Cyber Intelligence Dashboard

IST Date: 09 Aug 2026 • Showing: Recent 48h (fallback)
Merged cache: 09 Aug 2026, 10:55
🔄 Force Refresh
Per-feed TTL: 600s • Global TTL: 300s
Zero-Day / Exploit
8 items
Hackers breach TrueConf to trojanize client installers with backdoors
BleepingComputer • 08 Aug 2026, 19:46
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]
Zero-Day / Exploit Read full
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
The Hacker News • 08 Aug 2026, 12:28
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attack...
Zero-Day / Exploit Read full
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
The Hacker News • 08 Aug 2026, 12:27
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat ac...
Zero-Day / Exploit Read full
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The Hacker News • 08 Aug 2026, 12:22
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026...
Zero-Day / Exploit Read full
Metabase SQLi zero-day exploited in customer data-theft attacks
BleepingComputer • 08 Aug 2026, 01:44
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]
Zero-Day / Exploit Read full
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
The Hacker News • 08 Aug 2026, 00:18
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, bu...
Zero-Day / Exploit Read full
Growing Up The Hard Way
The Hacker News • 07 Aug 2026, 17:25
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back wh...
Zero-Day / Exploit Read full
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
The Hacker News • 07 Aug 2026, 15:39
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a ...
Zero-Day / Exploit Read full
CVE / CWE / Vulnerability
1 items
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
The Hacker News • 07 Aug 2026, 18:26
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with a...
CVE / CWE / Vulnerability Read full
VAPT Tools & Releases
3 items
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
The Hacker News • 08 Aug 2026, 13:33
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, h...
VAPT Tools & Releases Read full
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
The Hacker News • 07 Aug 2026, 16:40
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6....
VAPT Tools & Releases Read full
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
The Hacker News • 07 Aug 2026, 13:48
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the ...
VAPT Tools & Releases Read full
Cybercrime & Incidents
11 items
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
The Hacker News • 08 Aug 2026, 14:24
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. Promp...
Cybercrime & Incidents Read full
Unlimited Technology Systems breach impacts 3.8 million people
BleepingComputer • 08 Aug 2026, 01:00
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
Cybercrime & Incidents Read full
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
The Hacker News • 07 Aug 2026, 23:59
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host a...
Cybercrime & Incidents Read full
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
The Hacker News • 07 Aug 2026, 23:46
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating ...
Cybercrime & Incidents Read full
Levi Strauss & Co. says hackers stole corporate data in cyberattack
BleepingComputer • 07 Aug 2026, 21:18
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
Cybercrime & Incidents Read full
Real emails, hijacked payments: Two H1 2026 attack chains
BleepingComputer • 07 Aug 2026, 19:30
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]
Cybercrime & Incidents Read full
North Carolina Ports confirms cyberattack disrupting operations
BleepingComputer • 07 Aug 2026, 19:04
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]
Cybercrime & Incidents Read full
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
The Hacker News • 07 Aug 2026, 16:28
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the re...
Cybercrime & Incidents Read full
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
The Hacker News • 07 Aug 2026, 16:08
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email....
Cybercrime & Incidents Read full
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
The Hacker News • 07 Aug 2026, 14:22
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it control...
Cybercrime & Incidents Read full
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
The Hacker News • 07 Aug 2026, 12:20
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The connection is sup...
Cybercrime & Incidents Read full
General Security News
1 items
AI-Generated Patches Fail Half the Time
DarkReading • 07 Aug 2026, 22:17
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
General Security News Read full
All (merged)
135 items
Metabase SQLi zero-day exploited in customer data-theft attacks
BleepingComputer • 08 Aug 2026, 01:44
Unlimited Technology Systems breach impacts 3.8 million people
BleepingComputer • 08 Aug 2026, 01:00
AI-Generated Patches Fail Half the Time
DarkReading • 07 Aug 2026, 22:17
Real emails, hijacked payments: Two H1 2026 attack chains
BleepingComputer • 07 Aug 2026, 19:30
North Carolina Ports confirms cyberattack disrupting operations
BleepingComputer • 07 Aug 2026, 19:04
Growing Up The Hard Way
The Hacker News • 07 Aug 2026, 17:25
Researcher Claims Control of ChatGPT Secure Sandbox
DarkReading • 07 Aug 2026, 02:08
Swiss government SharePoint breach compromised 200 accounts
BleepingComputer • 06 Aug 2026, 23:44
Canadian Man Pleads Guilty in Snowflake Extortions
KrebsOnSecurity • 06 Aug 2026, 22:30
Meta AI model hacked a company during misconfigured cyber test
BleepingComputer • 06 Aug 2026, 21:41
AI Sends Global Crime Syndicates Into Fraud Nirvana
DarkReading • 06 Aug 2026, 05:05
No Perfect Fix for AI Browser Prompt Injection Flaws
DarkReading • 06 Aug 2026, 03:48
Canadian pleads guilty to Snowflake cloud data-theft attacks
BleepingComputer • 06 Aug 2026, 03:23
CSS: The Hidden Threat Lurking in Your Inbox
DarkReading • 06 Aug 2026, 01:17
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
DarkReading • 06 Aug 2026, 00:38
Angola's Largest Telco Breached Hours Before IPO
DarkReading • 05 Aug 2026, 13:30
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
DarkReading • 04 Aug 2026, 12:30
New Tool Traces AI Videos Back to Their Source
DarkReading • 04 Aug 2026, 02:12
Is There Really a Fix for CISO Fatigue?
DarkReading • 03 Aug 2026, 19:30
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
DarkReading • 31 Jul 2026, 23:43
AI Harnesses Burst With Potential Exploit Opps
DarkReading • 31 Jul 2026, 01:10
Read This Before You Buy That TV Streaming Stick
KrebsOnSecurity • 30 Jul 2026, 22:19
SE Asian Cybercriminal Syndicates Become a Global Power
DarkReading • 30 Jul 2026, 06:30
LG to Ban Residential Proxies from Smart TV Apps
KrebsOnSecurity • 22 Jul 2026, 06:40
Microsoft Patches a Record 570 Security Flaws
KrebsOnSecurity • 15 Jul 2026, 00:52
Lessons Learned from CISA’s Recent GitHub Leak
KrebsOnSecurity • 13 Jul 2026, 20:33
For Every type business

Powered by INetSecurity.in • Feeds: The Hacker News, BleepingComputer, Exploit-DB, CISA, SecurityWeek, ThreatPost, DarkReading, KrebsOnSecurity