Everything is better with pickles... except Windows
Operating system indigestion pops up over chicken sandwich ad
Aggregated from vendor advisories, security research, and industry publications.
Operating system indigestion pops up over chicken sandwich ad
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Opera…
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs ap…
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared firs…
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions…
Developer spotted hostname and credential string lurking in autocomplete
CEO says buyers are moving fast and shuffling budgets to replace old boxen
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is C…
Plans to build models instead because it thinks selling tokens will prove more lucrative in the long term
Attackers could extract data, even working from inside a guest VM
ChatGPT Ads, I wish I knew how to quit you
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
And it'll jump through every financial hoop it can to get there
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time.…
Some say the world will end in fire, some say an agentic swarm
Think your bugs are a pain to track? WAL-Reset took six months of hunting and development of a new logging tool to identify
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack cust…
Same stateful trick, now with your own infrastructure
Eight years on, we're still paying to hide the future glimpsed during speculative execution
NeMo Switchyard brings GPT-5-style model routing to the mainstream
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a …
Exploit Wednesday's back, baby
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a neve…
Contributors wanted: 167B transparent tokens have a long way to go against AI giants' trillions
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base…
Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Despite significant public pushback, North America’s data center industry is engaging in unprecedented expansion, with more than 66 gigawatts (GW) of capacity under construction as…
Neocloud says AI compute demand is becoming continuous, but so is the spending
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor softwar…