New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Today’s signal The Hacker News recently reported New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts. Published context: August 6, 2026. Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), wh ...

August 7, 2026 · 3 min · David Gomez

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

Today’s signal The Hacker News recently reported CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild. Published context: August 6, 2026. A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated atta ...

August 6, 2026 · 3 min · David Gomez

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

Today’s signal The Hacker News recently reported New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch. Published context: August 5, 2026. A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclose ...

August 5, 2026 · 3 min · David Gomez

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

Today’s signal The Hacker News recently reported CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises. Published context: August 4, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 ...

August 4, 2026 · 3 min · David Gomez

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

Today’s signal The Hacker News recently reported PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web. Published context: August 3, 2026. The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified ...

August 3, 2026 · 3 min · David Gomez

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Today’s signal The Hacker News recently reported Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory. Published context: July 29, 2026. Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been code ...

August 2, 2026 · 3 min · David Gomez

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Today’s signal The Hacker News recently reported Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction. Published context: August 1, 2026. Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect ...

August 1, 2026 · 3 min · David Gomez

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Today’s signal The Hacker News recently reported Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations. Published context: July 31, 2026. Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the di ...

July 31, 2026 · 3 min · David Gomez

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Today’s signal The Hacker News recently reported Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data. Published context: July 30, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an una ...

July 30, 2026 · 3 min · David Gomez

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

Today’s signal The Hacker News recently reported OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach. Published context: July 29, 2026. OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more ...

July 29, 2026 · 3 min · David Gomez

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Today’s signal The Hacker News recently reported Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In. Published context: July 28, 2026. JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. ...

July 28, 2026 · 3 min · David Gomez

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Today’s signal The Hacker News recently reported Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data. Published context: July 22, 2026. Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: ...

July 27, 2026 · 3 min · David Gomez