US SOC teams are dealing with a growing volume of alerts, while analyst time and security budgets remain limited. Too much of that time is spent checking signals that turn out to …
Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack
August 11, 2026 Poland’s energy sector attack has revealed how one compromised remote-access device can become the first step in a wider industrial intrusion. The campaign moved from a wind-farm …
New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines
August 11, 2026 A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings, stealing credentials, and creating persistent backdoors. The research was …
Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment
August 11, 2026 Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment Proactive AI-native security vendor Horizon3 has announced a major $20 million investment into its global partner ecosystem. The …
Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware
August 11, 2026 Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote access malware. The campaign turns interest in DeepSeek …
DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
August 11, 2026 DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July 2025, it had listed more …
LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
August 11, 2026 A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident placed build …
CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being exploited in ransomware attacks and have been added to its KEV catalog. …
Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
August 11, 2026 Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter fingerprinting activity. The activity includes requests to the /sdk/ endpoint using …
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
August 11, 2026 A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open remote viewing sessions, while its …
