CyberNews

Cybersecurity News Dashboard

Showing 11–20 of 268 articles
NEWS The Hacker News

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client - The Hacker News

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it had happened. The patches are not new. Client fixes shipped in June and July, roughly two months before the flaws were made public, and no exploitation has been reported as of publication. None of the three identifiers appear in CISA's Known Exploited Vulnerabilities catalog. The research came from "A Security," an Israeli-founded offensive-security startup that left stealth in June with $37 million in funding. It says it went from finding the flaw to a working exploit in under a day, using fewer than 20 prompts on publicly available AI models.

Aug 11, 2026, 07:08 PM Read more →
NEWS The Hacker News

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

Aug 11, 2026, 06:36 PM Read more →
NEWS BleepingComputer

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. ​The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers or aircraft operating systems. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said. “One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight.” After learning about the unauthorized wireless network, the cabin crew deactivated the Wi-Fi functionality in the aircraft for nearly 30 minutes.

Aug 11, 2026, 06:34 PM Read more →
NEWS BleepingComputer

Windows 10 KB5120249 cumulative update released with fixes

Microsoft has released the Windows 10 KB5120249 Extended Security Updates (ESU) for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. Today's update is mandatory as it contains the August 2026 Patch Tuesday security updates. You can install today's update by going to Start > Settings > Update & Security > Windows Update and clicking on 'Check for updates.' You can also manually download and install the update from the Microsoft Update Catalog. After installing today's update, Windows 10 will be updated to OS Builds 19045.7663 and 19044.7663. With today's update, Microsoft is fixing a File History backup issue and expanding the rollout of new Secure Boot certificates. Here's the full list of improvements and fixes: Microsoft also said that Secure Boot certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.

Aug 11, 2026, 06:26 PM Read more →
NEWS BleepingComputer

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege. The approximate number of bugs in each vulnerability category is listed below: When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month. While this Patch Tuesday is not as large as last month's, which fixed 570 flaws, it is still very large compared to the previous month.

Aug 11, 2026, 06:08 PM Read more →
NEWS Security Affairs CVE-2026-53413

Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory corruption issue found by A Security that could allow a meeting participant to […]

Aug 11, 2026, 05:48 PM Read more →
NEWS BleepingComputer

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has released Windows 11 KB512103 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. Today's updates are mandatory as they contain the August 2026 Patch Tuesday security patches for 400 vulnerabilities discovered in previous months. You can install today's update by going to Start > Settings > Windows Update and clicking on 'Check for Updates.' You can also manually download and install the update from the Microsoft Update Catalog. This is the eighth 'Patch Tuesday' release in 2026, and it's based on 24H2, which means 25H2 gets the same update. There are no exclusive or special changes. You'll get the same fixes across the two versions of Windows 11. With today's update, Microsoft is making Windows Search better at typos and rolling out multiple performance-related fixes, but the catch is that most changes don't show up right away.

Aug 11, 2026, 05:38 PM Read more →
NEWS The Hacker News CVE-2026-55040

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

Aug 11, 2026, 04:47 PM Read more →
NEWS The Hacker News

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE - The Hacker News

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them. It lets a remote unauthenticated attacker assume a chosen user's identity. The attack has one prerequisite: the intruder has to know which account they want to become, either by its Active Directory security identifier (SID) or its user principal name (UPN), which is formatted like an email address. Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials. Microsoft and the firm disclosed that second flaw on August 11 as CVE-2026-63520 (CVSS 8.1), an unsafe .NET type instantiation in SharePoint's Business Connectivity Services.

Aug 11, 2026, 04:47 PM Read more →
NEWS Security Affairs

ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]

Aug 11, 2026, 04:44 PM Read more →