If you have trouble remembering the passwords for all of your online accounts, we've handpicked the best password manager apps to help you stay protected.
GitHub already has an EDR. You just have to listen to it
Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.…
At their Black Hat USA 2026 presentation, researchers Yossi Weizman of…
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.…
Three of the vulnerabilities affect all Zoom client applications for a…
6, while the fourth impacts Zoom Workplace VDI Client for Windows and …
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.…
The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-202…
Past vulnerabilities in this component have let an authorized attacker…
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.…
The Metabase vulnerability revealed on August 6, designated CVE-2026-7…
Outdated Cybercrime Laws Put Security Researchers at Risk
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted.…
That instinct is increasingly out of date.
A growing body of security research — exploit demonstrations, independ…
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.…
Researchers from Malwarebytes found the campaign distributing a malici…
Attackers created a lookalike CCleaner download site and used it to di…
Microsoft wants you to rethink your approach to cyber defense
Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft.…
David Weston, group manager in the Windows team at Microsoft, told del…
Weston’s keynote — entitled “The End of Rare: Defending When Offense I…
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.…
The researcher, who goes by the name Nightmare Eclipse, has been engag…
Nightmare Eclipse has not provided the further details we requested, h…
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
Microsoft's Patch Tuesday Deluge Continues With August Updates
The most concerning bug in the batch is CVE-2026-62878 (CVSS: 9.8), a remote code execution (RCE) vulnerability in Windows DNS Server that requires no user interaction.
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.