📡 Tech & Security Digest — 2026-08-11
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers breach TrueConf to trojanize client installers with backdoors — The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with …
- Critical Progress LoadMaster flaw now actively exploited in attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster comma…
- Metabase SQLi zero-day exploited in customer data-theft attacks — A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact …
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity se…
- OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users — OpenAI has developed a new model called “GPT 5.6 Cyber,” designed for vulnerability research, penetration testing, incident response, and remediation….
Hacker News
- Exploiting System Management Mode with a very long interrupt (151 pts)
- How Claude marks AI-generated content (103 pts)
- Exploring Claude/GPT Knowledge Cutoffs and Pre-Training Timelines (139 pts)
- Docker Sandboxes – Disposable, isolated sandboxes for AI agents (646 pts)
- Show HN: Needle2: 14MB agentic LLM for phones, wearables, smart home and robots (282 pts)
- The “mechanical miracle” that ruined Mark Twain’s life (111 pts)
- Mark Zuckerberg attacks ‘closed’ AI rivals as Meta returns to open models (469 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild — A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S…
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploit…
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors — A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting…
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster …
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore — The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian…
- AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory — A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It ab…
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch — A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured di…
- Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development — North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running a…
- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets — A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own cod…
- New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts — Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isola…