Operation CameraSwarm: Dahua Cameras Compromised
August 20, 2026 Threat intelligence firm Hunt.io has uncovered a massive 35-day campaign that compromised more than 14,500 Dahua IP cameras across Ukraine and Russia. The operation, dubbed Operation CameraSwarm, exploited credential attacks,…
Critical Windows IKE Extension RCE CVE-2026-33824 Under Active Exploitation
August 19, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Windows Internet Key Exchange (IKE) vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026. Threat actors are actively…
CISA Confirms Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw
August 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a high-severity Windows Task Host privilege escalation vulnerability tracked as CVE-2025-60710. Consequently,…
ShieldBreak CVE Microsoft Defender Zero-Day
August 18, 2026 Microsoft confirmed it is actively working on a security patch for CVE-2026-69414, a zero-day vulnerability in Microsoft Defender publicly known as ShieldBreak. The flaw allows local attackers with limited permissions to escalate to…
Lazarus Exploits Windows Zero-Day to Deploy Troy Backdoor
August 17, 2026 The North Korean Lazarus Group has been caught exploiting a newly patched Windows zero-day vulnerability as part of its long-running Operation Dream Job campaign. The flaw, tracked as CVE-2026-68820, targets the Windows Ancillary Function…
Threema DDoS Attack Disrupts Secure Messaging Service
August 16, 2026 Large-scale distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service on August 12, 2026. Consequently, users experienced severe communication disruptions for several hours. Threema is a Swiss end-to-end…
Sable Squirrel Spends Million on Expired Domains for Malware
August 16, 2026 A threat actor tracked as Sable Squirrel has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise. Consequently, the group operates illegal sports streaming platforms, online gambling promotions, and…
Mirai Successor Hijacks Routers for SOCKS5 Proxies and DDoS Attacks
August 15, 2026 A new modular Linux botnet named Evooo1Bot is actively exploiting internet-facing gateway devices across multiple regions. Also, it turns compromised routers and IoT hardware into SOCKS5 proxy relays for concealed malicious traffic. What…
SAP Commerce Cloud Unauthenticated RCE Under Active Exploitation Days After Patch
August 15, 2026 Threat actors are actively exploiting a maximum-severity vulnerability in SAP Commerce Cloud that allows unauthenticated remote code execution. Tracked as CVE-2026-58231, this critical flaw carries a CVSS score of 10.0 and was patched on…
Plug and Pwn Attack: Fake USB Devices Hijack Windows Plug and Play for SYSTEM Privileges
August 13, 2026 Researchers have unveiled Plug and Pwn, a new class of attacks that abuses Windows Plug and Play to install vulnerable vendor software and gain SYSTEM privileges with little or no user interaction. First demonstrated at DEF CON 34, the…