A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks. The flaw has a CVSS severity score …
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader. The campaign relies on a familiar social-engineering trick: an attacker poses as an …
Microsoft August 2026 Windows Updates Trigger Issues on Devices Using RGB Lighting Features
Microsoft is investigating a Windows 11 issue in which the August 2026 security updates can cause certain games to freeze, crash, display access-violation errors, or restart affected PCs. The problem …
AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs
AmnesiaStealer is a newly identified macOS information stealer that does more than copy saved passwords. It can give criminals quiet control of a browser that is already signed in, turning …
Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto
Mac users are being lured into a ClickFix campaign that turns a routine CAPTCHA check into a path for password theft, remote control, and cryptocurrency mining. It persuades a visitor …
Hugging Face Reportedly Explores $13 Billion Sale Following Recent AI Security Incident
Hugging Face is testing a sale that could value the open-source AI hub at $13 billion or more, even as it is still closing out July’s autonomous-agent intrusion. People familiar …
Anthropic’s Claude AI Suffers Another Outage With Elevated Errors
Anthropic’s Claude AI platform experienced another wave of elevated errors on August 24, 2026, marking yet another disruption in what has become a troubling pattern of instability for one of …
Hackers Infect Android Car Screens Through Their Built-In Software Update System
A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target. Rather than tricking drivers into installing a suspicious app, attackers used the software update path …
AWS Network Firewall Now Shows Which Security Rules Are Actually Being Triggered
AWS has introduced rule hit count support for AWS Network Firewall, giving security teams direct visibility into which stateful firewall rules are matching live network traffic. The new capability is …
Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks
Malicious npm packages are being used to place a Linux backdoor inside calendar and streak-calculation tools. The packages deliver legitimate date functions, making the malicious code easy to miss. The …
