Swiss government SharePoint breach compromised 200 accounts
Swiss Government SharePoint Breach Shows Why Patching Must Be Combined with Credential and Server RecoveryThe cyberattack affecting Microsoft SharePoint servers operated by Switzerland’s Federal Office of Information Te…
Aug 07, 2026
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
WebKit Proxy Bypasses Show How Browser Features Can Undermine IP PrivacyThe discovery of proxy bypasses in Apple’s WebKit browser engine demonstrates how privacy protections can fail when individual browser features do …
Aug 06, 2026
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Thousands of Internet-Exposed Rockwell PLCs Highlight Growing Risks to Water and Critical InfrastructureThe discovery of more than 4,400 Rockwell Automation programmable logic controllers directly accessible from the in…
Aug 06, 2026
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA Flags Actively Exploited TeamCity Vulnerability Threatening CI/CD PipelinesCISA’s decision to add CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog highlights the substantial security consequences of vu…
Aug 06, 2026
CISA Adds One Known Exploited Vulnerability to Catalog
Actively Exploited TeamCity Flaw Threatens Software Builds and CI/CD Supply ChainsCISA’s addition of CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog highlights the serious risk created when attackers gain …
Aug 06, 2026
COLDCARD security audit phishing attack installs remote access tool
Fake COLDCARD Security Audit Uses ScreenConnect to Gain Remote Access to Cryptocurrency UsersA phishing campaign impersonating COLDCARD demonstrates how quickly attackers can weaponise public concern surrounding a genui…
Aug 06, 2026
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
ClickFix Campaign Uses Browser Fingerprinting to Hide macOS Infostealer AttacksThe discovery of more than 250 domains supporting a macOS-focused ClickFix campaign demonstrates how attackers are improving the infrastruct…
Aug 06, 2026
Hackers run khunt post-exploitation toolkit from Oracle database
KHunt Attack Shows How SQL Injection Can Turn an Oracle Database into a Hidden Post-Exploitation PlatformThe discovery of the KHunt post-exploitation toolkit operating directly from inside an Oracle Database demonstrate…
Aug 06, 2026
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
CISA Warning Highlights Active Exploitation of Langflow, N-central and Apache Tomcat VulnerabilitiesCISA’s warning regarding actively exploited vulnerabilities in IBM Langflow, N-able N-central and Apache Tomcat demonst…
Aug 05, 2026
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
OVSwrap Linux Kernel Flaw Allows Local Users to Gain Root Through Open vSwitchA newly disclosed Linux kernel vulnerability known as OVSwrap demonstrates how a flaw in a specialised networking component can expose system…
Aug 05, 2026
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link Omada ZTP Vulnerabilities Show How Automated Network Provisioning Can Become an Attack PathThe discovery of 15 vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning ecosystem demonstrates how technol…
Aug 05, 2026
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
QuickFox Supply-Chain Attack Delivered FDMTP Backdoor Through Official Windows InstallerThe discovery of a long-running supply-chain compromise affecting QuickFox demonstrates how attackers can transform a trusted softw…
Aug 05, 2026