-
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores h…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail servi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Levi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three employee-issued computers and exfiltrate unspecified corporate information. According to the appare…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
This market runs from $0 to seven figures, and the free options power half the paid ones — so price comparisons here reward honesty. The verdict up front: Snort and Suricata are the best-value detection engines on earth (free, production-grade, industr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from August 3–7, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmwar…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login screen and can be chained into full remote code execution. Researchers at pw…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address Reconfiguration implementation. Researchers at Tencent Zhuque Lab’s Corvus AI project…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both macOS and Windows machines. Documented by Jamf, unlike most macOS malware, which typically rel…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated remote attackers to execute arbitrary code and access files with root-level privileges. The flaw is e…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


