Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Security researchers disclosed a two-stage exploit chain against Unisoc modem firmware that achieves full Android kernel access through an incoming VoLTE video call. Stage 1 (March 2026) provides modem-level RCE; Stage 2 (August 2026) exploits shared physical address space between modem and application processors to escalate to kernel access.
The French Ministry of the Economy and Finance disclosed a data breach affecting 678,000 individuals and professionals after an attacker, using the handle “ZeroBytes,” gained unauthorized access to the General Directorate of Public Finances (DGFiP) systems. The breach was discovered on August 12, 2026, when the threat actor listed the stolen database for sale on the PwnForums hacking forum.
This article positions Symantec CBX as a disruptive, predictive XDR platform that merges the legacy strengths of Symantec and Carbon Black into a single cloud-based solution. It directly counters competitor criticisms (e.g., “siloed legacy code”) by emphasizing CBX’s unified correlation across endpoints, networks, data, and cloud—all visible in one pane of glass.
Researchers at Fortinet FortiGuard Labs discovered Evooo1Bot, a Mirai-derived Linux botnet active since July 2026 that weaponizes 10 known vulnerabilities across routers and edge devices. The botnet combines DDoS capabilities with encrypted C2, credential sniffing, and a SOCKS5 proxy module that operators use to anonymize traffic, bypass geo-restrictions, and access internal networks through compromised devices.
Microsoft has confirmed it is working on a security patch for “ShieldBreak,” a zero-day privilege escalation vulnerability in Microsoft Defender tracked as CVE-2026-69414. The flaw was publicly disclosed by security researcher “Nightmare Eclipse” after the August 2026 Patch Tuesday updates, without prior notice to Microsoft.
WeLiveSecurity examines how QR-code phishing evades corporate defenses by moving victims from protected environments to unmanaged mobile devices, with malicious URLs hidden in visual patterns that bypass traditional email security filters.