The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced that hackers are exploiting two vulnerabilities, CVE-2026-72529 and CVE-2026-72530, in the TrueConf Server video conferencing software, and has added these flaws to its list of actively exploited vulnerabilities.
Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Cyber Dispatch™️
Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Alibaba's anti-abuse scripts use a fingerprinting technique with a hidden audio graph on the homepage — a sawtooth tone pushed through the browser's audio engine, then measured on the way out. CPU, OS and browser each process it slightly differently, and that variation results in a fingerprint they can track you with.
Frequent Power Outages Reduce the Resilience of Mobile Networks
The ongoing power outages have highlighted the weakness of the backup batteries at BTS (Base Transceiver Station) sites more than ever. In some sites, outdated batteries can no longer sustain the communication equipment for a sufficient period, and when the power goes out, the mobile antenna becomes unavailable after only a few minutes.
The ongoing power outages have highlighted the weakness of the backup batteries at BTS (Base Transceiver Station) sites more than ever. In some sites, outdated batteries can no longer sustain the communication equipment for a sufficient period, and when the power goes out, the mobile antenna becomes unavailable after only a few minutes.
Researchers at the Guangdong Academy of Aerospace Technology in China have developed a star-based navigation system for hypersonic flights, which can determine the aircraft's trajectory and position even if GPS and the BeiDou system are disrupted. This project has recently passed its final evaluation by experts.
Android car head units are getting malware through built-in updaters.
Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Five CVSS 10.0 flaws affect Cisco Crosswork and Secure Workload.
They’re among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.
They’re among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.
Attackers are exploiting a GitLab flaw days after disclosure.
CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.
CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.
Attackers can weaponize Defender’s own signed driver to delete security software at boot.
BTR.sys runs from Ring 0 before Defender’s user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
BTR.sys runs from Ring 0 before Defender’s user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
A CVSS 10.0 Entra ID flaw was exploited in the wild.
CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.
Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.
Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Rust supply chain attack hits three crates, including 245 million-download arrayref.
A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
Critical NetScaler flaw can bypass authentication on certain Gateway and AAA configurations.
Citrix patched CVE-2026-19490 (CVSS 9.3). Exposure depends on the NetScaler version and configuration, with SAML required in some cases.
Citrix patched CVE-2026-19490 (CVSS 9.3). Exposure depends on the NetScaler version and configuration, with SAML required in some cases.
Attackers are exploiting a Zimbra flaw that can lead to unauthenticated RCE.
CVE-2026-73570 affects ZCS before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled. Crafted SMTP requests may execute OS commands as the Zimbra user.
CVE-2026-73570 affects ZCS before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled. Crafted SMTP requests may execute OS commands as the Zimbra user.
Expired Visa payment cards can be revived for real purchases.
New “Zombie Card” attack rewrites the expiry date a contactless terminal reads over NFC, while the card’s cryptography still validates.
New “Zombie Card” attack rewrites the expiry date a contactless terminal reads over NFC, while the card’s cryptography still validates.
Manic can exfiltrate data even when a phone is offline.
New Manic Android malware uses nearby infected devices as C2 relays, with four hops by default. It targets 169 apps and can capture PINs, one-time codes, messages, files, and location data.
New Manic Android malware uses nearby infected devices as C2 relays, with four hops by default. It targets 169 apps and can capture PINs, one-time codes, messages, files, and location data.
NASA AIT-GUI could let unauthenticated attackers issue spacecraft commands.
The operator console also exposed script and sequence execution, while malicious web pages could reach command routes through cross-origin POST requests.
The operator console also exposed script and sequence execution, while malicious web pages could reach command routes through cross-origin POST requests.
ToxicPanda and GoldDigger are moving beyond credential theft.
ToxicPanda 2.0 adds 167 remote commands, PIN harvesting, lock-screen credential replacement, and shell access. GoldDigger can control banking apps, view screens live, and initiate fraudulent transactions.
ToxicPanda 2.0 adds 167 remote commands, PIN harvesting, lock-screen credential replacement, and shell access. GoldDigger can control banking apps, view screens live, and initiate fraudulent transactions.
14 npm packages drop RedC2 4.0 on Linux.
The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
40 Firefox extensions pose as Web3 products to steal wallet secrets.
They impersonate OKX, Rabby Wallet, TronLink and others, capturing recovery phrases, private keys, keyrings, credentials or clipboard data. Some began as sports or utility add-ons.
They impersonate OKX, Rabby Wallet, TronLink and others, capturing recovery phrases, private keys, keyrings, credentials or clipboard data. Some began as sports or utility add-ons.
Unauthenticated attackers could turn Elementor Pro uploads into RCE.
CVE-2026-32475 lets an attacker skip the file-extension blocklist and upload PHP when a published Form widget has a File Upload field. Elementor fixed it in 4.2.2.
CVE-2026-32475 lets an attacker skip the file-extension blocklist and upload PHP when a published Form widget has a File Upload field. Elementor fixed it in 4.2.2.
A Spectre attack leaked a JWT from a co-located Cloudflare Worker.
Researchers demonstrated the attack in Cloudflare’s production environment at up to 12 bits/second, 360× faster than the 2021 result. No customer data was accessed.
Researchers demonstrated the attack in Cloudflare’s production environment at up to 12 bits/second, 360× faster than the 2021 result. No customer data was accessed.