Lazarus Exploits Windows AFD.sys Zero-Day in Defense Sector Attacks
August 21, 2026 North Korean Lazarus hackers exploited CVE-2026-68820, a zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys), to deploy their FudModule rootkit and gain SYSTEM privileges on defense-sector targets. Microsoft patched…
Rust Supply Chain Attack on arrayref Crate
August 21, 2026 The Rust Security Response Team has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency. That dependency executed a…
Operation CameraSwarm: Dahua Cameras Compromised
August 20, 2026 Threat intelligence firm Hunt.io has uncovered a massive 35-day campaign that compromised more than 14,500 Dahua IP cameras across Ukraine and Russia. The operation, dubbed Operation CameraSwarm, exploited credential attacks,…
ShieldBreak CVE Microsoft Defender Zero-Day
August 18, 2026 Microsoft confirmed it is actively working on a security patch for CVE-2026-69414, a zero-day vulnerability in Microsoft Defender publicly known as ShieldBreak. The flaw allows local attackers with limited permissions to escalate to…
Lazarus Exploits Windows Zero-Day to Deploy Troy Backdoor
August 17, 2026 The North Korean Lazarus Group has been caught exploiting a newly patched Windows zero-day vulnerability as part of its long-running Operation Dream Job campaign. The flaw, tracked as CVE-2026-68820, targets the Windows Ancillary Function…
Threema DDoS Attack Disrupts Secure Messaging Service
August 16, 2026 Large-scale distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service on August 12, 2026. Consequently, users experienced severe communication disruptions for several hours. Threema is a Swiss end-to-end…
Sable Squirrel Spends Million on Expired Domains for Malware
August 16, 2026 A threat actor tracked as Sable Squirrel has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise. Consequently, the group operates illegal sports streaming platforms, online gambling promotions, and…
Head Mare Hacktivists Trojanize TrueConf Installers to Deploy PhantomCore and PhantomGraph Backdoors
August 10, 2026 The Head Mare hacktivist group has been exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors. Researchers at Kaspersky discovered the campaign in…
North Carolina Ports Cyberattack Disrupts Three Major Maritime Facilities
August 8, 2026 The North Carolina Ports Authority confirmed a cyberattack that forced a systems-wide outage across three major port facilities. The incident disrupted operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte…
CISA KEV Alert for Active Zero-Day Exploitation of Cisco FMC
July 30, 2026 CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The vulnerability, tracked as CVE-2026-20316, allows…