<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:gd="http://schemas.google.com/g/2005" xmlns:georss="http://www.georss.org/georss" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:thr="http://purl.org/syndication/thread/1.0"><id>tag:blogger.com,1999:blog-4802841478634147276</id><updated>2026-08-23T22:11:20.456+05:30</updated><title type="text">The Hacker News</title><subtitle type="html">The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackers</subtitle><link href="https://thehackernews.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml"/><link href="https://thehackernews.com/feeds/posts/default?redirect=false" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/" rel="alternate" type="text/html"/><link href="http://pubsubhubbub.appspot.com/" rel="hub"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default?start-index=26&amp;max-results=25&amp;redirect=false" rel="next" type="application/atom+xml"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><generator uri="http://www.blogger.com" version="7.00">Blogger</generator><openSearch:totalResults>17090</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-9046270093170292996</id><published>2026-08-22T20:02:41.442+05:30</published><updated>2026-08-22T20:02:41.442+05:30</updated><title type="text">TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit</title><summary type="html">
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.

As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9046270093170292996" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9046270093170292996" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html" rel="alternate" title="TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuigeGBdB6K4zmYLAIVAQ2NR4LskJUGGLo94UiAtL1d89WIdT3ekZUY58J7Em-QxANVODEDSuLoEwVlBKiwEQCBss89hDYzpOuUWcAd8bUphqatYsgIA801ytGpe6c9Pr66CZicJqHx81XREePakS0n3RhYGdD_awrTW5UNGjUdSEmwcKo0K5UOrOIdyGo/s260-e100/tiktok.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-9106512871147062705</id><published>2026-08-22T00:23:00.784+05:30</published><updated>2026-08-22T00:23:00.784+05:30</updated><title type="text">14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2</title><summary type="html">
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.

"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9106512871147062705" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9106512871147062705" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html" rel="alternate" title="14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvZpEOpS6_M3zQlIDwvD1wMhESnRAMTCz1nW2JFP__pGSVWOw28REaDTZ5lI7sdwvcRKSSUHI4sm1CUuWs6_gvOXE1c5BbvKnR75iyBl9Er1SckweDAxBEotnOlSikBeOE5WEBIIGlS74w4b85pvznpr3c4mj88LzLt-3pGr1HHXHQDg5v7T9FxdBSWSlK/s260-e100/linux-npm.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1080698021728142767</id><published>2026-08-21T21:22:10.843+05:30</published><updated>2026-08-21T21:22:10.844+05:30</updated><title type="text">Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot</title><summary type="html">
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.

The driver, BTR.sys (Boot Time Removal Tool), is a </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1080698021728142767" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1080698021728142767" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html" rel="alternate" title="Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCbsmb6Wk8pQKWQmByAl5wnZQEVjS7ZYiHrlsHRM7VlcoPL7s30TaoTReoaQ4LI8Oy3KfKlIRHn9sN_7bjEKd_FWPHi1V0JR6LERepKBWSdJOk6cSUNgfIN2KVc6ydfbTILTy11owREYfpO7K11gFQV00l6qf1zl5rzF28jPhcN744yTvRAA-EjyDSBXs/s260-e100/windows.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1706691025838017717</id><published>2026-08-21T21:11:44.580+05:30</published><updated>2026-08-21T21:14:30.130+05:30</updated><title type="text">Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet</title><summary type="html">
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.

Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.

"The malware spread through the built-in updaters of </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1706691025838017717" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1706691025838017717" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/android-car-malware-spreads-through.html" rel="alternate" title="Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1EQE-DqLXTzpjwGf3nQnM4CTnjibkKl_2ersn8abw3Gmqoc5MUaFC2LvkA7c6Xoa0XBPZeHL4wHHiXU7Pc9nGLcI1zTorwFTwvYXfww4Q68oSUrgcQhmBzQBNqYp-woIZFK_I1OOsnBNptiwA90VHhpE_hvlz3qdFomOmOMLreYe5YCenvR2CeawvRrMU/s260-e100/car.png" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-798004233934494608</id><published>2026-08-21T16:51:39.213+05:30</published><updated>2026-08-21T16:51:39.213+05:30</updated><title type="text">Wazuh and AI For Enhanced SOC Workflows</title><summary type="html">
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/798004233934494608" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/798004233934494608" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html" rel="alternate" title="Wazuh and AI For Enhanced SOC Workflows" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSZWG6Sgh8GPFwyz6pxs_gis36Lo0bAHyFSaNrybGElVQbCBkjPrypJ_abTOidSIKSaVJs574hUuDYvUPGymaq3qfnecNfbc-RMnwTuH8vr4jLcsnQCLnxjscJMSLEfITdwIvVt4Ax_wzwKe3MpD5Bm9vIW_f94MESP1p1qNpoxrkkDstHJ1lL7eljzB4/s260-e100/WAZUH.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1901192983867487220</id><published>2026-08-21T15:33:11.724+05:30</published><updated>2026-08-21T15:33:11.724+05:30</updated><title type="text">Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0</title><summary type="html">
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -


  </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1901192983867487220" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1901192983867487220" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html" rel="alternate" title="Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEis5Ujhq79PHPVr7VjuOjS0fOAyYm0aDTCJi9c5ieu-uya3FUM4Dh58yAT5U5J3VaXaGfNb4XowkyJ1lj3UTy8bOoF-u0O-5qdl-O7leomQjQw5jAI3m8WpZvC3se70f8mRP_KKIcScS0Nf9wJcsq4TWgiS_li3K6CSUbbG643IMhZBVGzW5XflwAbz0d1M/s260-e100/cisco.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5034838800185445602</id><published>2026-08-21T12:34:25.738+05:30</published><updated>2026-08-21T12:34:25.739+05:30</updated><title type="text">GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure</title><summary type="html">
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.

The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5034838800185445602" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5034838800185445602" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html" rel="alternate" title="GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8jpyIqzuMd0vBKcxrQRj7eBbEebcRgNHLRFpx7YuxJlTPksUDEar7HPu4unQPNaOzpChBl1-dYyPHwuyjhgetrrh6PZ9OHPRqnc6nXeNdaX9f8AcSDe6gpmRecFfryf3-3BgsNoxvOyNc6xz703Qzsd7hJLuKbQt4Q6bgVxRZDGdpFzy8O2SByvUouC3J/s260-e100/gitlab-cve.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5981637457497793334</id><published>2026-08-21T11:36:11.050+05:30</published><updated>2026-08-22T01:26:26.126+05:30</updated><title type="text">Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution</title><summary type="html">

Update: The story was updated after publication to note that the vulnerability has not been exploited.

Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5981637457497793334" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5981637457497793334" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html" rel="alternate" title="Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEid22xatm4tPGWO1VA9heA8p7i0iK4au3br36QORRasXlUO2uY5836xkZe6gywLOId9oHICopC6jZ8J-di4JI9O3CPOSOGsqoOR4Ps4DrEbKCXSXwMxX_wOGo0fY3zaTW4By4nzbY6jldD58kLAlBYfFxMOEeZOglaQu8R0TtT23Q2jLbQjHwJSoS21pqu5/s260-e100/entraid.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1221033276012390576</id><published>2026-08-21T01:52:35.781+05:30</published><updated>2026-08-21T01:53:57.411+05:30</updated><title type="text">Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads</title><summary type="html">


The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1221033276012390576" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1221033276012390576" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html" rel="alternate" title="Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgshVe5DUMbByJkLQGRgak37eOf3HddCtrF6KCJfISPdm7l2ZwLFlnjQM3pN2mxPDpc9lWwSoH2fYfucYKBKk3vpuGAKdR5U685IZh8EFbMxWcyVenuRMyqIgvbFUa0_5Sx9pVl9Imu5omju6i7eRE0sKKxiCSKYEV1Say1LLhQHEufY10dgovzX0Nt7as/s260-e100/rust.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4065073648678412420</id><published>2026-08-21T01:29:19.146+05:30</published><updated>2026-08-21T20:24:29.459+05:30</updated><title type="text">Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts</title><summary type="html">
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.

These clusters include UNC6293, UNC7005, and UNC5976.

"These clusters engage in persistent, adaptive </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4065073648678412420" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4065073648678412420" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html" rel="alternate" title="Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEix5lAWOEf4I8fcz0CJYg-EBclOrTPnlbsf6tKT2-L8xsfQ4XqtjOq15iU6EBbIsWlqQq3e1-hIXrPe7MMg4JwSGj6mSwjSwG8V3UFMrfgYD-Lo9bKvncTGJ9lPbZoxq-1RNmKLyL_jZSiurWVgGuIxjgYYJeXW_wE51PRTDUhT7kRxp0MMpc3YflI9bntb/s260-e100/google-whatsapp.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4643517499416210622</id><published>2026-08-20T22:53:48.678+05:30</published><updated>2026-08-21T11:09:14.347+05:30</updated><title type="text">ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More</title><summary type="html">
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.

Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage.

Nothing here needs </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4643517499416210622" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4643517499416210622" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html" rel="alternate" title="ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrmpCA-Pjqqy5BQaFvVtYqPZocJNkI4XUD8bcD9KrGaBcLyKd3J-aWVUtB8HwTiVqrFSI8U5wtTPhtjowrBWukeoUwSM5Y0-YKY535m1iDdQCXLYbSlx-qS-2TzZUpWVghvC3b9qWHxPoY4b-d3uUn3E4jeeW6iPt6Klxte-iNHfbq7K4aUpKH-EfhZV69/s260-e100/threatsday-main.png" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1257008071567637531</id><published>2026-08-20T22:29:44.952+05:30</published><updated>2026-08-21T11:09:51.545+05:30</updated><title type="text">AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure</title><summary type="html">

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.

The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1257008071567637531" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1257008071567637531" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html" rel="alternate" title="AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSn562AFIpj2ldmT5inFv5tGgfNbaM4F1OBNvCW-80nP-YmFewnJd9VMlbgYnhgWrUpHS81bS6uEXRgEmg37c14OqmkO29XqY3FcBCl637vmAxfqB3UDtL3Rvgio6cPAQQv3bYtLUIyRdog4bpgD8MqJJYhTLish4L2Ljt6aJ_WpjFmTXYhmrA-TguqH98/s260-e100/plc.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6943051255897942819</id><published>2026-08-20T20:06:27.502+05:30</published><updated>2026-08-20T20:44:15.985+05:30</updated><title type="text">New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data</title><summary type="html">
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page.

The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6943051255897942819" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6943051255897942819" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/new-cryptographic-context-injection.html" rel="alternate" title="New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPv76ODDXuPeov3fu_Gs_V-72pKnjw38Qu9A4qXOn_2QFd9daTYFAXre2eubEQ6Fwb65SwXgv10mhyDCGE_KcvL69c-CGe2BfEiOj74UTHwv6WAhMyxNuVGOEdUZYwz0Y9v55SFmaOwjHQYHbOyzvZEofi0egkTfeFxQlJRD3Sj6ve-TZ47SM1sNfYGB0/s260-e100/grok-chat.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6416389565176784276</id><published>2026-08-20T19:18:24.200+05:30</published><updated>2026-08-20T19:18:24.201+05:30</updated><title type="text">Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE</title><summary type="html">
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.

The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0. </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6416389565176784276" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6416389565176784276" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html" rel="alternate" title="Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJ3-aEfGwe03ZMojsoiYaQ4TNjUiAPEFK-m68uY5JSlF8knbnGWOcBrqiB_4s6J47lPjyhQEuWdUMHnktRU6YfOcltn7_lXga77C8TNH4GOVAPrmIH_T0MsFKFkmQSMnvf42bnLlH0pC4BVMEpAZJLLTH51GpgfZybiZ_UWNLhKxx1oGi8PyD3bOUGG0_F/s260-e100/nodejs.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1676516301717763085</id><published>2026-08-20T19:05:13.079+05:30</published><updated>2026-08-20T19:05:13.080+05:30</updated><title type="text">Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers</title><summary type="html">


Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.

According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1676516301717763085" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1676516301717763085" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html" rel="alternate" title="Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoCXrYMA_j7aJrrdIZKt2gQwTWYXhhHZTfBvrNcgpLLBTa5hzcmDNguBKwBhiD8p7kO5K2OeQYVbIPg2HHDBwu9LNzR6oAFE-znmFWIgjY_XzA0qdy-rA8XzV_uGvsxLWRNXCyyOlUKdDV0LGrXPN15wxYsTuZslyecGQ1cqE2OKdX5cocpp74uXenwdj0/s260-e100/citrix.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7752707518383896157</id><published>2026-08-20T18:54:28.708+05:30</published><updated>2026-08-22T12:57:29.547+05:30</updated><title type="text">Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution</title><summary type="html">
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).

The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.

"A remote code execution vulnerability exists in Zimbra </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7752707518383896157" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7752707518383896157" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html" rel="alternate" title="Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5vbtHH6C3JbT58Yghw2KNalqy-xoKLuJlsV9AGd_j2mQj4NKzVgWiOc9CDvUsT2JY0AchCk5140WhvNgZdKY2fwmeGEEi9FMvSSJvrBYVWndOKV9R47OEMZ59OOjv56DkPgpKo55fvHT7JSRW4yvh9_Xp5KBbw9xyJg2EGStHzg8ctloKfsJJPDLss1xR/s260-e100/zimbra.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4225341716644192986</id><published>2026-08-20T17:31:24.497+05:30</published><updated>2026-08-21T00:00:00.554+05:30</updated><title type="text">Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments</title><summary type="html">
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography.

The attack, which the researchers named "Zombie Card," requires physical </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4225341716644192986" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4225341716644192986" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html" rel="alternate" title="Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsJMUJluWegBU4C6RiZ4QHg6rTqhFHMt5JJt3RR2K7l06c3FOFlnq8gIVuBqVUX8qsJFiAh6KKAlDXpVAydAoC2rM0dUKUayta50sqRXoW36_V2OgSXJBKaaAFY4boBYhtHkqeyBaBZavbo7bz3S8otNwyb3NUmW9j88edph6zAfnyJikYhLBrAHuCdBA/s260-e100/visa.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8544701287347986557</id><published>2026-08-20T17:15:00.000+05:30</published><updated>2026-08-22T14:03:06.417+05:30</updated><title type="text">Why "Shady AI" is Security's Next Big Governance Problem</title><summary type="html">
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.&amp;nbsp;

The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8544701287347986557" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8544701287347986557" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html" rel="alternate" title="Why &quot;Shady AI&quot; is Security's Next Big Governance Problem" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw0UN7paSPEt1BbP-tObzJmXd5LHvNrZpta_hHK2pwYGVsYyZt2FQO20Ld8uePEO35Hg9MUqHRoA3tvbxXf9Wdh2D8IgHIt9M56YTvveuPUILhMZ_drcaBL6ILCPzZmAwryt6cqjNvh4A0NUIPIBS6tpJCHJz6R5Lu42t06EyJ56wnlATWOg5UC-5JlBA/s260-e100/tines.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3480975684679821465</id><published>2026-08-20T17:09:35.922+05:30</published><updated>2026-08-20T17:09:35.922+05:30</updated><title type="text">CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification</title><summary type="html">
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server.

The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu, </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3480975684679821465" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3480975684679821465" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html" rel="alternate" title="CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDFisNx669R67D6R9VnkWr_DIhB1VjYqDPrXqKAoeCz0YxbSngLxB15XYLtuKb00YSEE0rxQEfop5v7JIr2SMVOErIM2r_GZqA6q1FDNl_wBeAaukVoAse6l0kXv35dJRTQjT8R0DhS9ihwYUXNd9cFuqYM3GS0o28NyIBAgliuQR8XhKQqhixFcjdZpo/s260-e100/cdn-boost.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-217477310170513585</id><published>2026-08-20T16:56:08.173+05:30</published><updated>2026-08-21T22:40:26.141+05:30</updated><title type="text">Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices</title><summary type="html">
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.

"Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/217477310170513585" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/217477310170513585" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html" rel="alternate" title="Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNJ75E0bEnkBf9REZEnmMNusCu2L2mrut4dSX8g-VVXH2THKdkXD1GwCZ_O5ZsnGzdamG2t0TVnelMj1TKMghauv4cIndc3OA7kuHQAdxf7FbngV7BaWV_-qmhvLZRNwN_5tkv5dSHViEwDgZ4Mou0TNLrFlyQ2yzyb7GYNQ6PPNVjCoJ7VzeKmly4Ntsf/s260-e100/Manic.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1596334674641462452</id><published>2026-08-20T16:35:11.712+05:30</published><updated>2026-08-20T22:50:23.965+05:30</updated><title type="text">NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands</title><summary type="html">
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus.

The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1596334674641462452" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1596334674641462452" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html" rel="alternate" title="NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0aHi13XpphD98KUUKTJJB0T5eJW8TLe8qecYWanC8lqujxWOn4dtJUXThwqpfnrd9daSkiLMxXb7r6EFFbYY2fy3qSZteMtPB5Sl5t4K01MKoHywiyohPzUQX17h3oj126zywGtTEP8twGQnbs0wjaecaY8nLhAWXLw0anuJuL2iSJmKBVnzlZhy842E/s260-e100/nasa.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7069604996829637195</id><published>2026-08-20T16:08:28.041+05:30</published><updated>2026-08-20T16:56:55.201+05:30</updated><title type="text">ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud</title><summary type="html">
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally.

Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7069604996829637195" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7069604996829637195" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html" rel="alternate" title="ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq19iWDNnvPUAAC2_MJN09g-1SHoPWQv82zvmQGTvrniDXm9BUWK73QrKCNCgxk0uGp6MrKF8cDQrigQCI3CW1G8V8GNltJ0GRc-yBjt69zPem4YW_b0XCZwsIFhWiOoul7eIhEOjb_F0X9A9B_DOmQNbCWHF6AzqDro4U0XjH_CgtJ_J0MVZjDPmyDL1p/s260-e100/android-banking-malware.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4071906814766805070</id><published>2026-08-20T14:12:03.724+05:30</published><updated>2026-08-20T14:12:03.724+05:30</updated><title type="text">40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets</title><summary type="html">
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.

According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4071906814766805070" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4071906814766805070" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html" rel="alternate" title="40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA5ySurVDL2oPvG7l78G22fbZEDplybrP5KX79GCEuhHybqkIgDGWDY_iHNfSLhKMt4sxn51CF33lRNwyjQy-l4Zajbkl9qUFxsjHEIoVsFhWBcGoHavMzOnmbWAI-8VHreBmZhuoCPs_N5KAKLFccr-bFLhzvJq12bvhvp5upRSkZulRN4tUDUTkfTRqo/s260-e100/firefox.png" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1964953964852855066</id><published>2026-08-20T11:34:34.449+05:30</published><updated>2026-08-20T11:34:34.449+05:30</updated><title type="text">Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code</title><summary type="html">
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.

The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.

"The flaw lives in the Forms module's File </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1964953964852855066" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1964953964852855066" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html" rel="alternate" title="Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitKWjeNJOL_DEahUmMAYpH9qh94s2iFi8igtfSlAzOVWiUBU-EIM0MWMsFYPmA5NDL6Rs9E-w9vvCmw3Cc6Og0q-TDt87Q2hwYIePNAQ0xQ3OJYHzgCizDFm-YK9SxW4ncWnuVLaOzgb3SPO7Qpx17zHMaFzBQfYllgz5IP-p1jMALgWlasRkj1nV3Tq3G/s260-e100/wordpress.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1641799291855126428</id><published>2026-08-20T00:32:40.028+05:30</published><updated>2026-08-20T00:32:40.028+05:30</updated><title type="text">Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second</title><summary type="html">
Cybersecurity researchers have disclosed details of a&amp;nbsp;remote Spectre attack&amp;nbsp;against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.

The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers, </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1641799291855126428" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1641799291855126428" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html" rel="alternate" title="Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi50HcHSWt796lc8zQ8Anp_fHUqgV-BM0xiS1NxJW8zRDgBRJ9ovZOECiIhdQt0aVTUdhduJYP1o5wTa5RpDoCwhihq8rKqWmh73E9E8UzafyDcq1n1khCEIDCikK2L6NEt1mbIuMRm6F36bap74JtZawFqqCPvWF72SAm25BzREVerWYaRIDEo1O89V4k/s260-e100/jwt.jpg" width="72"/></entry></feed>