Sep. 3, 2026
Photo by Markus Winkler on Unsplash
Researchers affiliated with the University of Massachusetts Amherst have found that you can get payments out of certain expired contactless credit cards, a process detailed at the recent USENIX Security 2026 conference. Credit cards, the authors explain in their paper, have expiration dates, but the way these dates get checked and enforced isn’t consistent. Thus, they were able to devise an attack that makes expired contactless cards appear to be valid to payment terminals.
Sep. 3, 2026
Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, academics, government officials, think-tank analysts, and defense sector personnel across Europe and the United States. The three clusters are tracked as UNC6293, UNC7005, and UNC5976, and while they operate differently and with different tools, Google published them together for a reason.
Aug. 27, 2026
Photo by Pawel Czerwinski on Unsplash
Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page.
Source: blog.laserphile.com
Aug. 27, 2026
We dive into the decentralized architecture of “The Com,” exposing its hybrid ecosystem of hacking, extortion, and real-life violence. The Community, more widely known as “The Com” is a sophisticated hybrid threat ecosystem in which cybercrime serves as the venture capital for domestic terrorism. Existing since the early 2010s, it operates in the “edgesphere”, a grey area where mainstream social media overlaps with underground criminal networks, blending nihilistic violent extremism (NVE) with high-level financial fraud. In The Com, cybercrime against Fortune 500 companies is the primary revenue stream used by members to fund a domestic terror network that aims to radicalize youth and encourage real-world violence.
Aug. 27, 2026
Photo by Boitumelo on Unsplash
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit - EU IRU and the Spanish Intelligence Centre against Terrorism and Organised Crime (CITCO). This successful action complements the efforts undertaken within Project COMPASS, coordinated by Europol’s European Counter Terrorism Centre, which unites law enforcement authorities from EU…
Source: europol.europa.eu
Aug. 27, 2026
The FBI is warning the public about Hacker Com, one of three subsets of the growing and evolving online threat group known as The Com, short for The Community, a primarily English speaking, international, online ecosystem comprised of multiple interconnected networks whose members, many of whom are minors, engage in a variety of criminal violations.
Source: fbi.gov
Aug. 23, 2026
Photo by Luca Cavallin on Unsplash
Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan. Even as the digital components of so many life-critical systems have proven susceptible to cybersabotage—cars, medical devices, even water utilities and power grids—the computer systems of airplanes have, thankfully, remained uniquely inaccessible to hackers. But one group of academic researchers has spent years testing a different, devious approach to aviation cybersecurity. Perhaps, they suggest, a plane could be hacked the same way that spies and saboteurs have targeted other high-value, offline computers: by surreptitiously gaining physical access to one and plugging in a device designed to silently run the attackers’ malicious code.
Aug. 21, 2026
The Memorandum directs agencies to incentivize co-development of space transportation infrastructure with private sector partners, expedite permitting and environmental reviews, develop fair and transparent cost recovery policies for common space services and infrastructure, and develop range scheduling criteria and publish range schedules to maximize allocation of launch resources.
Source: whitehouse.gov
Aug. 21, 2026
On August 18th, 2026, a data release occurred on the illicit forum pwnforums. The threat actor known as Satanic published sensitive information extracted from hundreds of vendors utilizing the Stripe payment platform. Figure 1: The initial forum post by Satanic announcing the breach, detailing the compromise of databases and 1,033 API keys, totaling 33GB, along with millions of email matches. Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach. Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach.
Aug. 21, 2026
Cybersecurity researchers from TU Graz have disclosed a highly sophisticated Remote-Timer-as-a-Service side-channel execution flaw against serverless edge environments. In a controlled production test, this cloudflare workers spectre attack (a modern evolution of the foundational CVE-2017-5753 Spectre flaw) successfully leaked a JSON Web Token (JWT) from a co-located Worker at an astonishing rate of 12 bits per second (at 99.16% accuracy)—nearly 360 times faster than similar attacks demonstrated in 2021.
Aug. 13, 2026
The Connective signing extension, used by 8 of the 10 largest banks in Belgium and 60+ government agencies, let any website read your eID and Maestro cards, recover your eID PIN, and trigger a drive-by RCE. All the victim sees is a file download.
Source: amibeingpwned.com
Aug. 13, 2026
So…what’s going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about. But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room. For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.
Aug. 13, 2026
Photo by Towfiqu barbhuiya on Unsplash
Jacob Baines, chief technology officer at security firm VulnCheck, said more than 20 models of Chinese-made Zbtlink routers ship with a hidden backdoor that hands outsiders a route onto the local network, in a finding published August 5. The implant, named ENDLESSDOORS and tracked as CVE-2026-66747 with a severity score of 9.3 out of 10, starts at boot and beacons to a fixed address and a China-registered domain as often as every 35 seconds. Whoever controls those endpoints can issue commands and open a root shell, the highest level of control on the device.
Jul. 28, 2026
The US government discloses an Iranian APT compromising internet-exposed PLCs in water and energy facilities, disabling safety logic to cause potential⦠The escalation is assessed as a direct response to geopolitical tensions among Iran, the United States, and Israel. The shift from public defacement in 2023 to silent sabotage of industrial control systems marks an operational turning point with potentially physical consequences. The actors gain initial access by exploiting PLCs and OT devices directly exposed on the internet. The advisory identifies five specific ports: 44818, 2222, 102, 502 for industrial protocols, plus port 22 for SSH modems. This exposure, typical of architectures that assume “security by obscurity,” eliminates any intermediary: the attacker interacts directly with the controller.
Jul. 28, 2026
Photo by Misha Feshchak on Unsplash
Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.ReliaQuest assesses this tradecraft is similar to that of âAPT28â (also known as âFancy Bearâ and âForest Blizzardâ), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all trafficâincluding DNSâthrough the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.
Jul. 28, 2026
A Cold War-era law called the Invention Secrecy Act of 1951 allows U.S. government agencies to suppress patents deemed threats to national security, fueling decades of conspiracy theories about hidden world-changing inventions like the legendary “water engine.”The Invention Secrecy Act lacks clear accountability measures and vaguely defines what constitutes “national security,” making it theoretically possible for the government to suppress inventions to protect corporate interests, though no credible evidence proves this has occurred.In fiscal year 2025 alone, over 6,500 patents were subjected to secrecy orders under the act—more than half the total suppressed during all of World War II—raising questions about whether the government is applying the law too broadly.
Jul. 15, 2026
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.
Jul. 15, 2026
Microsoft has confirmed the existence of a persistent Windows device identifier called GDID, first publicly detailed in an FBI federal complaint against an alleged hacker. Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group. The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.
Jun. 30, 2026
Cannabis Club Systems, also known as Nefos Solutions, left passports and photo IDs potentially exposed on the public web.Nearly a million passports and photo IDs were left unprotected on the public internetThis should be a wakeup call for data security.
Source: theverge.com
Jun. 29, 2026
Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees.
Source: arstechnica.com