Skip to content
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia… 

Gogs 10.0 RCE, n8n Workflow-to-RCE, M Reward, GLM-5.3 AI Exploit and More

Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Ravie LakshmananAug 20, 2026Hacking News / Cybersecurity News A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help… 

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an “active threat” targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct… 

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI’s Grok chatbot to send a user’s name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server… 

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Ravie LakshmananAug 20, 2026Vulnerability / Application Security Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers… 

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Ravie LakshmananAug 20, 2026Network Security / Enterprise Security Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing… 

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Ravie LakshmananAug 20, 2026Vulnerability / Email Security A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability… 

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication… 

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up…