August 4, 2026 DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure. The campaign targets iPhones running iOS 18.4 through …
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
August 4, 2026 CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the flaw affects N-central servers running versions earlier …
Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges
August 4, 2026 A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an unprivileged local user to perform …
Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage
August 4, 2026 A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat. Players seeking an “undetected” Xeno script executor are being lured through …
Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites
August 4, 2026 A Russian-speaking hacker has been linked to a broad operation that breached organizations worldwide, collected credentials, and prepared access for sale to ransomware groups. The activity affected …
Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack
Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access …
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks
August 4, 2026 A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote …
Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution
August 4, 2026 Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as …
A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline
August 4, 2026 A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a …
Chinese Military Researchers Use AI Distillation to Train Drone and Battlefield Systems
Chinese military-linked researchers are studying ways to turn the outputs of advanced Western AI systems into smaller, cheaper models for drones, battlefield tools, cyber work, and public-security platforms. The concern …
