ShieldBreak CVE Microsoft Defender Zero-Day
August 18, 2026 Microsoft confirmed it is actively working on a security patch for CVE-2026-69414, a zero-day vulnerability in Microsoft Defender publicly known as ShieldBreak. The flaw allows local attackers with limited permissions to escalate to…
Threema DDoS Attack Disrupts Secure Messaging Service
August 16, 2026 Large-scale distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service on August 12, 2026. Consequently, users experienced severe communication disruptions for several hours. Threema is a Swiss end-to-end…
Gunra Ransomware: CISA and FBI Warn of Conti-Derived RaaS Targeting Global Critical Infrastructure
August 11, 2026 CISA, the FBI, the NSA, and South Korea’s National Police Agency have issued a joint advisory warning that the Gunra ransomware gang is actively targeting government agencies, critical infrastructure, and healthcare organizations…
North Carolina Ports Cyberattack Disrupts Three Major Maritime Facilities
August 8, 2026 The North Carolina Ports Authority confirmed a cyberattack that forced a systems-wide outage across three major port facilities. The incident disrupted operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte…
Metabase SQLi Zero-Day Flaw Grants Attackers Admin Access and Steals Database Credentials
August 7, 2026 A critical SQL injection vulnerability in Metabase is under active zero-day exploitation, allowing unauthenticated attackers to seize administrator control of instances and steal connected database credentials. The flaw has already…
Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
July 28, 2026 More than 24,000 internet-exposed servers are leaking authentication password hashes through a 20-year-old vulnerability in their Baseboard Management Controller interfaces. Researchers at cybersecurity firm Lava discovered that…
Zimbra CVE: Russian Spies Exploit Zero-Click XSS
July 23, 2026 A Russian state-sponsored advanced persistent threat group known as Laundry Bear (also called Void Blizzard) has been silently reading Western mailboxes by exploiting a stored cross-site scripting vulnerability in Zimbra Collaboration…
South Korea Diplomat Data Breach
July 22, 2026 South Korea disclosed a major data breach on July 22, 2026, that exposed the personal information of current and former Ministry of Foreign Affairs employees. Hackers maintained access to the National Diplomatic Academy’s online…
Nihon Kotsu Cyberattack Shuts Down Japan Largest Taxi Fleet
July 14, 2026 Japan’s largest taxi operator, Nihon Kotsu, suffered a damaging cyberattack on July 12, 2026, forcing the company to shut down critical systems and suspend dispatch services across multiple cities. The incident highlights the growing…
Ghostcommit Prompt Injection Attack Steals Secrets via AI Code Review Blind Spot
July 11, 2026 Researchers from the University of Missouri Kansas City’s ASSET Research Group have disclosed a new supply-chain attack called Ghostcommit. This technique hides malicious prompt-injection instructions inside a PNG image embedded in an…