The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being exploited in ransomware attacks and have been added to its KEV catalog. …
Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
August 11, 2026 Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter fingerprinting activity. The activity includes requests to the /sdk/ endpoint using …
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
August 11, 2026 A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open remote viewing sessions, while its …
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition
August 11, 2026 Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions. The flaws affect the …
Anthropic to Add Invisible Watermarks to All Claude AI Outputs
August 11, 2026 Anthropic has announced plans to add invisible watermarks and signed metadata to content created by Claude AI. The move follows the company’s decision to sign the European …
New Phishing Attack Leverage SSL/TLS Certificates to Target High-value Brands Customers Via Whatsapp
August 11, 2026 A phishing operation is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is designed to make fraudulent pages …
OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming
August 11, 2026 OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue and Daybreak Red—alongside a new …
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
August 10, 2026 A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency …
HP ThinPro TPM Disk Encryption Flaw Lets Attackers Extract LUKS Keys
August 10, 2026 A security researcher has disclosed a boot-chain weakness in HP ThinPro 8 and 9 that could allow attackers with physical access to a thin client to extract …
Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
August 10, 2026 Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID Weaknesses That Can Bypass Phishing-Resistant MFA A new “Pass-the-Passkey” family of attack techniques demonstrates how systemic implementation flaws …
