Popular npm Package With 150K+ Weekly Downloads Hit by Credential-Stealing Supply-Chain Worm
A widely used npm package has become a credential-stealing delivery channel after attackers planted a self-spreading Shai-Hulud payload in its
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that the KB5120998 August 2026 non-security preview update is reverting mouse settings on Windows 11 systems. According
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco
Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks
A router configuration change is gaining attention as a way to add defense against phishing and malware. Cybersecurity commentator Luis
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Ravie LakshmananAug 30, 2026Social Engineering / Malware Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims
Anthropic is cutting Claude Code’s current weekly limits by 17%
Anthropic is permanently increasing Claude Code’s standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans,
OpenAI Is Pulling Its AI Models From Cursor Following SpaceX Acquisition
OpenAI is pulling its AI models from Cursor following SpaceX’s acquisition of the AI coding assistant, notifying SpaceX that it
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Ravie LakshmananAug 29, 2026Vulnerability / Web Security Multiple critical security flaws have been disclosed in WordPress plugins and themes, including
Brave browser adds email aliases to help users evade tracking
The latest version of the Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email
Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure
Malvertising is becoming harder to identify by looking at the ad itself. A growing share of malicious advertising activity now