Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA). Managed detection and response (MDR) services company Huntress […]
Hackers breach govt webmail while running parallel crypto fraud
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. Although the threat actor has targeted government agencies and organizations in critical sectors, including defense, telecommunications, education, and aviation, its cryptocurrency-related activity suggests that they may also operate as a hack-for-hire group that seeks to profit from […]
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as “LegacyHive,” disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the “Nightmare Eclipse” handle in protest of Microsoft’s bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours […]
AI ‘watermark removers’ flood the web. Almost none can prove they work.
A market for removing AI watermarks has sprung up days after Anthropic disclosed switching on invisible marks in everything Claude writes, spanning a GitHub project with over 4,500 stars, a cluster of newly registered web tools, and at least one established AI detection evasion service. None of the claims about defeating the text watermark can […]
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran, and France. Broadcom disclosed CVE-2026-59310 […]
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. During the incident, the attackers gained access to customers’ order data, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained in a Thursday blog post, the […]
White House taps security firms for offensive hack-back operations
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. Signed on Wednesday, the national security presidential memorandum (NSPM) enables the NCC (part of the Homeland Security Task Force) […]
WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has begun rolling out a new optional “Scam Alert” feature, which uses a local machine learning model to warn users when scammers are targeting them. Scam Alert is now available as part of a limited beta rollout while the company tests this new warning system with researchers in its Bug Bounty community. “Today, we’re […]
“City-Forum” data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. The data-theft campaign, dubbed City-Forum by SaaS security firm Reco, has been traced to a single server that has targeted multiple organizations worldwide. These organizations include telecommunications companies, banks and financial services firms, […]
Android malware combo takes out loans and relays victims’ credit cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time. In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem […]