📡 Tech & Security Digest — 2026-08-06
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- Thousands of servers can be backdoored by exploiting buggy motherboard controllers — Baseboard management controllers from the world’s biggest manufacturers are a security mess. …
BleepingComputer
- COLDCARD security audit phishing attack installs remote access tool — A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to …
- Hackers run khunt post-exploitation toolkit from Oracle database — Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a co…
- TP-Link patches Omada ZTP flaws allowing hackers to breach networks — TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previous…
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central…
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts — Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. […]…
- OpenAI, Anthropic AI agents targeted real people and systems in cyber tests — OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that r…
- How AI-powered phishing killed blocklists for good — AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Securit…
Hacker News
- Born Against, or why hobby programming communities are against LLM usage (246 pts)
- Proxmox VE now available for ARM64 (63 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm — Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tr…
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known…
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories — A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or…
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch — A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured di…
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself — An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber eval…
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws — The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Ac…
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database — A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write ac…
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) ca…
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN)…
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction — Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation…