Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

Today’s signal The Hacker News recently reported Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner. Published context: August 15, 2026. A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an atta ...

August 18, 2026 · 3 min · David Gomez

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Today’s signal The Hacker News recently reported Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware. Published context: August 17, 2026. Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a mali ...

August 17, 2026 · 3 min · David Gomez

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Today’s signal The Hacker News recently reported Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access. Published context: August 12, 2026. Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrar ...

August 16, 2026 · 3 min · David Gomez

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Today’s signal The Hacker News recently reported Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws. Published context: August 12, 2026. Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulne ...

August 15, 2026 · 3 min · David Gomez

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Today’s signal The Hacker News recently reported Attackers Exploit SharePoint Authentication Bypass After Public PoC Release. Published context: August 13, 2026. Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch T ...

August 14, 2026 · 3 min · David Gomez

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

Today’s signal The Hacker News recently reported OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development. Published context: August 11, 2026. OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. “Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to re ...

August 13, 2026 · 3 min · David Gomez

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Today’s signal The Hacker News recently reported ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access. Published context: August 12, 2026. The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePla ...

August 12, 2026 · 3 min · David Gomez

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Today’s signal The Hacker News recently reported Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks. Published context: August 11, 2026. Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. “Gunra is another ...

August 11, 2026 · 3 min · David Gomez

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Today’s signal The Hacker News recently reported New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA. Published context: August 10, 2026. Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the ...

August 10, 2026 · 3 min · David Gomez

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Today’s signal The Hacker News recently reported Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts. Published context: August 8, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could ...

August 9, 2026 · 3 min · David Gomez

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Today’s signal The Hacker News recently reported Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication. Published context: August 8, 2026. Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application databas ...

August 8, 2026 · 3 min · David Gomez

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Today’s signal The Hacker News recently reported New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts. Published context: August 6, 2026. Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), wh ...

August 7, 2026 · 3 min · David Gomez