August 10, 2026 CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI …
Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks
August 10, 2026 Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose accounts can open doors to contracts, payments, …
Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT
August 10, 2026 Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows how old delivery methods can gain …
Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE
August 10, 2026 Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards …
Hackers Distributing Malicious VBS/PowerShell RAT Chain Via Multiple DuckDNS Hosts
August 10, 2026 A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic Script, …
Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval
August 10, 2026 RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian …
Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS
August 10, 2026 Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A new Elastic investigation found …
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
August 10, 2026 A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the …
Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
August 10, 2026 Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results provided in its system card. …
Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts
August 10, 2026 Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than 1.2GB of …
