Critical MLflow CVE Enables SSRF Cloud Credential Theft
August 20, 2026 CISA has added a critical MLflow vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw, tracked as CVE-2026-64849, is a DNS-rebinding server-side request forgery…
Operation CameraSwarm: Dahua Cameras Compromised
August 20, 2026 Threat intelligence firm Hunt.io has uncovered a massive 35-day campaign that compromised more than 14,500 Dahua IP cameras across Ukraine and Russia. The operation, dubbed Operation CameraSwarm, exploited credential attacks,…
CISA Confirms Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw
August 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a high-severity Windows Task Host privilege escalation vulnerability tracked as CVE-2025-60710. Consequently,…
SafePal Data Breach Crypto Wallet Customers Exposed
August 17, 2026 Cryptocurrency hardware wallet provider SafePal disclosed a data breach that exposed customer order information for approximately 39,798 users. The incident involves an authorization flaw in the company’s order-tracking system, and…
SAP Commerce Cloud Unauthenticated RCE Under Active Exploitation Days After Patch
August 15, 2026 Threat actors are actively exploiting a maximum-severity vulnerability in SAP Commerce Cloud that allows unauthenticated remote code execution. Tracked as CVE-2026-58231, this critical flaw carries a CVSS score of 10.0 and was patched on…
macOS Screen Sharing CVE: Active Exploitation Confirmed for Root Access and Crypto Mining
August 14, 2026 The Netherlands’ National Cyber Security Centre (NCSC) has confirmed active exploitation of CVE-2026-65400, a macOS Screen Sharing authentication bypass vulnerability. Attackers with network access to TCP port 5900 can gain root…
Plug and Pwn Attack: Fake USB Devices Hijack Windows Plug and Play for SYSTEM Privileges
August 13, 2026 Researchers have unveiled Plug and Pwn, a new class of attacks that abuses Windows Plug and Play to install vulnerable vendor software and gain SYSTEM privileges with little or no user interaction. First demonstrated at DEF CON 34, the…
Critical Progress LoadMaster CVE Enables Unauthenticated Command Injection
August 11, 2026 CISA has added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities Catalog. Attackers are actively exploiting this flaw to execute arbitrary commands on unpatched…
Head Mare Hacktivists Trojanize TrueConf Installers to Deploy PhantomCore and PhantomGraph Backdoors
August 10, 2026 The Head Mare hacktivist group has been exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors. Researchers at Kaspersky discovered the campaign in…
SCTPhantom Linux Kernel Flaw: 18-Year-Old SCTP Bug Enables Root and Container Escape
August 9, 2026 Researchers at Tencent Zhuque Lab disclosed an 18-year-old Linux kernel vulnerability in the Stream Control Transmission Protocol (SCTP) that could allow a local attacker to gain root privileges and escape container boundaries. Tracked as…