August 11, 2026 OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue and Daybreak Red—alongside a new …
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
August 10, 2026 A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency …
HP ThinPro TPM Disk Encryption Flaw Lets Attackers Extract LUKS Keys
August 10, 2026 A security researcher has disclosed a boot-chain weakness in HP ThinPro 8 and 9 that could allow attackers with physical access to a thin client to extract …
Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
August 10, 2026 Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID Weaknesses That Can Bypass Phishing-Resistant MFA A new “Pass-the-Passkey” family of attack techniques demonstrates how systemic implementation flaws …
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026 CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037, the flaw affects …
Windows WalletService Vulnerability Allows Attackers to Escalate Privileges – PoC Released
August 10, 2026 Microsoft has patched a Windows WalletService vulnerability that could let local attackers gain SYSTEM privileges, with a public proof of concept urging organizations to deploy the July …
GitHub Expands Supply Chain Malware Detection From npm to 8 Package Registries
August 10, 2026 GitHub has expanded its malware detection capabilities beyond npm, providing developers with broader protection against malicious open-source packages. Dependabot alerts can now identify harmful dependencies across 8 …
Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers
August 10, 2026 A malicious Chrome extension masquerading as GoogleTranslate that can steal sensitive browser data, live-stream web sessions, and allow threat actors to remotely interact with Chrome windows while …
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
August 10, 2026 Android users are facing a fresh reminder that a familiar app-store listing can hide a financial threat. Researchers have observed malicious loaders on Google Play that can …
Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption
August 10, 2026 Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and response tools, interrupt Windows telemetry, …
