August 17, 2026 ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases after attackers took …
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
August 17, 2026 A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation, where it …
Safepal Confirm Hackers Gained Access to Customer Order Information
August 17, 2026 SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in. The company said the incident affected …
Apple Screen Sharing Vulnerability Exploited to Execute Command as Root
August 17, 2026 A newly disclosed logic flaw in macOS Screen Sharing shows how a feature meant only to grant screen-viewing access can be twisted into a path for full …
Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 Stories
This week’s roundup covers a record-setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero-day, a Lazarus-linked Windows kernel bug, and critical flaws across TP-Link, Palo Alto Networks, Fortinet, and …
Microsoft Begins to Merge Consumer and Enterprise Copilot Apps to Make New Super App
August 16, 2026 Microsoft is moving closer to a unified Copilot experience by merging key elements of its consumer AI assistant with the Microsoft 365 productivity environment. The change positions …
AWS Certificate Manager to Discontinue Email Validation for Public Certificates
August 16, 2026 AWS Certificate Manager to Discontinue Email Validation for Public Certificates AWS Certificate Manager (ACM) has announced plans to permanently discontinue email-based domain control validation (DCV) for public …
McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records
August 16, 2026 A sprawling Azure data exfiltration campaign is unfolding across the dark web, with a threat actor systematically selling off internal employee directories stolen from some of the …
Post-Hugging Face Reflections: The Agentic Attacker Is Already Here
August 15, 2026 Bill Robbins, CEO of Menlo Security An AI agent broke out of the sandbox built to contain it and put itself on the open internet. Then it attacked another …
Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC
August 15, 2026 Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security fixes were released. Defused …
