Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

A sophisticated threat actor has been using a novel technique called Cavern C2 to blend malicious activity with legitimate traffic, evading detection by security systems. This clever tactic leverages Google Apps Script and DNS to create an almost undetectable attack path, putting countless organizations at risk. Cavern C2 works by utilizing Google’s cloud infrastructure to … Read more

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A Critical Flaw in Forminator WordPress Plugin Exposes Sites to Remote Code Execution Attacks A severe vulnerability has been discovered in the popular Forminator plugin for WordPress, which allows attackers to execute arbitrary code on affected websites without authentication. The critical flaw, uncovered by security researchers, can be exploited via malicious PHP uploads, putting hundreds … Read more

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

A Critical GitHub Actions Flaw Exposes Developers to Command Injection Attacks A severe vulnerability has been discovered in GitHub’s Actions feature, which allows maliciously crafted issues to trigger command injection attacks against developers’ repositories. The flaw, identified by a researcher, enables an attacker to inject arbitrary system commands into affected projects, giving them elevated privileges … Read more

French tax authority data breach affects 678,000 individuals

A massive data breach at the French tax authority has left 678,000 individuals exposed, with sensitive financial and personal information potentially compromised. The attack, which was announced on August 12, is just the latest in a string of cyberattacks to hit French government agencies this year. According to the French Finance Ministry, an attacker using … Read more

Philips and GE investigating Clop ransomware data theft claims

Two Tech Giants and an Oil Giant Investigate Claims of Clop Ransomware Data Theft A trio of high-profile companies is facing a potentially serious cybersecurity breach after the notorious Clop ransomware gang claimed to have stolen sensitive data from their systems. General Electric (GE), Philips, and Shell are all investigating claims that the attackers exploited … Read more

Certighost and the Privilege Hiding in Your Certificate Authority

A Critical Flaw in Active Directory Exposes Organizations to Domain Compromise A disturbing vulnerability has been discovered in Microsoft’s Active Directory Certificate Services, which can be exploited by an attacker with minimal privileges to compromise an entire domain. The flaw, tracked as CVE-2026-54121, is a result of a combination of trust and privilege failure, rather … Read more

Microsoft confirms GitHub is down worldwide

Widespread Outage Brings GitHub to its Knees, Leaving Developers Scrambling A devastating global outage has crippled GitHub, a crucial platform for developers and open-source projects, sending shockwaves through the tech industry. As of this morning, thousands of users are experiencing errors accessing various parts of the website, including API requests, Actions, Webhooks, Issues, and Pull … Read more

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Cybersecurity Threats Escalate as Identity Exposure Creates Active Attack Paths A recent investigation has uncovered a concerning trend in cyber attacks, where compromised identities are being exploited to create active attack paths. This alarming phenomenon not only puts sensitive data at risk but also reveals a sophisticated approach employed by attackers to breach even the … Read more

Certighost and the Privilege Hiding in Your Certificate Authority

A recently disclosed vulnerability in Microsoft’s Active Directory Certificate Services has exposed a hidden privilege that can be exploited to gain control over an entire domain. The flaw, tracked as CVE-2026-54121, is known as Certighost and it allows an attacker to coerce a Certification Authority (CA) into issuing a valid authentication certificate for a Domain … Read more

Microsoft confirms GitHub is down worldwide

GitHub’s Global Outage Leaves Developers Reeling A massive disruption is affecting developers worldwide as GitHub, a popular platform for collaboration and version control, has gone dark. The outage, which began early on August 17th, has crippled various services, including API Requests, Actions, Webhooks, Issues, and Pull Requests, leaving many users unable to access their projects. … Read more