Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja MartĂnez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs […]
Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. Microsoft addressed the flaw in this month’s Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July. Microsoft […]
FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults’ and children’s social media and other online accounts to steal sexually explicit images or videos. As the law enforcement agency explained in a public service announcement published this week, the attackers may use the stolen content to blackmail the victims or try to sell it on criminal […]
Hackers leverage new Microsoft SharePoint exploit in attacks
A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks. Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. Microsoft patched […]
Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven’t been intercepted. The new feature is part of a “key transparency” system that uses Cloudflare and Trail of Bits as trusted third-party independent auditors to verify the integrity of Signal conversations. “It works through a […]
New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldBreak” after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. However, cybersecurity expert Kevin […]
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. In a new blog post, Google argues that notification abuse has increasingly been used to distribute scams, malware, phishing attempts, and fraudulent payment requests. To reduce the abuse, Google developed a “Swiss […]
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. The threat actor emerged in mid-2025 and uses double-extortion tactics (data theft/leak and file encryption) to pressure victims into paying a ransom. By July this year, DeadLock’s data leak site listed 80 organizations, mostly from […]
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of Sandworm (APT44). In the campaign, […]
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense […]