News
Short, source-based assessments of current security incidents.
Insight
Security is decided in the boardroom, not the server room
In most organisations, information security is still something handled by somebody else, somewhere further down the structure. Responsibili…
Operational security in the energy sector is national preparedness
In energy and other critical infrastructure, the cost of an outage is rarely measured in lost revenue alone. It is measured in what else st…
Under NIS2, the board's accountability is personal and documented
NIS2 places accountability for security where the decisions are made. The directive requires the management body to approve risk management…
Records are being pulled from Salesforce and ServiceNow portals that need no login
Reco is tracking an ongoing campaign it calls City-Forum, in which a single tool written in Go pulls records from customer portals in Salesforce Experience Cloud and ServiceNow. All the traffic comes from one server that has been standing since March 2025, and the targets include telecoms, banks, software vendors and public sector portals.
New exploit is said to grant SYSTEM through Microsoft Defender
On 12 August 2026 the researcher known as Nightmare Eclipse released exploit code called ShieldBreak, said to grant SYSTEM privileges through Microsoft Defender on fully patched machines. The researcher describes it as a full bypass of the RoguePlanet fix, and Will Dormann states that the code works when Defender is enabled.
A signed kernel driver now hides the CoolClient backdoor on Windows
Kaspersky has analysed a new version of the CoolClient backdoor that installs a signed driver in the Windows kernel. The driver hides the malware process, its files and its registry keys, and the activity is attributed to HoneyMyte, also known as Mustang Panda.
Contractor jailed for two years after trying to extort the company that hired him
A former contract data analyst has been sentenced to two years in prison for attempting to extort 2.5 million dollars in cryptocurrency from an international technology company. Prosecutors state that he sent more than 60 emails under the alias Loot after his contract was not renewed.
A fake donation app steals the logged in Telegram session
On 13 August 2026 Kaspersky described an espionage campaign it attributes to the Armored Likho group, in which an app posing as a donation service is in reality a dropper. The Still Toolkit steals Telegram session data and pulls out conversations, while a separate module listens for speech and records audio.
Citrix reports multiple vulnerabilities in NetScaler ADC and Gateway
Citrix has published a bulletin covering multiple NetScaler ADC and Gateway vulnerabilities, scored 6.9 to 8.8 in CVSSv4 and requiring no authentication.
Attackers picked up the SharePoint exploit code the day after it was published
On 11 August 2026 Rapid7 published a technical analysis of CVE-2026-55040 in Microsoft SharePoint, together with code showing how the flaw is exploited. Defused states on X that attackers were using that same code against its SharePoint honeypots the following day.
Meta says one of its models broke into another company during testing
Meta says one of its models unexpectedly gained internet access during a security evaluation, and that the model then exploited a vulnerability in a service outside the test environment. The test was run by Irregular, which also ran the evaluations for Anthropic, and the firm told the BBC that it is the same test environment fault Anthropic disclosed the week before.
New technique shows when a language model notices it is being tested
On 6 July 2026 Anthropic published research on what it calls the J-space, a small set of internal patterns that reveal which words a language model holds in mind without writing them down. The company says the method has caught a model noticing that it was being tested, producing fabricated data on purpose, and pursuing a hidden goal planted during training.
Only two of 421 vulnerabilities in the August release carry a flag
Microsoft's August security release consists of 421 CVEs. One is marked Exploitation Detected and one Publicly Known, and both are elevation of privilege flaws that require a local account.
Fake recruiters talked IT staff into installing a VPN client that ran hidden code
CERT-UA describes how the threat cluster UAC-0145 approaches IT professionals on job sites and runs a full hiring process, complete with a Telegram conversation and a genuine Zoom interview. The candidate is eventually asked to download a VPN client called SopraVPN, built from WireGuard source code and running PowerShell code hidden in the SymmetricKey configuration option.
A fake job offer ended with a rootkit in the Windows kernel
Check Point Research attributes a new wave of Operation Dream Job to Lazarus, where fake job offers in the defence and aviation industries ended in exploitation of the zero-day CVE-2026-68820 in the Windows AFD.sys driver. Microsoft fixed the flaw on 11 August 2026 after Check Point reported it, and the same investigation found command traffic running through hijacked Roundcube and WordPress servers.
Approved partners get access to a model that finds unknown vulnerabilities
OpenAI is expanding Daybreak with two access levels and releasing GPT-5.6-Cyber, a model trained for tasks such as finding zero-day vulnerabilities and developing exploit chains. The model is available through Daybreak Red, and access to the underlying models remains with the approved partner rather than the customer.
How an email with no script at all can steal your password
PortSwigger shows that style rules in an email can break out of the message and reach into the webmail interface. The attacks hit Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail, and need no script at all.
A flaw in Metabase gave administrator access without a sign-in
Metabase confirmed on 6 August that a vulnerability in version 58 and later is being exploited in attacks. An unauthenticated attacker can inject SQL into Metabase's own application database through the password reset endpoint, and from there gain administrator access.
How attackers reached a Polish power plant through a shared mobile network
CERT Polska published a follow-up report on 8 August covering the 29 December 2025 attacks on Poland's energy supply. It describes an attack on a heat and power plant serving around 50,000 residents, where the way in ran through the grid operator's private mobile network.
A hidden paragraph in the document makes the AI assistant send the data out
Two reports show that Atlassian's AI assistant Rovo can be tricked into sending out data it has access to. One technique starts in an uploaded document, the other in a single click on a link.
An eighteen-year-old Linux kernel flaw hands ordinary users root
Tencent Zhuque Lab has found a flaw in the SCTP part of the Linux kernel that has been there since 2008. An ordinary user can use it to gain root, and to escape a container.
The WordPress login screen let anyone inject code
WordPress released version 7.0.3 on 6 August, fixing a vulnerability on the login screen that requires no sign-in. The finders show how the flaw can, under certain conditions, end with PHP code running on the server.
Voicemail lures slip past MFA and hunt for payroll payouts
Arctic Wolf has uncovered a widespread phishing campaign against Microsoft 365 accounts in Europe, Canada and the US. The attackers take over the session after MFA is completed, hunting specifically for payroll, HR and finance.
Official installers for QuickFox VPN carried a backdoor for nearly a year
Fortinet has found that the QuickFox VPN installers spread a backdoor for nearly a year. The backdoor was only installed on machines that looked like work machines.
Europe takes more control of the vulnerability register, and NATO IT agency joins
ENISA announced on 6 August 2026 that the NATO Communications and Information Agency and the company AISLE have become CVE Numbering Authorities under the ENISA Root. According to ENISA there are now twenty such authorities under the European Root, eight of them transferred from the MITRE Root.
The industrial software shipped with a database that went out of date years ago
CISA published three new industrial control system advisories on 6 August 2026. The weightiest concerns ABB Ability Zenon, where the IIoT services install alongside MongoDB 4.2, and where twelve of the thirteen listed vulnerabilities date from 2020 and 2021.
The voice on the phone was not the boss, and the funds were all called the same day
Bloomberg reported on 5 August 2026 that several of Wall Street's largest funds faced attempted attacks using voice phishing, where AI-generated voices impersonate known people over the phone. Two Sigma states the attempt was stopped, Point72 states an initial review found no client data stolen, and no confirmed breaches have been reported.