Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The article reports a fake CCleaner installer that infects Windows users with GhostDesk spyware via a malicious Chrome extension. The multi-stage attack modifies Chrome and establishes command-and-control to steal sensitive data.
Microsoft's August 2026 Patch Tuesday addressed a record 398 vulnerabilities, including one actively exploited zero-day (CVE-2026-68820) in a Windows kernel driver that allows privilege escalation to SYSTEM. The update also patched four critical remote code execution flaws (CVSS 9.8) requiring no user interaction, affecting Windows DNS Server, WDS, QUIC, and HPC Pack, though none were reported as exploited at release.
The NSA has appointed Kerianne Tobitsch, a former senior lawyer at the Department of Homeland Security, as its new general counsel. The news was reported by Recorded Future News based on sources.
Cisco is warning about a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense software. The flaw is being actively exploited to remotely crash affected devices.
The article details the discovery of Kimwolf v7, an Android and IoT botnet that uses HTTP/2 DDoS attacks mimicking legitimate browsing. It also describes improvements in command-and-control resilience and the removal of scanning functionality to separate propagation from core payload.
A ransomware group claimed to have exfiltrated 6 terabytes of data from a hospital system, including highly sensitive health records. The stolen data includes records related to sexual assault, mental health, and abortions.