched…
Solidity Pro VS Code Extensions Steal Crypto Wallets and Developer Credentials
August 10, 2026 Cybersecurity researchers have uncovered malicious Microsoft Visual Studio Code extensions posing as Solidity development tools. These extensions steal browser crypto wallets, API keys, SSH keys, and cloud credentials from unsuspecting…