August 11, 2026 Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service, Hijack Storage, and Leak Credentials Ivanti has issued a security advisory for Ivanti Endpoint Manager (EPM), disclosing …
Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory
August 11, 2026 SAP’s August 2026 Security Patch Day has delivered a substantial round of fixes, addressing 28 new security notes and one GitHub security advisory, alongside two updates to …
Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal
August 11, 2026 Claroty Team82 has uncovered 23 vulnerabilities in Copeland’s XWEB Pro supervisory controllers, widely used to manage commercial refrigeration in supermarkets, warehouses, and hospitals. Of these, 21 are …
Mozilla Revokes Firefox and Thunderbird Signing Key After Unencrypted Subkey Was Committed to GitHub
August 11, 2026 Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was accidentally committed to …
Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks
August 11, 2026 Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITYSYSTEM. The technique, published by researchers Alejandro Hernando …
Alert Fatigue Is Hitting US SOCs Hard: How to Cut Through the Noise
US SOC teams are dealing with a growing volume of alerts, while analyst time and security budgets remain limited. Too much of that time is spent checking signals that turn out to …
Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack
August 11, 2026 Poland’s energy sector attack has revealed how one compromised remote-access device can become the first step in a wider industrial intrusion. The campaign moved from a wind-farm …
New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines
August 11, 2026 A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings, stealing credentials, and creating persistent backdoors. The research was …
Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment
August 11, 2026 Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment Proactive AI-native security vendor Horizon3 has announced a major $20 million investment into its global partner ecosystem. The …
Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware
August 11, 2026 Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote access malware. The campaign turns interest in DeepSeek …
