Microsoft fixes over 400 flaws in August 2026 Patch Tuesday, including one zero-day
Check Point said the North Korean Lazarus group exploited CVE-2026-68820 to deploy the FudModule kernel-mode rootkit.
Check Point said the North Korean Lazarus group exploited CVE-2026-68820 to deploy the FudModule kernel-mode rootkit.
Gunra also exploits credential-exposure and SSH access control security flaws in internet-facing VPN gateways to gain remote access to victims' systems.
The campaign uses job offers and fake recruitment processes to target system administrators and other IT professionals.
In the observed attack, Storm-1175 deployed remote monitoring and management tools, including AnyDesk and SimpleHelp.
The company said its Metabase Cloud platform was targeted via a previously unknown flaw affecting versions 1.58 and later.
In brief: a critical N-able flaw exploited in the wild; Russian hackers target hotel Wi-Fi systems; and more.
The attackers gained access through a vulnerable autocomplete search feature in a public-facing Java application hosted on Apache Tomcat.
The attack, called ChainDrop, began after hackers infected the keyv and cacheable packages.
Researchers started with a lower-level employee's compromised email account and used the AI assistant to gather information and plan an attack.
Researchers said INC Ransomware was not the first group to abuse the flaws, but it has been the most aggressive in combining both vulnerabilities into a full attack chain.
Showing elements 71 - 80