Cybersecurity

CSS attacks in webmail can steal passwords, tokens

PortSwigger researcher Gareth Heyes presented CSS-based email attacks at Black Hat USA 2026 on August 8.The attacks exploited HTML and CSS techniques in Outlook,...

New Go-Based macOS Malware Drains Crypto Wallets via ClickFix

ClickFix-style attacks are delivering Go-based malware on macOS that steals cryptocurrency wallet funds, browser passwords, and iCloud Keychain data.The malware includes a "DRAIN" routine...

Linux SCTP bug allows full container escape, root access

CVE-2026-64564 (SCTPhantom) is a use-after-free bug in Linux's SCTP networking code that can escalate to full root access and container escape.The flaw has existed...

AI discovers new HTTP desync attacks, 700+ sites at risk

PortSwigger's AI system, HTTP Terminator, autonomously generated and validated novel HTTP desynchronization attacks after exploring 30,000 candidate vectors.The research identified roughly 700 vulnerable targets...

Cisco Patches Critical Flaws in Catalyst SD-WAN, IOS XE

Cisco disclosed multiple critical vulnerabilities in Catalyst SD-WAN and IOS XE Software, discovered during internal security testing using frontier AI models.The flaws include improper...

WebKit bug lets websites bypass iCloud Private Relay, leak IP

Cybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed a WebKit vulnerability that bypasses Apple's iCloud Private Relay.Three specific features in WebKit—DNS prefetching, WebAuthn,...

Ransom Cartel kingpin sentenced to 16 years in prison

Maksim Silnikau, a Belarusian national, was sentenced to 16 years in prison for running the Ransom Cartel ransomware-as-a-service operation.The scheme targeted at least 18...

MacOS ClickFix Campaign Uses Fingerprinting to Hide Malware Lures

A macOS ClickFix campaign uses over 250 front-end domains to deliver information-stealing malware to targeted users.The attack employs a server-side fingerprinting gate that hides...

Latest news

Google releases fast AI; OpenAI previews ultrafast

Google launched Gemini 3.7 Flash on Thursday, a low-cost model for coding and agents, now generally available in over...

Trezor data leak exposes 13,689 customers to phishing risks

A data breach at Trezor's shipping partner ShipMonk leaked personal details of 13,689 customers across seven countries.The exposed data...

Public miners cut capacity faster than network, shift to AI

A cohort of public Bitcoin miners reduced realized hashrate by 13.4% from Q4 2025 to Q2 2026, with a...