Octagon is an Android theft tool that turns an infected phone into a platform for account takeover. It can steal login details, watch the screen, and capture verification codes that …
Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS
August 18, 2026 Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary …
OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Security Vulnerabilities
August 18, 2026 OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Security Vulnerabilities OpenAI has warned that advancing artificial intelligence models are increasingly capable of automating critical phases of …
Why Threat Intelligence Feeds Often Fail to Meet SOC Expectations
Threat intelligence (TI) feeds are expected to close visibility gaps that inevitably emerge in enterprise SOCs and make investigations faster and more effective. This promise sounds particularly attractive to leaders of growing …
Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting
August 18, 2026 A cryptocurrency fraud operation has been found using AI coding tools to turn huge phone lists into a sharper victim-targeting system. The campaign combined account checks, phishing …
10 Best Dark Web Monitoring Tools in 2026
Dark web monitoring involves tracking activities on the hidden internet, accessible only via specialized software and configurations. This shadowy realm hosts illicit markets for stolen data, illegal drugs, weapons, hacking …
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
August 18, 2026 CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. The flaw can allow …
Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse
August 18, 2026 Shadow hVNC is a remote access tool built to operate where victims cannot see it. Instead of taking over the visible desktop, it can create a separate …
Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks
August 18, 2026 A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of …
VMware Syslog Path Traversal Becomes Root RCE, Persistent SSH Access and ESXi Ransomware
August 18, 2026 A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310, a critical path traversal bug …

