Cronos blockchain restarts after $74 million Tectonic exploit

The Cronos blockchain network has resumed trading after a price manipulation attack on the Tectonic cryptocurrency lending platform resulted in an attacker borrowing $74 million. The exploit is attributed to an attacker manipulating the price of the CRO token, which was then used to borrow an excessive amount of stablecoins.

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Microsoft has identified a bug in Windows that incorrectly reports Microsoft Defender Antivirus as turned off, despite it functioning normally. This issue affects various Windows versions and is being addressed by Microsoft, but industry experts express concern that it could train users to ignore critical security alerts, making them more vulnerable to attacks.

Is Someone Hacking DoD Refrigerators?

The Department of Defense (DoD) has confirmed refrigeration disruptions at several military commissaries, leading to speculation that these systems may have been hacked. The affected locations include installations across California, Wyoming, Arizona, Rhode Island, and Mississippi.

OpenAI confirms ChatGPT outage as users report errors

OpenAI has confirmed a partial outage affecting ChatGPT, preventing users on various subscription plans from initiating or continuing tasks. The outage is impacting users globally, with many reporting errors.

Chinese Fire Ant hackers turn Cisco routers into spying platforms

Chinese Fire Ant hackers are using Cisco routers as spying platforms by exploiting Generic Routing Encapsulation (GRE) tunnels. Researchers discovered an unexplained GRE tunnel interface on a Cisco IOS XR router, indicating a novel attack vector.

File servers are here to stay. Here’s how to manage them securely

File servers continue to be essential in IT infrastructures, but managing their access permissions securely presents challenges due to accumulation over time. tenfold Software provides five best practices to streamline file server administration and enforce least-privilege access.

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow has released patches for three critical code injection vulnerabilities. These vulnerabilities could allow attackers to execute arbitrary code, potentially leading to unauthorized data access or modification.

Boston Scientific Still Recovering From Cyberattack

Boston Scientific is still experiencing the aftermath of a cyberattack that caused significant global network disruptions. The medical device company has engaged cybersecurity firm CrowdStrike to assist in the ongoing investigation of the incident.

Microsoft asks users to ignore 'Antivirus is turned off' errors

Microsoft has advised users to disregard false "Antivirus is turned off" notifications that have appeared after installing the latest Defender updates. This issue is causing confusion for users who believe their protection is compromised when it is not.

Is your cloud security strategy ready for AI’s looming threat?

AI agents are introducing a new, faster, and more expansive threat to cloud security architectures. These autonomous agents can chain vulnerabilities and exploit misconfigurations at machine speed, making it challenging for organizations to maintain a strong cloud security posture.

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs has disclosed a critical vulnerability in the shared Cosmos EVM module that was exploited between August 20 and August 25, 2026, leading to the draining of funds from six blockchains. The flaw, identified as GHSA-7g4w-cg88-2cq2, has been rated Critical by Cosmos Labs, though it was released without a CVE or CVSS score.

GPUThor hardware attack can root Nvidia GPU systems

Researchers have developed a new hardware attack called GPUThor that exploits memory bit flipping techniques to bypass error-correcting codes (ECC) on enterprise Nvidia GPUs. This attack can lead to root access on the underlying system, improving upon previous Rowhammer-style attacks.

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Android 17 will introduce new network security features, including support for Encrypted Client Hello (ECH). ECH is a privacy standard designed to prevent network providers from monitoring which websites users visit. These updates aim to improve connection privacy and protect user data on home networks.

You Need Cyber Deception for OT

The article highlights the challenges of responding to OT cyberattacks due to a lack of data, trails, and history. It suggests that cyber deception techniques are necessary to address these gaps.

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 internet-exposed Gitea servers remain vulnerable to critical remote code execution attacks due to unpatched security flaws. Cybersecurity watchdog Shadowserver reported the ongoing exploitation of these vulnerabilities.

Key Reasons Why Identity Fabric Matters in 2026

An Identity Fabric integrates disparate identity systems to provide a unified view of identity behavior across various applications, APIs, and infrastructure. As enterprises adopt more cloud services and automated workloads, maintaining identity security increasingly relies on real-time visibility rather than static configurations.

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel has released patches for a critical security vulnerability in its cPanel and WebHost Manager (WHM) software. This flaw could allow a hosting customer to gain root control of an entire server by exploiting domain parking and addon domain functionalities. The vulnerability is assigned the CVE identifier CVE-2026-65643 and affects all supported versions.

Chinese Routers Sold Worldwide Contain Backdoors

An untold number of ZBT routers sold globally as white-label products have been found to contain several implants developed by the manufacturer. This discovery raises significant security concerns for users of these devices.

Manchester Airports Group says hackers stole travelers' data

The Manchester Airports Group (MAG) has reported a data breach resulting from a cyberattack. Hackers successfully accessed MAG's systems and exfiltrated customer data, specifically information collected during Wi-Fi sign-ups across Manchester, Stansted, and East Midlands airports.

Cleartext Credential Recovery in ServiceNow

This article details a method for recovering cleartext credentials within ServiceNow, a popular IT service management platform. It explains how script includes can be utilized to create a mechanism for retrieving any discovery or LDAP credential type.

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Vercel has released security patches for two critical vulnerabilities in the Next.js web framework. One vulnerability allows for remote code execution through specially crafted AVIF image files, while the other involves a path traversal flaw exploitable on Windows filesystems.

Schrödinger's backup: not actually recovered until you try to restore IT

This article emphasizes the critical importance of testing backups to ensure their recoverability. It highlights that a backup is only truly valuable if a successful restore can be performed, urging organizations to regularly verify their data recovery capabilities.

Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

The White House has issued a new executive order (14420) aimed at increasing scrutiny of industrial control systems within the US power grid. This order seeks to prevent foreign actors from introducing backdoors and engaging in cyber sabotage against critical energy infrastructure.

Android 17 adds ECH support to make web browsing harder to track

Android 17 is introducing new network security features, including Encrypted Client Hello (ECH) support, to enhance connection privacy and protect users from tracking during web browsing. These updates also aim to address cellular vulnerabilities and safeguard home network privacy.

Rockwell Automation OTTO Fleet Manager

A security vulnerability (CVE-2026-75112) has been identified in Rockwell Automation OTTO Fleet Manager versions less than or equal to V2.36.2. This flaw involves the use of insufficient computational effort in password hashing, making offline brute-force attacks against stored hashes easier for attackers. Successful exploitation could lead to the compromise of weakly hashed credentials if an attacker obtains an unencrypted system backup.

Xiiaozet LK100W

Xiiaozet LK100W devices running firmware version below 2.1.240 are vulnerable to multiple security flaws, including OS command injection and authentication bypass. Successful exploitation could allow an attacker to gain control over the affected devices. The vulnerabilities have a CVSS v3.1 base score of 9.8.

All-Line Equipment Company Fuel-Boss

Multiple vulnerabilities have been identified in All-Line Equipment Company's Fuel-Boss systems, specifically affecting versions running PHP 7.1.5 or earlier. Successful exploitation could allow remote attackers to execute arbitrary commands or code on affected industrial control systems.

Applied Systems Engineering ASE2000 V2 Communications Test Set

Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37 are vulnerable to XML External Entity (XXE) injection and improper certificate validation. Successful exploitation could allow attackers to read or write local files, initiate outbound network requests, or intercept and modify communications.

Ebyte NA111-M

Ebyte NA111-M devices running Firmware 9013-2-17 are affected by multiple critical vulnerabilities. These flaws, including Missing Authentication and Cross-Site Request Forgery, could allow remote attackers to fully compromise the device, leading to disruption of availability and access to sensitive information.

Mitsubishi Electric Multiple FA Products (Update D)

Mitsubishi Electric has released an update concerning multiple FA products, specifically addressing a vulnerability (CVE-2025-3511) in their CC-Link IE TSN Remote I/O modules. Successful exploitation could lead to a denial-of-service condition, timeout errors, or communication delays.

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA has issued a directive mandating U.S. federal agencies to patch a critical remote code execution (RCE) vulnerability affecting Citrix NetScaler appliances. The vulnerability is reportedly being actively exploited in the wild, and agencies must complete the patching by Saturday.

Critical infrastructure’s long, undefended tail exposed by UK energy attack

A cyberattack on a small British electricity generator, which took it offline for four days, has highlighted a significant weakness in critical infrastructure. Thousands of smaller industrial sites, including generators and water systems, have aging operational technology connected to the internet without adequate security, making them easy targets. While the initial attribution to Iran-linked hackers is unconfirmed, the incident prompted UK government engagement with energy executives to assess and strengthen protections.

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Academic researchers have revealed a new Rowhammer attack, named GPUThor, that targets NVIDIA workstation GPUs with GDDR6 memory. This attack successfully bypasses Error Correction Codes (ECC), a primary defense against GPU Rowhammer, and can lead to denial-of-service and root access on the host system.

Recent Citrix NetScaler Vulnerability Exploited in the Wild

CISA is strongly advising government agencies to promptly address a vulnerability affecting Citrix NetScaler. This vulnerability, identified as CVE-2026-8452, has reportedly been exploited in active attacks.

CVE-2023-49105: ownCloud Improper Authentication Vulnerability

ownCloud has an improper authentication vulnerability (CVE-2023-49105) that allows unauthenticated attackers to access, modify, or delete files if the victim's username is known and they lack a signing key. Organizations must apply vendor-provided mitigations and comply with CISA's BOD 26-04 guidance for prioritizing security updates.

CVE-2026-53362: Linux Kernel Unspecified Vulnerability

A significant vulnerability, CVE-2026-53362, has been identified in the Linux Kernel's IPv6 networking subsystem. This flaw allows for privilege escalation and affects numerous Linux distributions, including Suse and Red Hat. CISA has mandated that stakeholders apply mitigations according to vendor instructions and follow specific guidance on prioritizing security updates.