Check Point Researchers Weaponize Microsoft Defender Remediation Driver for Kernel-Level Attacks
August 23, 2026 Check Point Research has disclosed a technique that weaponizes Microsoft Defender’s own signed boot-time remediation driver, BTR.sys, to execute arbitrary kernel-level file and registry operations on fully patched Windows systems.…
MoYu Group Deploys Proxy Botnet Malware on Android Car Head Units via DoFun Update App
August 22, 2026 Kaspersky researchers have uncovered a supply-chain attack targeting Android-based car head units that uses a legitimate device-update app to spread proxy botnet malware. The operation, attributed to the MoYu threat actor group, marks the…
ShieldBreak CVE Microsoft Defender Zero-Day
August 18, 2026 Microsoft confirmed it is actively working on a security patch for CVE-2026-69414, a zero-day vulnerability in Microsoft Defender publicly known as ShieldBreak. The flaw allows local attackers with limited permissions to escalate to…
Threema DDoS Attack Disrupts Secure Messaging Service
August 16, 2026 Large-scale distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service on August 12, 2026. Consequently, users experienced severe communication disruptions for several hours. Threema is a Swiss end-to-end…
macOS Screen Sharing CVE: Active Exploitation Confirmed for Root Access and Crypto Mining
August 14, 2026 The Netherlands’ National Cyber Security Centre (NCSC) has confirmed active exploitation of CVE-2026-65400, a macOS Screen Sharing authentication bypass vulnerability. Attackers with network access to TCP port 5900 can gain root…
Gunra Ransomware: CISA and FBI Warn of Conti-Derived RaaS Targeting Global Critical Infrastructure
August 11, 2026 CISA, the FBI, the NSA, and South Korea’s National Police Agency have issued a joint advisory warning that the Gunra ransomware gang is actively targeting government agencies, critical infrastructure, and healthcare organizations…
North Carolina Ports Cyberattack Disrupts Three Major Maritime Facilities
August 8, 2026 The North Carolina Ports Authority confirmed a cyberattack that forced a systems-wide outage across three major port facilities. The incident disrupted operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte…
Metabase SQLi Zero-Day Flaw Grants Attackers Admin Access and Steals Database Credentials
August 7, 2026 A critical SQL injection vulnerability in Metabase is under active zero-day exploitation, allowing unauthenticated attackers to seize administrator control of instances and steal connected database credentials. The flaw has already…
N-able CVE: Active Exploitation of N-central Auth Bypass Threatens MSPs and Downstream Clients
August 4, 2026 N-able has confirmed active exploitation of an authentication bypass vulnerability in its N-central remote monitoring and management platform. The flaw, tracked as CVE-2026-18577, allows threat actors to seize administrative control of…
Iranian APT Actors Exploit Internet-Exposed PLCs in U.S. Critical Infrastructure
August 3, 2026 Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure sectors, including government facilities, water systems, and energy plants. A joint…