20/08/2026
Source : The Hacker News Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. « The operation doesn’t rely on a single piece of malware, but on […]
20/08/2026
Source : The Hacker News Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker […]
20/08/2026
Source : BleepingComputer A suspected ransomware affiliate is posing as a ransomware recovery service called « Ransom Busters, » contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type […]
20/08/2026
Source : The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting […]
20/08/2026
Source : The Hacker News Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed […]
20/08/2026
Source : The Hacker News Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of […]
19/08/2026
Source : The Hacker News Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part […]
19/08/2026
Source : BleepingComputer Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security’s Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. […] Lire l’article original Vous vous demandez si votre entreprise est […]
19/08/2026
Source : The Hacker News A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to […]
19/08/2026
Source : The Hacker News Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. « TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services, » Ontinue said in a technical report shared with The Hacker News. « Tasking flows through SharePoint Online file Lire […]