AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.
AI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.
Researcher Claims Control of ChatGPT Secure Sandbox
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.
If you have trouble remembering the passwords for all of your online accounts, we've handpicked the best password manager apps to help you stay protected.
GitHub already has an EDR. You just have to listen to it
Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.…
At their Black Hat USA 2026 presentation, researchers Yossi Weizman of…
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.…
Three of the vulnerabilities affect all Zoom client applications for a…
6, while the fourth impacts Zoom Workplace VDI Client for Windows and …
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.…
The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-202…
Past vulnerabilities in this component have let an authorized attacker…
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.…
The Metabase vulnerability revealed on August 6, designated CVE-2026-7…
Outdated Cybercrime Laws Put Security Researchers at Risk
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.