Evooo1Bot turns routers into SOCKS5 relays: what defenders should fix
A Mirai-derived botnet is turning residential and edge routers into SOCKS5 relays for criminal traffic, and quietly harvesting credentials along the way.
US government authorizes private security firms to hack overseas cybercriminals
The Trump administration has issued a National Security Presidential Memorandum authorizing private security firms to conduct offensive cyber operations against overseas criminal organizations. The program, managed by the National Coordination Center under the Homeland Security Task Force, marks the first time the US government has formally delegated offensive cyber authority to the private sector. Under […]
Critical VMware vCenter RCE exploited via reverse SSH
A critical remote code execution vulnerability in VMware vCenter’s Syslog Server is under active exploitation right now. Tracked as CVE-2026-59310, the flaw carries a CVSS 3.1 score of 9.8 and is being used in a live campaign that drops an open source reverse SSH tool onto compromised hosts for persistence and remote access. If you […]
Pass-ta-key: What the New Passkey Attack Actually Does
Passkeys were supposed to end the era of phishing. They are cryptographic, they do not rely on passwords you can type into a lookalike website, and the big platform vendors have spent years pushing them as the replacement for credentials. So when a new attack with the catchy name “Pass-ta-key” hit the news, it was […]
Cisco ClamAV flaws with public exploits leave a detection gap
Cisco has warned about a batch of vulnerabilities in the ClamAV engine that ships inside its Secure Endpoint Connector. Seven flaws, disclosed on August 7, all let an unauthenticated remote attacker crash the malware scanner by feeding it a crafted file. Two of them already have public proof-of-concept code, which is why the advisory is […]
DeadLock ransomware uses blockchain to shrug off takedowns
Ransomware groups have spent years moving their leak sites around the internet, hopping from domain to domain as takedowns land. DeadLock tries to remove the weak point entirely. It spreads its command structure across a blockchain, so there is no single server for police to seize and no domain name to sinkhole. How it stays […]
Critical LoadMaster Command Injection Is Under Active Attack, Patch Now
If you run Progress LoadMaster (or the Kemp-branded versions of it), this is a patch-this-week story, not a note-for-later story. CISA has confirmed that a critical command injection vulnerability in the load balancer is being actively exploited in the wild, and the agency has added it to the Known Exploited Vulnerabilities catalog. That KEV listing […]
Mythos Attack Breaks a Post-Quantum Crypto Candidate, and the Lesson Is Uneasy
Late last month a team of cryptographers took a post-quantum signature scheme out of contention before it ever shipped, and they did it with an attack that left the research community quietly reassessing how much trust to place in the standards pipeline. The scheme was HAWK, a lattice-based digital signature candidate that had made it […]
TrueConf Servers Hijacked to Push Backdoored Installers
Video conferencing vendor TrueConf has confirmed a supply chain attack in which hackers hijacked servers and swapped legitimate client installers for backdoored versions. The intrusions, attributed by Kaspersky to the hacktivist group Head Mare, targeted unpatched TrueConf servers and used them to hand malicious software to anyone who downloaded the client. The attack is a […]
Januscape: The 16-Year-Old KVM Flaw That Earned a $250K Bounty
Google handed out $250,000 for a Linux kernel vulnerability that had been hiding in plain sight for 16 years. Named Januscape and tracked as CVE-2026-53359, the flaw is a use-after-free bug in the KVM hypervisor’s shadow MMU code. It lets a guest virtual machine escape to the host, and it is the first KVM exploit […]
LegacyHive Zero-Day Bypasses July’s Record Patch Tuesday
Microsoft shipped its largest Patch Tuesday in history on July 14, 2026, fixing 622 CVEs. Within hours, a security researcher released a proof-of-concept for a Windows privilege escalation bug that the massive update did not fix. Named LegacyHive, the exploit targets the Windows User Profile Service and lets a standard user reach administrator privileges on […]
Metabase SQL injection zero-day is being exploited for data theft
A critical Metabase vulnerability is being actively exploited in the wild to steal customer data, and at least two well-known companies have already confirmed they were hit. Framework Computer and the accounting platform Tally both disclosed breaches tied to the flaw, which is an unauthenticated SQL injection in Metabase versions 1.58 and newer. If you […]