Tuesday, August 25, 2026
Follow on LinkedIn

Cyber Security

Apple’s Private Find My People Reversed to Decrypt Live Shared Locations on Linux

A security researcher has successfully reverse-engineered Apple's private Find My People protocol, demonstrating that a Linux machine can register with Apple's internal services, receive an existing location-sharing key, and decrypt a friend's live location without ever touching a Mac...

Critical Microsoft Entra ID Vulnerability Enables Remote Code Execution Attacks

Update: The article was updated post-publication to reflect a Microsoft update, clarifying that the vulnerability is not currently being exploited in the wild. Microsoft has confirmed a critical remote code execution flaw in Entra ID, its cloud-based identity and access...

CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users

A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on legitimate websites.The attack, called CRLF-Powered Desync, begins when an application incorrectly handles encoded carriage return...

AWS Shows How to Stop a Hijacked AI Agent From Reading Data the User Cannot Access

Enterprises are racing to deploy AI agents that pull from databases, document repositories, SaaS platforms, and internal knowledge bases to automate workflows. But a quiet risk lurks beneath the convenience: most agents have no built-in awareness of who is...

Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel

Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative privileges to neutralize endpoint security protections. The Check Point research does not describe a conventional vulnerability or...

New “Zombie Card” Flaw Lets Expired Visa Cards Make Contactless Payments

Security researchers have demonstrated that an expired credit card is not as dead as most cardholders believe. A new study from the University of Massachusetts Amherst, presented at the 35th USENIX Security Symposium, reveals a practical NFC relay attack...

U.S. Agencies Warn of Hackers Actively Attacking Siemens S7 PLCs in Critical Facilities

The NSA, CISA, FBI, Department of Energy, and EPA issued a joint cybersecurity advisory on August 19 warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) across America's critical infrastructure. The agencies describe this as...

T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network

T-Mobile's security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese state-backed hackers' access to its systems, according to new reporting from Bloomberg. The dramatic move came...

AI Agent Hacks Snowflake GitHub Workflow and Reaches Internal Jira

An autonomous AI security agent built by Wiz Research has demonstrated how quickly a single overlooked line of shell code can cascade into a full credential leak. The tool, known as Wiz Red Agent, independently discovered, exploited, and validated a...

Windows Defender Update for 0-day Vulnerability Breaks Virus Scans

Microsoft Defender has been aborting Quick, Full, and Offline virus scans after a cluster of Security Intelligence updates reached Windows PCs on August 18, 2026, leaving home users and Defender for Endpoint admins without a reliable malware check. Community testers...

Latest News

Latest News