Microsoft Plugs Nearly 400 Security Holes

Microsoft’s August Patch Tuesday delivered a massive 398 security updates for Windows operating systems and supported software. This is just one of several recent record-breaking patches from the tech giant, which has attributed its success in part to the use of artificial intelligence (AI) in vulnerability discovery. The sheer number of flaws patched this month … Read more

DeadLock ransomware uses blockchain to resist infrastructure takedown

DeadLock Ransomware Operators Use Blockchain to Evade Takedown Efforts, Expose 80 Organizations In a brazen display of cryptocurrency-fueled innovation, the DeadLock ransomware operation has leveraged blockchain technology to fortify its communication channels and data leak activities against disruption by law enforcement agencies. The threat actor, which emerged in mid-2025, employs double-extortion tactics – stealing sensitive … Read more

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

Zoom Annotation Flaws Expose Users to Hijacking Risks A concerning vulnerability has been discovered in Zoom’s annotation feature, potentially allowing a meeting participant to take control of another attendee’s client and access their personal data. The issue affects all versions of the popular video conferencing platform, making it a pressing concern for users who rely … Read more

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

A new Android botnet, dubbed Kimwolf v7, has emerged on the cybersecurity scene, leveraging a clever trick to masquerade as legitimate web traffic. This sophisticated malware has been infecting devices worldwide, posing a significant threat to online security and making it challenging for defenders to distinguish between benign browsing activity and malicious DDoS attacks. Kimwolf … Read more

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft Patches 398 Flaws, Including a Zero-Day Driver Vulnerability Under Active Attack A massive batch of patches from Microsoft has just been released, addressing an astonishing 398 vulnerabilities across its various products and services. Among these, one critical zero-day vulnerability in a Windows driver is already being actively exploited by attackers, making it imperative for … Read more

Microsoft Plugs Nearly 400 Security Holes

Microsoft’s latest Patch Tuesday update has plugged nearly 400 security vulnerabilities across its Windows operating systems and supported software, including one critical flaw that is already being actively exploited. The sheer volume of patches released by Microsoft has raised questions about whether artificial intelligence (AI) is truly effective in helping to identify and fix these … Read more

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Unauthorized Wi-Fi Network Disrupts Flight Carrying DEF CON Attendees, Raises Concerns About In-Flight Security A bizarre incident unfolded on a Delta Air Lines flight from Las Vegas to Atlanta yesterday, when an unauthorized Wi-Fi network appeared on board, allegedly brought by passengers returning from the DEF CON 34 hacking conference. The rogue network was quickly … Read more

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

A High-Severity VPN Flaw in Cisco Software is Being Actively Exploited, Causing Devices to Crash A critical vulnerability has been discovered in Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, which is being exploited by attackers to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, affects devices running certain remote … Read more

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

A Novel Threat Emerges: DeadLock Ransomware Leverages Polygon Smart Contracts for Unprecedented Extortion Capabilities DeadLock, a highly sophisticated ransomware variant, has been making headlines in recent weeks due to its innovative use of Polygon smart contracts. This malware strain has successfully exploited a previously unknown vulnerability in the decentralized finance (DeFi) sector, allowing it to … Read more

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

A newly disclosed vulnerability in Microsoft’s SharePoint software has left organizations vulnerable to unauthenticated remote code execution (RCE) attacks, thanks to an AI-assisted exploit chain that exploits weaknesses in user identity exposure. Researchers have revealed a sophisticated attack path that leverages cross-domain privilege escalation to reach sensitive areas of the network, posing significant risks to … Read more