Critical Elementor Pro CVE Enables Unauthenticated RCE on WordPress Sites
August 23, 2026 A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload executable PHP files for remote code execution on affected servers. Furthermore, the flaw has been actively disclosed and patched,…
ToxicPanda 2.0 Android Malware Abuses VPN and Wireless ADB
August 23, 2026 A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload executable PHP files for remote code execution on affected servers. Furthermore, the flaw has been actively disclosed and patched,…
Check Point Researchers Weaponize Microsoft Defender Remediation Driver for Kernel-Level Attacks
August 23, 2026 Check Point Research has disclosed a technique that weaponizes Microsoft Defender’s own signed boot-time remediation driver, BTR.sys, to execute arbitrary kernel-level file and registry operations on fully patched Windows systems.…
MoYu Group Deploys Proxy Botnet Malware on Android Car Head Units via DoFun Update App
August 22, 2026 Kaspersky researchers have uncovered a supply-chain attack targeting Android-based car head units that uses a legitimate device-update app to spread proxy botnet malware. The operation, attributed to the MoYu threat actor group, marks the…
Lazarus Exploits Windows AFD.sys Zero-Day in Defense Sector Attacks
August 21, 2026 North Korean Lazarus hackers exploited CVE-2026-68820, a zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys), to deploy their FudModule rootkit and gain SYSTEM privileges on defense-sector targets. Microsoft patched…
Rust Supply Chain Attack on arrayref Crate
August 21, 2026 The Rust Security Response Team has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency. That dependency executed a…
Critical MLflow CVE Enables SSRF Cloud Credential Theft
August 20, 2026 CISA has added a critical MLflow vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw, tracked as CVE-2026-64849, is a DNS-rebinding server-side request forgery…
Operation CameraSwarm: Dahua Cameras Compromised
August 20, 2026 Threat intelligence firm Hunt.io has uncovered a massive 35-day campaign that compromised more than 14,500 Dahua IP cameras across Ukraine and Russia. The operation, dubbed Operation CameraSwarm, exploited credential attacks,…
Critical Windows IKE Extension RCE CVE-2026-33824 Under Active Exploitation
August 19, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Windows Internet Key Exchange (IKE) vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026. Threat actors are actively…
CISA Confirms Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw
August 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a high-severity Windows Task Host privilege escalation vulnerability tracked as CVE-2025-60710. Consequently,…