A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on any machine that loads it. The flaws bypass …
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition …
Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild
August 3, 2026 Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud Orchestrator (VCO) deployments. This vulnerability, tracked as …
Android RAT Survives Reboots Using Watchdog Services and Boot Receivers
August 3, 2026 Android users are facing a new remote-access threat that hides behind a fake emergency alert application. The malware, called Octagon, poses as Bahrain’s BH Alert service and …
ModernStealer Threat Actor Linked to Government and Defense Data-Leak Claims
ModernStealer is the name behind underground posts claiming to offer military, government, nuclear, and aerospace material. The posts appeared on dark web forums and Telegram, making a single alias a …
Internet-Facing SonicWall SMA Appliances Face Zero-Click Root Compromise
Internet-facing SonicWall Secure Mobile Access, or SMA, appliances face a serious threat after attackers turned two flaws into a route to full VPN-gateway control. The campaign gives an outsider a …
XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands
XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once …
MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets
August 3, 2026 Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on …
Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console
August 3, 2026 N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated attackers to gain full administrative, or “god-mode,” …
Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft
August 3, 2026 A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing …
