Three high-severity vulnerabilities in HP Easy Start for macOS could allow attackers to interfere with printer-software installation workflows and potentially gain elevated privileges. The flaws affect versions earlier than 2.16.7.260722, …
Hackers Use QR Codes With No Images to Bypass Email Security
Hackers are using QR codes without image files to slip past email defenses. The tactic turns email markup into a scannable code, routing recipients to a phishing page while depriving …
Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host
Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious …
New StreamRAT Android Trojan Gives Hackers Full Remote Control Through VNC and Accessibility
StreamRAT is a new Android banking trojan that gives criminals broad control of an infected phone. It pairs streaming offers with screen viewing, remote actions and deceptive login windows, turning …
Hackers Turn Trusted Node.js Runtime Into Malware Launcher in Ransomware-Linked Attacks
Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses, according to new findings from the Symantec Threat Hunter Team. Since February 2026, …
Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks
A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics. The flaw, tracked …
Microsoft Teams, Outlook Crashes Following August 2026 Updates on ARM-Based Devices
Microsoft has confirmed a known issue causing Microsoft Teams and the new Outlook for Windows to crash or fail to launch on ARM-based PCs after installing security updates released on …
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and recovery services before deploying ransomware in less than …
WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks
A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 …
Malicious Apache Modules Turn Trusted Government Websites Into Stealth Phishing Proxies
Brazilian government websites have been quietly turned into gateways for phishing pages on trusted public domains. Rather than sending victims to obvious scam sites, attackers are using compromised web servers …
