Vendors' News

Vendor announcements

Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog 
  

Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog 

How malicious Chrome extensions steal passwords, drain cryptocurrency wallets and display fake ClickFix instructions, and what to do if you

Defining the Standard for AI Security 
  

Defining the Standard for AI Security 

Palo Alto Networks Named a Market Shaper in 2026 September Gartner® Emerging Market Quadrant for AI Application Security — Established

Inside the Modern SOC: Defending the Cross-Environment Pivot 
  

Inside the Modern SOC: Defending the Cross-Environment Pivot 

Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS 
  

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS 

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could

From guidance to action: Security fundamentals that materially reduce risk  
  

From guidance to action: Security fundamentals that materially reduce risk  

AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take

CAPIF 5: Regional Interconnectivity in Central Asia 
  

CAPIF 5: Regional Interconnectivity in Central Asia 

Central Asia’s Internet looks very different than it did back at CAPIF 1. We trace the rise of direct regional

Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026) 
  

Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026) 

Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that

Improving email security outcomes with real-world Microsoft Defender insights 
  

Improving email security outcomes with real-world Microsoft Defender insights 

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats

AI Threat Landscape Digest: July–August 2026 
  

AI Threat Landscape Digest: July–August 2026 

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents 
  

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents 

Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and

How MSSPs Can Prove Their Value When “Nothing Happened” 
  

How MSSPs Can Prove Their Value When “Nothing Happened” 

For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business

Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution 
  

Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution 

Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts 
  

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts 

A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare’s

Atomic macOS (AMOS) Stealer Activity 
  

Atomic macOS (AMOS) Stealer Activity 

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block

NightEagle targets Russian companies 
  

NightEagle targets Russian companies 

Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on

Latest

RatHat Turns Android Accessibility Into an Attack Weapon
 

RatHat Turns Android Accessibility Into an Attack Weapon

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones.

RatHat Turns Android Accessibility Into an Attack Weapon

RatHat Turns Android Accessibility Into an Attack Weapon

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones.

Bank of Japan rate hike exposes cracks in Bessent’s facade

Bank of Japan rate hike exposes cracks in Bessent’s facade

TOKYO – Two words sprang to mind when the Bank of Japan lifted its policy rate to a 31-year high

AI consciousness shaping into next great societal divide

AI consciousness shaping into next great societal divide

The debate about AI consciousness is growing, in academic articles, newspaper opinion pieces, and even among AI bots themselves. I doubt this is

Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog 

Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog 

How malicious Chrome extensions steal passwords, drain cryptocurrency wallets and display fake ClickFix instructions, and what to do if you

As Big Tech Takes Over Hollywood, the Picture Onscreen Gets Darker

As Big Tech Takes Over Hollywood, the Picture Onscreen Gets Darker

“The Social Reckoning” and other movies reflect growing discontent with Silicon Valley founders. But such films may be at the

ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response 
  

ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response 

Speed and clarity are the ultimate advantages for modern SOC teams. The integration of ANY.RUN into SentinelOne delivers exactly that.

What Indicators Miss: Geo-Aware Malware and Two Hidden Backdoors 
  

What Indicators Miss: Geo-Aware Malware and Two Hidden Backdoors 

// VMRAY LABS · THREAT RESEARCH What indicators miss: geo-aware malware and two hidden backdoors Executive summary A file hash

Boost Engagement with Free Passkeys by Wordfence 
  

Boost Engagement with Free Passkeys by Wordfence 

Wordfence 9 introduces passkeys, and passkeys provide a huge friction reduction because your user no longer has to remember their

Cisco Delivers Trusted AI at Scale Through New Splunk Advancements 
  

Cisco Delivers Trusted AI at Scale Through New Splunk Advancements 

Cisco delivers new Splunk innovations that give customers the ability to safely and cost-efficiently scale AI wherever their data already

August 2026 Detection Highlights: Stronger Phishing Detection, 7 New VTIs, and 50+ YARA Rules 
  

August 2026 Detection Highlights: Stronger Phishing Detection, 7 New VTIs, and 50+ YARA Rules 

The Labs team at VMRay actively gathers publicly available data to identify any noteworthy malware developments that demand immediate attention.

Have it both ways: stay discoverable in search while disallowing AI training 
  

Have it both ways: stay discoverable in search while disallowing AI training 

Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation

Give every teammate and agent the right level of access to your Workers 
  

Give every teammate and agent the right level of access to your Workers 

You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents

6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs 
  

6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs 

ANY.RUN has released its H1 Cyber Risk Report, built on unique data from real-world submissions analyzed in the ANY.RUN Interactive

Protecting your smart TV and set-top box from hacking | Kaspersky official blog 
  

Protecting your smart TV and set-top box from hacking | Kaspersky official blog 

How cybercriminals recruit household appliances, and how to keep malware and malicious proxies off your home network.Kaspersky official blogRead More

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin 
  

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin 

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a

Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin 
  

Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin 

On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical

FedRAMP Moderate Authorization for Palo Alto Networks’ Quantum-Safe Security 
  

FedRAMP Moderate Authorization for Palo Alto Networks’ Quantum-Safe Security 

Palo Alto Networks has achieved FedRAMP Moderate authorization for Quantum-Safe Security (QSS), a turnkey Automated Cryptography Discovery and Inventory (ACDI)

Wordfence Bug Bounty Program Monthly Report – May 2026 
  

Wordfence Bug Bounty Program Monthly Report – May 2026 

In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working

14th September – Threat Intelligence Report 
  

14th September – Threat Intelligence Report 

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP

Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection 
  

Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection 

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard

Introducing automatic remediation policies with Cloudflare CASB 
  

Introducing automatic remediation policies with Cloudflare CASB 

Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically.

ChatGPT Computer History: the risks and a safe setup | Kaspersky official blog 
  

ChatGPT Computer History: the risks and a safe setup | Kaspersky official blog 

How ChatGPT tracks everything you do on your Mac, where your data ends up, and how to protect yourself from

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026) 
  

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026) 

Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were

Palo Alto Networks Named a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall 
  

Palo Alto Networks Named a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall 

Securing Every Environment at the Speed of Frontier AI Recognized as a Leader for the second consecutive time and positioned

Detect and disrupt AI-themed attacks with Microsoft Defender 
  

Detect and disrupt AI-themed attacks with Microsoft Defender 

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect

Protecting organizations from AI-assisted executive impersonation and invoice fraud 
  

Protecting organizations from AI-assisted executive impersonation and invoice fraud 

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with

Secure AI Coding: Governing every agent, artifact, and identity 
  

Secure AI Coding: Governing every agent, artifact, and identity 

Enterprises are seeing an unprecedented surge in AI coding adoption with spend on AI coding tools projected to top $13

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector 
  

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector 

Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English

  

Introducing AI Assistant for Akamai Web Security Analytics 

Discover how AI Assistant for Akamai Web Security Analytics helps SOC and AppSec teams investigate events faster and take guided

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it 
  

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it 

1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks

The /3 Body Problem 
  

The /3 Body Problem 

A large chunk of IPv6 is heading for space, and every policy question about it is currently going to be

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE 
  

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE 

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located

ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings 
  

ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings 

We’re excited to share that ANY.RUN has once again been recognized by G2 as a leader in malware analysis. In

Threat Matrix: Mapping threats across cloud web applications 
  

Threat Matrix: Mapping threats across cloud web applications 

Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats

Passkey-themed social engineering leads to identity and cloud compromise 
  

Passkey-themed social engineering leads to identity and cloud compromise 

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA

  

NIS2 Compliance in the AI Age: Why Traditional Cybersecurity Isn’t Enough 

Discover why achieving NIS2 compliance is more challenging in the AI age, the four key challenges organizations face, and why

How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility 
  

How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility 

Workers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with

How to completely uninstall apps on Mac and free up storage | Kaspersky official blog 
  

How to completely uninstall apps on Mac and free up storage | Kaspersky official blog 

Learn how to fully remove apps from your Mac, including cache, settings, and other leftover files, and free up disk

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure 
  

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure 

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days 
  

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days 

Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been

15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN 
  

15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN 

Security teams in the manufacturing sector face persistent operational demands. Recent ANY.RUN data shows their workloads are roughly 22% higher

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT 
  

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT 

Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation.

PolarProxy 2.0.2 Released 
  

PolarProxy 2.0.2 Released 

A few more handy features have been added to PolarProxy, our TLS inspection proxy. PolarProxy can now tunnel outgoing connections

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting) 
  

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting) 

Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with

A human approach to making cybersecurity stronger 
  

A human approach to making cybersecurity stronger 

One of my first cybersecurity roles focused on awareness and it taught me that cybersecurity is as much about behaviour,

HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures 
  

HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures 

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn

The Internet’s New Edge Builders 
  

The Internet’s New Edge Builders 

After building private backbones, content and cloud platforms are now moving closer to users. In doing so, they are taking

7th September – Threat Intelligence Report 
  

7th September – Threat Intelligence Report 

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP

How to secure edge AI in customer-owned environments 
  

How to secure edge AI in customer-owned environments 

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust

Silicon: The Element Behind Everything 
  

Silicon: The Element Behind Everything 

Explore the technology and systems that power modern life in a new video series on Cisco Story Lab. More RSS

Hacking the Boeing 737: inside the Bus Driver attack | Kaspersky official blog 
  

Hacking the Boeing 737: inside the Bus Driver attack | Kaspersky official blog 

Researchers have found a way to hack Boeing 737 systems with a device that costs less than US$100. Here’s how

Closing the IPv6 First-Packet Gap with GRAND 
  

Closing the IPv6 First-Packet Gap with GRAND 

There is a subtle asymmetry in IPv6 Neighbour Discovery: a host knows how to reach its router before the router

Angry Birds: Toy Ghouls’ new toys 
  

Angry Birds: Toy Ghouls’ new toys 

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models 
  

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models 

Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin 
  

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin 

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026) 
  

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026) 

Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were

ASCII smuggling crosses over from AI prompt injection to phishing evasion 
  

ASCII smuggling crosses over from AI prompt injection to phishing evasion 

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters

Irish Privacy Watchdog Details Psychiatric Data Breaches 
  

Irish Privacy Watchdog Details Psychiatric Data Breaches 

In a new article published on Data Breach Today, BH Consulting CEO Brian Honan discusses the enduring risks associated with

Security Roundup August 2026 
  

Security Roundup August 2026 

Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. Sound the AI-larm This summer,

When Traceroutes Lie: How TTL Jumps Can Give Us a False Impression of the Internet’s Topology 
  

When Traceroutes Lie: How TTL Jumps Can Give Us a False Impression of the Internet’s Topology 

Traceroute is a powerful tool for uncovering how packets travel across the Internet. However, as we recently discovered, some routers

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates 
  

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates 

Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America 
  

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America 

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access 
  

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access 

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote

Summer 2024 weather report: Cloudflare with a chance of Intern-ets 
  

Summer 2024 weather report: Cloudflare with a chance of Intern-ets 

This summer, Cloudflare welcomed approximately 60 interns from all around the globe, on a mission to #HelpBuildABetterInternet. Join us as

  

Your DNS Is Hiding in HTTPS — This Is Why It Matters 

Discover why unmanaged DNS over HTTPS (DoH) creates security visibility gaps and how a controlled DoH strategy restores visibility without

Building Securely From Day One: Palo Alto Networks Partners with the Zendesk Startup Program 
  

Building Securely From Day One: Palo Alto Networks Partners with the Zendesk Startup Program 

A secure workspace for your team – so you can focus on building, not on what could go wrong. Every

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin 
  

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin 

On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin

Getting AI for schoolwork right: 25 helpful prompts + usage tips | Kaspersky official blog 
  

Getting AI for schoolwork right: 25 helpful prompts + usage tips | Kaspersky official blog 

How to teach your kid to use chatbots for schoolwork without just copying answers, how to fact-check AI responses, and

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon 
  

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon 

Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation 
  

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation 

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and

Bridging the Gap Between Theory and Practice in Internet Operations 
  

Bridging the Gap Between Theory and Practice in Internet Operations 

Internet research can benefit from operational insight, and network operators from research expertise. Building on what we learned at RIPE

Triage & Response Bottlenecks Eating into MSSP Margins: How to Remove the Friction 
  

Triage & Response Bottlenecks Eating into MSSP Margins: How to Remove the Friction 

As MSSPs take on more clients, alert volumes grow fast. Analyst capacity usually doesn’t. That gap shows up in triage

Counterfeit installers to system compromise: Tracking a deceptive software download campaign 
  

Counterfeit installers to system compromise: Tracking a deceptive software download campaign 

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft

Cybersecurity IR Workshop: The workshop you shouldn’t miss 
  

Cybersecurity IR Workshop: The workshop you shouldn’t miss 

Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR

Making the Most of the Cloud Marketplace Opportunity 
  

Making the Most of the Cloud Marketplace Opportunity 

How Partners Can Turn Marketplace Momentum into Customer Value. Cloud marketplaces have become an increasingly important way for customers to

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms 
  

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms 

On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin 
  

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin 

On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and

Pivoting in MISP: From Individual Indicators to Broader Threat Context 
  

Pivoting in MISP: From Individual Indicators to Broader Threat Context 

In the first post, we set up VMRay UniqueSignal as a feed in MISP. In the second post, we looked at how a SOC

How we could save petabytes of cache storage with Zstandard and Pingora 
  

How we could save petabytes of cache storage with Zstandard and Pingora 

Could we get more cache space with the same hardware? We prototyped compression inside Cloudflare’s cache to find out.Cloudflare BlogRead

The IRR Landscape: What RPKI Can Replace 
  

The IRR Landscape: What RPKI Can Replace 

In the third part of our IRR landscape series, we use traffic measurements from AMS-IX and DE-CIX to assess which

Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk 
  

Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk 

August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set 
  

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set 

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.SecurelistRead

This Android malware steals banking credentials even without an internet connection | Kaspersky official blog 
  

This Android malware steals banking credentials even without an internet connection | Kaspersky official blog 

How the Manic Trojan steals passwords, banking credentials and SMS codes, takes control of Android phones, and relays stolen information

Introducing Adaptive Intelligence: undermining the economics of every bot attack 
  

Introducing Adaptive Intelligence: undermining the economics of every bot attack 

Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare’s new

  

31th August – Threat Intelligence Report 

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode 
  

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode 

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled

OT Networks Still Need Monitoring 
  

OT Networks Still Need Monitoring 

CERT Polska recently published a follow-up report detailing the hack of a Polish combined heat and power (CHP) plant in

ValleyRAT masquerading as adware 
  

ValleyRAT masquerading as adware 

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams 
  

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams 

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

TerminalFix campaign deploys a reverse tunnel through multistage intrusion 
  

TerminalFix campaign deploys a reverse tunnel through multistage intrusion 

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel,

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety 
  

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety 

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered

Detection blind spots: non-standard file formats in malicious email campaigns | Kaspersky official blog 
  

Detection blind spots: non-standard file formats in malicious email campaigns | Kaspersky official blog 

Disk images, atypical Office files, vector graphics, polyglots, and other techniques for covertly launching malware, as seen in real-world cyberattacks.Kaspersky

The Good, the Bad and the Ugly in Cybersecurity – Week 35 
  

The Good, the Bad and the Ugly in Cybersecurity – Week 35 

Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.SentinelOneRead More

BotBase for Operators: A clearer path to joining Cloudflare’s directory of bots and agents 
  

BotBase for Operators: A clearer path to joining Cloudflare’s directory of bots and agents 

Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission

Wordfence Argus: Moving Beyond Human Research Capability 
  

Wordfence Argus: Moving Beyond Human Research Capability 

When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to

​​​​​​What’s new in Microsoft Security: August 2026 
  

​​​​​​What’s new in Microsoft Security: August 2026 

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments,

How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache 
  

How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache 

Five Rust-level memory optimizations to the DNS cache layout of Big Pineapple cut per-entry memory by 56%, freeing approximately 100