21 Aug, 2026

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe […]

2 mins read

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider. Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver. Researchers at […]

2 mins read

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs […]

8 mins read

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. Microsoft addressed the flaw in this month’s Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July. Microsoft […]

3 mins read

FBI: Hackers target online accounts to steal nude photos

The FBI warns that cybercriminals are targeting adults’ and children’s social media and other online accounts to steal sexually explicit images or videos. As the law enforcement agency explained in a public service announcement published this week, the attackers may use the stolen content to blackmail the victims or try to sell it on criminal […]

3 mins read

Hackers leverage new Microsoft SharePoint exploit in attacks

A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks. Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. Microsoft patched […]

2 mins read

Signal adds new security feature to thwart man-in-the-middle attacks

Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven’t been intercepted. The new feature is part of a “key transparency” system that uses Cloudflare and Trail of Bits as trusted third-party independent auditors to verify the integrity of Signal conversations. “It works through a […]

2 mins read

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldBreak” after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. However, cybersecurity expert Kevin […]

2 mins read

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. In a new blog post, Google argues that notification abuse has increasingly been used to distribute scams, malware, phishing attempts, and fraudulent payment requests. To reduce the abuse, Google developed a “Swiss […]

2 mins read

DeadLock ransomware uses blockchain to resist infrastructure takedown

The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. The threat actor emerged in mid-2025 and uses double-extortion tactics (data theft/leak and file encryption) to pressure victims into paying a ransom. By July this year, DeadLock’s data leak site listed 80 organizations, mostly from […]

3 mins read