SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

18/08/2026 0 Comments 0 tags

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

18/08/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

17/08/2026 0 Comments 0 tags

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

17/08/2026 0 Comments 0 tags

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

17/08/2026 0 Comments 0 tags

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

17/08/2026 0 Comments 0 tags

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

17/08/2026 0 Comments 0 tags

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

17/08/2026 0 Comments 0 tags

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with

How MCP Servers Can Expose Enterprise Secrets

17/08/2026 0 Comments 0 tags

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

17/08/2026 0 Comments 0 tags

Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given