Head Mare Hacktivists Trojanize TrueConf Installers to Deploy PhantomCore and PhantomGraph Backdoors
August 10, 2026 The Head Mare hacktivist group has been exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors. Researchers at Kaspersky discovered the campaign in…
SCTPhantom Linux Kernel Flaw: 18-Year-Old SCTP Bug Enables Root and Container Escape
August 9, 2026 Researchers at Tencent Zhuque Lab disclosed an 18-year-old Linux kernel vulnerability in the Stream Control Transmission Protocol (SCTP) that could allow a local attacker to gain root privileges and escape container boundaries. Tracked as…
North Carolina Ports Cyberattack Disrupts Three Major Maritime Facilities
August 8, 2026 The North Carolina Ports Authority confirmed a cyberattack that forced a systems-wide outage across three major port facilities. The incident disrupted operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte…
Metabase SQLi Zero-Day Flaw Grants Attackers Admin Access and Steals Database Credentials
August 7, 2026 A critical SQL injection vulnerability in Metabase is under active zero-day exploitation, allowing unauthenticated attackers to seize administrator control of instances and steal connected database credentials. The flaw has already…
CISA KEV Alert: IBM Langflow CVE Enables Unauthenticated RCE on AI Workflow Platform
August 8, 2026 The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog. This critical flaw in IBM Langflow OSS allows unauthenticated attackers to execute remote code with superuser…
NatJack NAT Attack Hijacks TCP Sessions and Spoofs DNS
August 6, 2026 Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation connection state to hijack active TCP sessions, spoof DNS responses, and disclose victim IP addresses and mapped…
N-able CVE: Active Exploitation of N-central Auth Bypass Threatens MSPs and Downstream Clients
August 4, 2026 N-able has confirmed active exploitation of an authentication bypass vulnerability in its N-central remote monitoring and management platform. The flaw, tracked as CVE-2026-18577, allows threat actors to seize administrative control of…
Iranian APT Actors Exploit Internet-Exposed PLCs in U.S. Critical Infrastructure
August 3, 2026 Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure sectors, including government facilities, water systems, and energy plants. A joint…