Skip to content
Security News, Assessments & Alerts Page 35

Security News, Assessments & Alerts

Security Issues, Vulnerabilities, Exploits & Government Alerts

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

Ravie LakshmananAug 13, 2026Malware / Mobile Security A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as… 

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Ravie LakshmananAug 13, 2026Vulnerability / Enterprise Security Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score:… 

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Ravie LakshmananAug 12, 2026Vulnerability / Cyber Espionage The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a… 

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

Ravie LakshmananAug 12, 2026Browser Security / Privacy A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept… 

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) today released the K-12 Cybersecurity Foundations Resource Package, a comprehensive collection of guides, videos and supplemental materials to help K‑12 schools and districts prevent, mitigate and… 

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness… 

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Ravie LakshmananAug 12, 2026Vulnerability / Web Security Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege… 

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Ravie LakshmananAug 12, 2026Vulnerability / Threat Intelligence Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is…