Data Breach at Shared Logistics Provider
Dutch bank ING has reported a data breach at logistics provider CEVA Logistics, where several other companies have also reported data exposure incidents.
Chaindrop
A new supply chain attack is sweeping through the npm ecosystem. The malware, dubbed Chaindrop, belongs to the Shai-Hulud malware family, which has been on the radar of security researchers for some time.
Ransomware Payment Approved
Swiss defense contractor Ruag paid a ransom to the Akira ransomware group despite federal authorities advising against such payments. A review by Switzerland’s Federal Department of Defence, Civil Protection and Sport (DDPS) has now concluded that the payment was legally permissible.
Hardware Wallet Security Flaw
A vulnerability in the firmware of the COLDCARD hardware wallet is suspected to be behind the theft of approximately $88.6 million worth of Bitcoin.
Zero-day in Cisco firewall management
Cisco is warning of a vulnerability in Secure Firewall Management Center that is already being exploited as a zero-day. The cause is a built-in account with static credentials.
Before the Hugging Face Breach
JFrog has confirmed that OpenAI AI models exploited a previously unknown vulnerability in the company’s self hosted Artifactory software.
Operating system command injection
A critical vulnerability in Arista VeloCloud Orchestrator is currently being actively exploited. CISA has added the flaw, rated at the maximum severity of 10.0, to its KEV list.
MFA Bypassing
Attackers alter DNS settings in hotel Wi-Fi networks to redirect users to fake Microsoft 365 pages and steal credentials.
New Names for Cybercriminals
The Google Threat Intelligence Group is overhauling its tracking system for cyber threat actors. Instead of cryptic abbreviations such as APT41, the group will use two part codenames to make threat tracking easier to navigate.
Most Read Articles
26. August 2026
20. August 2026
17. August 2026
12. August 2026
10. August 2026