The best hacker and cyber security news. Contact us on
Aug 21, 2026
The Memorandum directs agencies to incentivize co-development of space transportation infrastructure with private sector partners, expedite permitting and environmental reviews, develop fair and transparent cost recovery policies for common space services and infrastructure, and develop range scheduling criteria and publish range schedules to maximize allocation of launch resources.
Source: whitehouse.gov
Aug 21, 2026
On August 18th, 2026, a data release occurred on the illicit forum pwnforums. The threat actor known as Satanic published sensitive information extracted from hundreds of vendors utilizing the Stripe payment platform. Figure 1: The initial forum post by Satanic announcing the breach, detailing the compromise of databases and 1,033 API keys, totaling 33GB, along with millions of email matches. Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach. Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach.
Aug 21, 2026
Cybersecurity researchers from TU Graz have disclosed a highly sophisticated Remote-Timer-as-a-Service side-channel execution flaw against serverless edge environments. In a controlled production test, this cloudflare workers spectre attack (a modern evolution of the foundational CVE-2017-5753 Spectre flaw) successfully leaked a JSON Web Token (JWT) from a co-located Worker at an astonishing rate of 12 bits per second (at 99.16% accuracy)—nearly 360 times faster than similar attacks demonstrated in 2021.
Aug 13, 2026
The Connective signing extension, used by 8 of the 10 largest banks in Belgium and 60+ government agencies, let any website read your eID and Maestro cards, recover your eID PIN, and trigger a drive-by RCE. All the victim sees is a file download.
Source: amibeingpwned.com
Aug 13, 2026
So…what’s going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about. But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room. For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.
Aug 13, 2026
Photo by Towfiqu barbhuiya on Unsplash
Jacob Baines, chief technology officer at security firm VulnCheck, said more than 20 models of Chinese-made Zbtlink routers ship with a hidden backdoor that hands outsiders a route onto the local network, in a finding published August 5. The implant, named ENDLESSDOORS and tracked as CVE-2026-66747 with a severity score of 9.3 out of 10, starts at boot and beacons to a fixed address and a China-registered domain as often as every 35 seconds. Whoever controls those endpoints can issue commands and open a root shell, the highest level of control on the device.
Jul 28, 2026
The US government discloses an Iranian APT compromising internet-exposed PLCs in water and energy facilities, disabling safety logic to cause potential⦠The escalation is assessed as a direct response to geopolitical tensions among Iran, the United States, and Israel. The shift from public defacement in 2023 to silent sabotage of industrial control systems marks an operational turning point with potentially physical consequences. The actors gain initial access by exploiting PLCs and OT devices directly exposed on the internet. The advisory identifies five specific ports: 44818, 2222, 102, 502 for industrial protocols, plus port 22 for SSH modems. This exposure, typical of architectures that assume “security by obscurity,” eliminates any intermediary: the attacker interacts directly with the controller.
Jul 28, 2026
Photo by Misha Feshchak on Unsplash
Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.ReliaQuest assesses this tradecraft is similar to that of âAPT28â (also known as âFancy Bearâ and âForest Blizzardâ), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all trafficâincluding DNSâthrough the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.
Jul 28, 2026
A Cold War-era law called the Invention Secrecy Act of 1951 allows U.S. government agencies to suppress patents deemed threats to national security, fueling decades of conspiracy theories about hidden world-changing inventions like the legendary “water engine.”The Invention Secrecy Act lacks clear accountability measures and vaguely defines what constitutes “national security,” making it theoretically possible for the government to suppress inventions to protect corporate interests, though no credible evidence proves this has occurred.In fiscal year 2025 alone, over 6,500 patents were subjected to secrecy orders under the act—more than half the total suppressed during all of World War II—raising questions about whether the government is applying the law too broadly.
Jul 15, 2026
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.