📡 Tech & Security Digest — 2026-08-10
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers breach TrueConf to trojanize client installers with backdoors — The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with …
- Metabase SQLi zero-day exploited in customer data-theft attacks — A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact …
- Meta AI model hacked a company during misconfigured cyber test — Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents …
- Swiss government SharePoint breach compromised 200 accounts — Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 ac…
Hacker News
- The Hacker’s Renaissance (2025) (109 pts)
- What Happened to HackerOne? (165 pts)
- Docker Sandboxes – Disposable, isolated sandboxes for AI agents (61 pts)
- Auto mode is now the default in Claude Code (151 pts)
- Show HN: Voice driven murder mystery, Interview AI suspects with your voice (53 pts)
- How I use LLMs to learn complex topics (588 pts)
- The tragedy of the commons, AI edition (110 pts)
- Tuxedo No. 2 – Cocktail recipes (82 pts)
- The main way I’ve seen people turn ideologically crazy (2025) (110 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild — A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S…
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploit…
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster …
- AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory — A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It ab…
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch — A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured di…
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself — An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber eval…
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) ca…
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN)…
- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets — A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own cod…
- New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts — Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isola…