August 4, 2026 A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an unprivileged local user to perform …
Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage
August 4, 2026 A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat. Players seeking an “undetected” Xeno script executor are being lured through …
Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites
August 4, 2026 A Russian-speaking hacker has been linked to a broad operation that breached organizations worldwide, collected credentials, and prepared access for sale to ransomware groups. The activity affected …
Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack
Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access …
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks
August 4, 2026 A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote …
Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution
August 4, 2026 Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as …
A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline
August 4, 2026 A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a …
Chinese Military Researchers Use AI Distillation to Train Drone and Battlefield Systems
Chinese military-linked researchers are studying ways to turn the outputs of advanced Western AI systems into smaller, cheaper models for drones, battlefield tools, cyber work, and public-security platforms. The concern …
Fake AI Tool Campaign Turns Developer Interest Into Enterprise Initial Access
August 4, 2026 A new malware campaign is turning interest in artificial intelligence tools into a route for enterprise intrusion. Attackers are cloning trusted GitHub projects, then hiding malicious files …
BINDCLOAK Steals Windows User and Process Tokens to Run Malware With Higher Privileges
August 4, 2026 A newly uncovered Windows backdoor is giving an East Asia-linked espionage operation a quiet way to deepen control inside targeted networks. Named BINDCLOAK, the modular implant is …
