Researcher Claims Control of ChatGPT Secure Sandbox
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.
If you have trouble remembering the passwords for all of your online accounts, we've handpicked the best password manager apps to help you stay protected.
GitHub already has an EDR. You just have to listen to it
Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.…
At their Black Hat USA 2026 presentation, researchers Yossi Weizman of…
You’re just not listening.
” The duo described an EDR-style detection approach built from GitHub’…
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.…
Three of the vulnerabilities affect all Zoom client applications for a…
6, while the fourth impacts Zoom Workplace VDI Client for Windows and …
Products such as Zoom Rooms and Zoom Meeting SDK before versions 7.
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.…
The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-202…
Past vulnerabilities in this component have let an authorized attacker…
“Exploitation has already been detected,” noted Jack Bicer, director o…
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.…
The Metabase vulnerability revealed on August 6, designated CVE-2026-7…
It is present in versions 1.
“You don’t see a perfect 10/10 on CVSS often, but when you do, be worr…
Outdated Cybercrime Laws Put Security Researchers at Risk
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.