CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands …
Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots
Microsoft is rolling out a fresh line of defense against unwanted digital eavesdroppers in virtual meetings. The tech giant confirmed that Microsoft Teams will soon let administrators automatically block identified …
Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages
Bank customers searching for a login page can now be led into a trap before they receive a suspicious email or text message. Criminals are manipulating Google and Bing results …
New Mysterious AI Model Dubbed Ox Alpha With Free 100 Trillion Tokens a Day for Coders
A mysterious AI system named Ox Alpha has sparked intense speculation across the developer community after appearing on OpenRouter as a free “stealth model” aimed at coding, long-running AI agents, …
Hackers Impersonate ReliaQuest Security Staff to Steal SSO Credentials and MFA Access
ReliaQuest has disclosed a social engineering attack in which threat actors impersonated members of its security team to lure employees to a fraudulent single sign-on page. The incident briefly exposed …
768 Leaked Corporate AWS Keys Remain Active With Full Administrator Access
A new cloud security investigation from Truffle Security has found that 768 publicly exposed AWS credentials still provide full administrative control over corporate AWS environments. The findings highlight a persistent …
Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data
Kimsuky has been linked to a new espionage campaign that turns a Chrome extension into a quiet Gmail collector. The operation begins with convincing phishing emails and ends with attackers …
WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks
A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks. The flaw has a CVSS severity score …
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader. The campaign relies on a familiar social-engineering trick: an attacker poses as an …
Microsoft August 2026 Windows Updates Trigger Issues on Devices Using RGB Lighting Features
Microsoft is investigating a Windows 11 issue in which the August 2026 security updates can cause certain games to freeze, crash, display access-violation errors, or restart affected PCs. The problem …
