📡 Tech & Security Digest — 2026-08-04
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- N-able warns of N-central auth bypass flaw exploited in attacks — N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises …
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts — Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. […]…
- Rails patches critical Active Storage flaw with RCE potential — A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and p…
Hacker News
- SQLite Critical CVEs or LLM Slop? (708 pts)
- AirLLM 70B inference with single 4GB GPU (217 pts)
- They Forgot What Happened Last Time: Hacking the Windows 365 Link [video] (48 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm — Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tr…
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts — South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers u…
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation — The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerabi…
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Mana…
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known…
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories — A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or…
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Ma…
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and Open…
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws — The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Ac…
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database — A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write ac…