Hacking

Pierluigi Paganini August 12, 2026
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE

Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other […]

Pierluigi Paganini August 11, 2026
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory corruption issue found by A Security that could allow a meeting participant to […]

Pierluigi Paganini August 11, 2026
ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]

Pierluigi Paganini August 11, 2026
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama

Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to at least 12 states since late July. The attacks are linked to Iranian hackers targeting […]

Pierluigi Paganini August 11, 2026
The inconvenient truth about AI pentesting: someone has to check all the work

AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, long after the workshop has flooded. The industry is busy measuring how fast AI finds vulnerabilities […]

Pierluigi Paganini August 10, 2026
Gym Booking Task Turns Into Real-World AI Cyberattack

An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didn’t ask it to remove another […]

Pierluigi Paganini August 10, 2026
Hackers Cross From IT to OT Through a Private APN in Poland

Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an ordinary-looking network design can turn into a route into […]

Pierluigi Paganini August 10, 2026
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark

Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s essentially what happened when Moonshot’s Kimi K3 model was put through a cybersecurity evaluation […]

Pierluigi Paganini August 09, 2026
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and […]

Pierluigi Paganini August 08, 2026
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]