OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

Today’s signal The Hacker News recently reported OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development. Published context: August 11, 2026. OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. “Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to re ...

August 13, 2026 · 3 min · David Gomez

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Today’s signal The Hacker News recently reported ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access. Published context: August 12, 2026. The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePla ...

August 12, 2026 · 3 min · David Gomez

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Today’s signal The Hacker News recently reported Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks. Published context: August 11, 2026. Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. “Gunra is another ...

August 11, 2026 · 3 min · David Gomez

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Today’s signal The Hacker News recently reported Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers. Published context: August 11, 2026. Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a ...

August 11, 2026 · 3 min · David Gomez

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Today’s signal The Hacker News recently reported New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA. Published context: August 10, 2026. Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the ...

August 10, 2026 · 3 min · David Gomez

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Today’s signal The Hacker News recently reported Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts. Published context: August 8, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could ...

August 9, 2026 · 3 min · David Gomez

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Today’s signal The Hacker News recently reported Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication. Published context: August 8, 2026. Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application databas ...

August 8, 2026 · 3 min · David Gomez

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Today’s signal The Hacker News recently reported New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts. Published context: August 6, 2026. Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), wh ...

August 7, 2026 · 3 min · David Gomez

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Today’s signal The Hacker News recently reported Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets. Published context: August 7, 2026. A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor’s agent in the configuration that the vendor ships by default, and presented th ...

August 7, 2026 · 3 min · David Gomez

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

Today’s signal The Hacker News recently reported CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild. Published context: August 6, 2026. A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated atta ...

August 6, 2026 · 3 min · David Gomez

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Today’s signal The Hacker News recently reported Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access. Published context: August 4, 2026. Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed The reason this matters is simple: buyers are paying attention to speed, operational resilience, and credible technical execution. A trending story can create awareness, but the business question is what a team should do with that attention. ...

August 6, 2026 · 3 min · David Gomez

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

Today’s signal The Hacker News recently reported New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch. Published context: August 5, 2026. A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclose ...

August 5, 2026 · 3 min · David Gomez