A new type of malware known as WindRelay is being used in conjunction with the SpyNote Remote Access Trojan (RAT) to execute live-call scams. This combination allows fraudsters to clone credit cards during phone calls, posing a significant risk to unsuspecting victims. The attackers can manipulate information in real-time, making it easier for them to deceive individuals and potentially steal their financial information. This incident serves as a reminder for users to be cautious during phone conversations, especially when discussing sensitive information. Awareness and vigilance are key to preventing falling victim to such scams.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The FBI has issued a warning regarding a growing trend where hackers are targeting social media and online accounts of both adults and children to steal explicit images and videos. These cybercriminals use various tactics to gain access to accounts, raising concerns about the safety and privacy of users online. The stolen content can be used for blackmail or shared publicly, which can have severe emotional and psychological impacts on the victims. This incident is particularly alarming given the increasing prevalence of such cyber crimes, especially as more people share personal content online. Users are urged to enhance their account security by using strong passwords and enabling two-factor authentication to protect their private information from these malicious actors.
SCM feed for Latest
Researchers recently identified vulnerabilities in Zoom's screenshare annotation feature that could allow attackers to execute remote code on devices of meeting participants. These flaws were uncovered with the help of AI tools, which indicates a growing trend of using advanced technology in security research. Users of Zoom, particularly those who frequently use the screenshare feature, are at risk. If exploited, these vulnerabilities could lead to unauthorized access to sensitive information or control over user devices. It's crucial for Zoom to address these flaws promptly to protect their users and maintain trust in their platform.
Help Net Security
For the past 17 months, an unknown individual has been accessing Salesforce and ServiceNow portals worldwide, according to researchers from Reco who are tracking this ongoing campaign dubbed 'City-Forum.' The campaign began using a domain that was registered back in 2002 but has since been linked to a generic server hosted in Germany. This unauthorized access has allowed the attacker to pull sensitive records from these widely used platforms, which could potentially compromise the data of numerous organizations. This situation raises serious concerns about the security measures in place for cloud-based services and highlights the need for companies to review their access controls and monitoring practices to protect against such long-term intrusions.
Signal has rolled out a new feature called automatic key verification to enhance the security of its encrypted messaging service. This feature allows users to easily confirm that their chats haven't been tampered with by any unauthorized parties. Signal, known for its strong end-to-end encryption, aims to give users peace of mind by streamlining the verification process. According to Signal engineer Katherine Yen, this mechanism helps ensure that no unexpected entities are intercepting conversations, bolstering user privacy and trust in the platform. As more people rely on secure messaging, such enhancements are crucial for maintaining confidentiality in digital communications.
Bitdefender has reported a concerning trend where fake downloads of the movie 'The Odyssey' are being used to spread Lumma Stealer malware. These downloads are disguised as scene releases, featuring .exe files that are made to look like VLC media player icons. Users attempting to download the movie may unknowingly install this malicious software, which can steal sensitive information. This situation poses a significant risk, particularly for those looking for free downloads of popular media. It serves as a reminder for users to exercise caution and verify the legitimacy of files before downloading them.
SecurityWeek
Researchers have discovered a new campaign dubbed 'City-Forum' that targets Salesforce and ServiceNow platforms. This attack takes advantage of unauthenticated guest access to silently gather and extract sensitive data from these services. The attackers use a specialized toolset to carry out their operations, which raises concerns about the security of user information on these widely used platforms. Since Salesforce and ServiceNow host critical business data for many organizations, this incident could have serious implications for data privacy and security. Companies using these platforms are urged to review their access controls and security measures to prevent unauthorized data access.
A recent report from Picus Labs reveals that while enterprise defenses are performing well against noisy attacks, they are struggling against more subtle, stealthy tactics used by attackers. Analyzing over 338 million real attack simulations in early 2026, the report shows that many defenses are tuned to detect loud, obvious threats, allowing quieter attacks to slip through unnoticed. This trend raises concerns for businesses, as it indicates that organizations may be overconfident in their security measures, potentially leaving them vulnerable to sophisticated intrusions. The findings suggest that companies need to reassess their security strategies to address these less visible threats, which could lead to significant breaches if not managed properly.
Ceva Logistics has faced a cyberattack that has disrupted operations at eight of its warehouses across Europe. This incident has resulted in shipment delays for several customers, impacting their supply chain processes. The attack highlights the vulnerabilities that logistics companies face in an increasingly digital world, where cyber threats can have significant real-world consequences. Customers relying on Ceva for timely deliveries may experience further delays as the company works to restore normal operations. This incident serves as a reminder for businesses to bolster their cybersecurity measures to protect against similar attacks.
Adobe has released important security updates to address multiple critical vulnerabilities affecting its ColdFusion, Commerce, and Campaign Classic products. Among these, the most serious is a command injection flaw in ColdFusion, identified as CVE-2026-48362, which has a maximum severity score of 10.0 on the CVSS scale. If exploited, this vulnerability could allow attackers to execute arbitrary code on affected systems, leading to potential privilege escalation. This is particularly concerning for organizations that rely on these Adobe products, as successful exploitation could compromise sensitive data and system integrity. Users are strongly advised to apply the latest patches to mitigate these risks.
Intel has announced the discovery of several high-severity vulnerabilities that could allow attackers to escalate privileges and execute arbitrary code on affected systems. The vulnerabilities affect a range of Intel products, posing significant risks to users and organizations relying on these technologies. In total, both Intel and AMD have fixed over 80 vulnerabilities combined, indicating a widespread issue within the chipmaking industry. Users are urged to apply the latest patches to safeguard their systems against potential exploitation. This situation underscores the need for continuous vigilance and prompt action in maintaining cybersecurity.
A new zero-day exploit called 'ShieldBreak' has been released by Nightmare Eclipse, targeting Microsoft Defender. This vulnerability grants attackers SYSTEM privileges, potentially allowing them to take full control of affected systems. Users and organizations running Microsoft Defender should be particularly vigilant, especially since this exploit emerged shortly after the August 2026 Patch Tuesday updates. The existence of such a vulnerability is concerning as it can lead to significant security breaches if not addressed promptly. Companies need to ensure their systems are up to date and monitor for any unusual activity that could indicate exploitation.
Schneier on Security
Researchers from Tracebit have discovered a method called 'context bombing' that can effectively counteract AI hacking attempts. By placing prompt injections alongside sensitive data like passwords and cryptographic keys on Amazon Web Services, attackers can be directed to issue forbidden commands to AI models. When these commands, such as requests for dangerous information or politically sensitive references, are encountered, the AI stops following its original instructions and shuts down. This finding is significant as it offers a new defensive strategy against potential AI-driven attacks, which raises concerns about the misuse of AI technologies. The research suggests that understanding and manipulating AI's guardrails can be a potential avenue for both attackers and defenders in the cybersecurity realm.
Help Net Security
In August 2026, Microsoft released patches addressing over 400 vulnerabilities, including a serious zero-day exploit identified as CVE-2026-68820. This particular flaw is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), which could allow a low-privileged local attacker to gain elevated privileges to the SYSTEM level. This means that attackers with local access could potentially execute malicious applications to take control of affected systems. The urgency of this update is underscored by the fact that the vulnerability is already being exploited in the wild. Users and organizations relying on Windows systems should prioritize applying these updates to mitigate potential risks.
The Hacker News
Recent research from QUIRSO reveals that attackers are exploiting a severe vulnerability in Broadcom's VMware vCenter, identified as CVE-2026-59310, which has a CVSS score of 9.8. This directory-traversal flaw allows malicious users with network access to execute arbitrary code on the server, creating a significant risk for organizations using this software. The vulnerability is particularly concerning because it enables persistent remote access, potentially compromising sensitive systems. VMware has issued patches to address this flaw, but organizations must act quickly to implement them to protect against active exploitation. This incident serves as a reminder of the importance of timely updates in cybersecurity management.