Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

A sophisticated Chinese threat actor has been using a leaked DarkSword exploit kit to deploy a notorious malware variant, GHOSTBLADE, on iOS devices. The attack vector targets iPhone and iPad users, compromising their sensitive data and potentially paving the way for further malicious activities. The DarkSword exploit kit, initially designed to target Android devices, has … Read more

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

A Critical Flaw in Hugging Face Diffusers Exposes Model Repositories to Code Execution Risks A vulnerability has been discovered in the popular Hugging Face Diffusers library, a widely-used tool for building and deploying AI models. The flaw, disclosed on August 3rd, could allow attackers to inject malicious code into model repositories, potentially leading to arbitrary … Read more

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

A Critical Vulnerability in N-central Servers Exposes Thousands of Businesses to Attackers N-central, a cloud-based IT management platform used by thousands of businesses worldwide, has been compromised by attackers who have taken control of its servers despite an initial fix being implemented. The incident highlights the importance of thorough security patching and the need for … Read more

CrowdStrike: AI is now both the weapon and the target in cyberattacks

As AI-powered systems become increasingly ubiquitous in the digital landscape, they’re also becoming a double-edged sword in the world of cybersecurity. According to CrowdStrike’s latest threat hunting report, AI-driven behaviors have surpassed human-triggered incidents as the primary source of potential malicious activity detected by the company’s systems. This alarming trend highlights the need for organizations … Read more

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

A critical vulnerability in Hugging Face’s Diffusers library has left millions of users exposed, potentially allowing attackers to execute arbitrary code on model repositories. The flaw, discovered by a researcher at MIT, could have severe consequences for organizations relying on these libraries for natural language processing and computer vision tasks. The issue stems from a … Read more

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

A Critical Vulnerability Lurks in N-central Servers, Despite Initial Patch Claims A disturbing story has unfolded in the cybersecurity world, where initial attempts to fix a critical vulnerability in N-able’s N-central servers have proven woefully inadequate. According to reports, attackers have successfully taken control of these servers, putting thousands of businesses and organizations at risk. … Read more

ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)

A devastating DNS amplification attack has been wreaking havoc on internet infrastructure worldwide, bringing several major websites to their knees. The assault, which began in the early hours of Monday morning, has already caused widespread disruptions and is expected to continue for the foreseeable future. The attack itself relies on a clever manipulation of the … Read more

ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)

A Critical Vulnerability in Common Utility Software Puts Millions of Devices at Risk A recent discovery has shed light on a critical vulnerability affecting millions of devices worldwide, making them susceptible to exploitation by attackers. The flaw, which resides in a widely used utility software called “Log4j”, allows hackers to execute arbitrary code on affected … Read more

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A catastrophic flaw in a popular hardware wallet’s random number generator (RNG) has been linked to a staggering $88.6 million Bitcoin heist, leaving thousands of users vulnerable to theft. Digital asset research firm Galaxy Research identified an initial wave of transactions that it believes was likely exploited using the vulnerability, draining approximately 1,083 BTC from … Read more