August 5, 2026 Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers. Rather …
15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution
August 5, 2026 A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be presented at Black Hat …
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections. Each …
Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes
August 5, 2026 The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python web framework. Developers and administrators …
New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access
August 5, 2026 A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root on a wide range of popular …
Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain
August 5, 2026 EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold can become a …
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026 Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to …
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation
August 5, 2026 Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools …
Multiple Veeam ONE Vulnerabilities Allows Code Execution Attacks
August 5, 2026 Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files, steal database data, and …
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands
A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and troubleshooting tools, where a poorly handled hostname …
