Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Three vulnerabilities in Zoom, collectively dubbed Zoomsday, allow attackers to exploit annotation data processing flaws to crash clients, leak information, or execute malicious code. These flaws affect Zoom Workplace, Zoom Rooms, and Zoom Meeting SDK on various platforms.
The FBI has issued a warning about cybercriminals targeting online accounts to steal sexually explicit images and videos from both adults and children. The threat spans social media and other platforms, emphasizing the importance of protecting personal accounts from unauthorized access.
A large set of 737 Chrome VPN extensions were found to route browser traffic through a fixed SOCKS5 proxy, placing the attacker in a position to intercept data. Many impersonated popular VPN brands, and while some have been removed, over 500 remain active, posing a privacy risk to users.
Fake remote workers can slip through hiring process gaps, gaining access under false identities. Specops Software recommends document verification and biometric liveness checks to ensure the person receiving access is the legitimate new hire.
Ransomware attackers struck Colombia's Justice Ministry just days ahead of a presidential transition, highlighting ongoing threats to critical infrastructure and government organizations in the country. The attack reflects a broader surge in cybercriminal activity across Latin America, where state-linked and critical entities remain prime targets.
Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities, 62 rated critical, including three zero-days. One Windows flaw has been actively exploited by the Lazarus group to gain SYSTEM privileges, while another publicly disclosed privilege escalation bug with a proof-of-concept poses additional risk.