August 3, 2026 Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud Orchestrator (VCO) deployments. This vulnerability, tracked as …
Android RAT Survives Reboots Using Watchdog Services and Boot Receivers
August 3, 2026 Android users are facing a new remote-access threat that hides behind a fake emergency alert application. The malware, called Octagon, poses as Bahrain’s BH Alert service and …
ModernStealer Threat Actor Linked to Government and Defense Data-Leak Claims
ModernStealer is the name behind underground posts claiming to offer military, government, nuclear, and aerospace material. The posts appeared on dark web forums and Telegram, making a single alias a …
Internet-Facing SonicWall SMA Appliances Face Zero-Click Root Compromise
Internet-facing SonicWall Secure Mobile Access, or SMA, appliances face a serious threat after attackers turned two flaws into a route to full VPN-gateway control. The campaign gives an outsider a …
XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands
XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once …
MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets
August 3, 2026 Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on …
Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console
August 3, 2026 N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated attackers to gain full administrative, or “god-mode,” …
Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft
August 3, 2026 A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing …
SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform
August 2, 2026 CALIFORNIA, USA, August 2nd, 2026, CyberNewswire AccuKnox, a leading Zero Trust Security platform, today announced that SabPaisa, an RBI-authorised digital payments company, has selected its AI-powered cloud …
Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 Stories
AI systems moved from experimental risk to confirmed attacker, a Cisco firewall zero-day was actively exploited in the wild, and a critical VMware authentication bypass put enterprise virtualization infrastructure at …
