Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A cyber espionage campaign named Operation QUICSILVER targets Myanmar's government and IT sectors using graduation ceremony invitations as lures. The attack delivers a Go-based backdoor called QUICAgent through a multi-stage process involving VHD files and abuse of legitimate Windows binaries.
Akamai research reveals that a small group of AI power users, the top 5%, pose the biggest security risk by embedding unvetted AI tools into critical operations. These super-adopters expand shadow AI, increase data leakage opportunities, and introduce autonomous agents outside corporate guardrails.
The Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch a Zimbra Collaboration Suite vulnerability that is being actively exploited. CVE-2026-73570 has been added to CISA’s Known Exploited Vulnerabilities catalog, requiring U.S. government agencies to apply patches within three days.
Microsoft has provided a temporary workaround for gaming issues on Windows 11 that arose after the August 2026 Patch Tuesday updates. The fix aims to restore normal game performance while the company develops a permanent solution.
A Chinese-speaking cybercrime group called UAT-10147 is targeting web servers worldwide using AI-powered tools to automate exploitation, reconnaissance, and payload deployment. The group deploys a cross-platform backdoor named SPECTRE that includes kernel-level EDR bypass and a Linux rootkit for stealthy persistence.
Multiple vulnerabilities were identified in Zimbra. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, sensitive information disclosure, security restriction bypass and remote code execution on the targeted system.