SonicWall SMA1000 Zero-Days Exploited To Breach Enterprise Networks post, augustus 11, 2026augustus 17, 2026 Ransomware operators are actively exploiting two recently patched SonicWall Secure Mobile Access 1000 vulnerabilities to obtain root-level control of internet-facing remote-access appliances, steal credentials and move deeper into corporate networks. The US Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalogue to identify CVE-2026-15409 and CVE-2026-15410 as… Continue Reading
Sandworm hackers target IT pros with trojanized WireGuard VPN client post, augustus 11, 2026augustus 17, 2026 Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of… Continue Reading
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees post, augustus 11, 2026augustus 17, 2026 Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers… Continue Reading
New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption post, augustus 10, 2026augustus 17, 2026 Three independent security investigations have exposed weaknesses in the systems surrounding passkeys, demonstrating how attackers with access to a Windows endpoint could impersonate users, bypass phishing-resistant multifactor authentication or recover the private keys behind cloud-synchronised credentials. The findings do not undermine the public-key cryptography at the heart of FIDO2 and… Continue Reading
SonicWall SMA1000 flaws now exploited by ransomware gangs post, augustus 10, 2026augustus 17, 2026 CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall… Continue Reading
Hackers breached a small Polish energy plant via private APN last year post, augustus 10, 2026augustus 17, 2026 Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland’s energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut… Continue Reading
Critical Linux SCTP Flaw Enables Root Access and Container Escape post, augustus 8, 2026augustus 17, 2026 A memory-safety vulnerability hidden in the Linux kernel for almost two decades can allow a low-privileged user to take complete control of affected systems and, under certain conditions, escape from a container to compromise the underlying host. Tracked as CVE-2026-64564 and named SCTPhantom, the vulnerability is a use-after-free flaw in… Continue Reading
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data post, augustus 7, 2026augustus 17, 2026 A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees… Continue Reading
ClickFix attack pushes macOS infostealer for crypto theft attacks post, augustus 6, 2026augustus 17, 2026 A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine… Continue Reading
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities post, augustus 6, 2026augustus 17, 2026 Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were… Continue Reading