Cronos Tectonic Exploit Drained 4 Million in 20 Minutes
September 1, 2026 Cronos blockchain halted all transactions on August 30, 2026, after a threat actor exploited the Tectonic lending platform in a $74 million price-manipulation attack. The attacker artificially inflated the price of Tectonic’s…
Fire Ant Espionage Campaign Hijacks Cisco Routers
August 31, 2026 A China-nexus cyber espionage actor tracked as Fire Ant has evolved beyond hypervisor compromise to hijack Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Consequently, the group turns trusted network…
Socket Uncovers 19 Malicious Chrome and Edge Extensions Stealing Crypto Wallets and Credentials
August 30, 2026 Socket researchers have uncovered a sprawling malware campaign hidden inside 19 browser extensions for Google Chrome and Microsoft Edge. Furthermore, the malicious framework steals cryptocurrency wallet secrets, harvests credentials, and…
Rhysida Ransomware Attack on Berlin Government
August 31, 2026 Berlin’s state government has confirmed that it is the target of a major ransomware and data extortion campaign. Consequently, threat actors claiming affiliation with the Rhysida ransomware group have added the German capital to…
PaperCut Releases Second Emergency Patch After Attackers Bypass Initial Fixes
August 29, 2026 PaperCut has released a second emergency security patch for two critical vulnerabilities in its PaperCut NG and PaperCut MF print management software after security researchers discovered multiple methods to bypass the original emergency…
ShinyHunters Steals 284 Million Healthcare Records in Vishing Attack
August 30, 2026 Healthcare and pharmaceutical distribution giant McKesson has disclosed a significant cybersecurity incident. The company confirmed unauthorized access to third-party applications and data exfiltration. Consequently, the ShinyHunters…
CISA Imposes 3-Day Patch Mandate on Perfect-10 Oracle WebLogic Proxy Flaw
August 28, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has imposed its tightest emergency patch mandate on a maximum-severity Oracle vulnerability that China-linked threat actors have exploited across government and commercial…
ATF Confirms Major Cybersecurity Incident After Qilin Ransomware Breach Claim
August 27, 2026 The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a major cybersecurity incident on August 26, 2026, after the Qilin ransomware gang listed the U.S. federal law enforcement agency on its dark web data leak portal.…
Mirage2FA Phishing Campaign Compromises 4,500 Microsoft 365 Accounts
August 25, 2026 The Mirage2FA phishing campaign has compromised an estimated 4,500 organizations across the United States and European Union by abusing legitimate Microsoft 365 login flows and bypassing traditional two-factor authentication.…
Unpatched Calix GS7 XGS Router CVE Lets Attackers Bypass NAT and Expose Internal Devices
August 24, 2026 An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass NAT and firewall protections and expose internal network devices to the public internet. The flaw, tracked as CVE-2026-75501, affects…