GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function. The issue can allow attackers to manipulate database queries via …
Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity
Z.ai has released GLM-5.3, a new AI model built to handle complex coding, long-running agent tasks, and cybersecurity analysis. The company says the model uses the same base model as …
New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks
August 17, 2026 A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content. Trellix …
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
August 17, 2026 Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to install malware …
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
August 17, 2026 A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that reaches internet-facing edge …
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
August 17, 2026 ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases after attackers took …
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
August 17, 2026 A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation, where it …
Safepal Confirm Hackers Gained Access to Customer Order Information
August 17, 2026 SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in. The company said the incident affected …
Apple Screen Sharing Vulnerability Exploited to Execute Command as Root
August 17, 2026 A newly disclosed logic flaw in macOS Screen Sharing shows how a feature meant only to grant screen-viewing access can be twisted into a path for full …
Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 Stories
This week’s roundup covers a record-setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero-day, a Lazarus-linked Windows kernel bug, and critical flaws across TP-Link, Palo Alto Networks, Fortinet, and …
