August 10, 2026 Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards …
Hackers Distributing Malicious VBS/PowerShell RAT Chain Via Multiple DuckDNS Hosts
August 10, 2026 A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic Script, …
Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval
August 10, 2026 RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian …
Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS
August 10, 2026 Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A new Elastic investigation found …
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
August 10, 2026 A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the …
Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
August 10, 2026 Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results provided in its system card. …
Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts
August 10, 2026 Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than 1.2GB of …
Claude-Powered OpenClaw AI Agent Exploits Gym API to Steal a Workout Slot
August 10, 2026 An Australian man’s AI assistant has become the center of what is being described as the country’s first known autonomous AI cyberattack, after it exploited a security …
Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories
This week’s roundup covers active exploitation of Apache Tomcat and SonicWall SMA, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able N-Central, Veeam ONE, Jenkins, and Cisco IOS XE, …
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
August 9, 2026 Metabase, the widely used open-source business intelligence and data visualization platform, has confirmed that a critical zero-day vulnerability tracked as GHSA-vwf4-m7j8-wcjf was actively exploited in the wild, …
