August 21, 2026
- 14 vulnerabilities in Apple's SPTM chain reportedly enable a jailbreak on A12–A17 devices across iOS 26.0–26.5 (and likely 26.6), per the researcher who reverse-engineered Secure Page Table Monitor; PoC credited to @rooootdev, with details promised shortly (@ncxcq). Useful background on SPTM, TXM and Exclaves in Steffin's deep dive.
· Vulnerability Research
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 17, 2026
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 15, 2026
- Apple sent a fresh round of "Threat Notification" alerts to users in 110 countries targeted by mercenary spyware; it has now notified customers in over 150 countries to date (BleepingComputer, TechCrunch).
· Threat Activity
in A Heavy Day for Exploit Research and In-the-Wild N-Days
August 14, 2026
- Apple paid a $150,000 bounty for a prompt-injection attack against Private Cloud Compute (CVE-2026-20685). The writeup goes "beyond prompt injection" into hacking Apple's confidential-compute AI backend. (Sentry Security)
· AI & Model Security
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 11, 2026
The Metabase SQL injection zero-day continues spreading to major customers including LexisNexis and Framework, with no CVE assigned despite maximum severity and unauthenticated remote administrator access. Black Hat Kerberos flaws ResetNightmare and KerberLoss have been weaponized on Linux systems, and North Korea's Kimsuky is deploying offline LLMs and AI-generated decoy documents to industrialize operations. OpenAI released GPT-5.6-Cyber, a defender-focused model answering 98.5% of normally-blocked security queries, while Meta released Muse Glimmer, a 30B open-weight agent model under Apache 2.0 for local deployments. New AI agent hijacking research shows "GhostJacking" attacks manipulating agents through security alerts, and Atlassian Rovo can be exploited via hidden PDF text to steal Jira and Confluence data.
August 10, 2026
- A pre-auth RCE PoC is circulating for macOS Screen Sharing (CVE-2026-65400). Apple's fix addresses an authentication state-management bug that lets an unauthenticated network attacker reach the service without valid credentials; patched in Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 (NCSC-NL advisory). Huntress urges immediate patching and has shared detection guidance (Huntress).
· Offensive & Exploitation
in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset
August 9, 2026
in AI Agents' Black Hat Reckoning Goes Public
August 7, 2026
- Apple clamped down on its bug bounty portal after being buried under AI-generated reports describing plausible-sounding but nonexistent vulnerabilities — a growing problem for triage teams that risks masking genuine exploits. Bitdefender
· AI & Model Security
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
August 2, 2026
- macOS Screen Sharing pre-auth RCE (macOS ≤ 26.5). An SRP frame-length validation bypass in
screensharingd enables remote root code execution — arbitrary file access and reverse shells before authentication. Fixed in macOS 26.6 (warez.sl0p.foo).
· Vulnerabilities & Exploits
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
July 28, 2026
PortSwigger released Burp AT, an agentic-AI testing tool, while researchers demonstrated the first fully AI-written iOS jailbreak (Relaxin) for Apple devices with SPTM protection. Microsoft launched MAI-Cyber-1-Flash, a security model scoring 96% on CyberGym benchmarks for autonomous attack/defense simulation. Multiple zero-day exploits surfaced including a pre-auth vBulletin RCE (CVE-2026-61511), an exploited Arista VeloCloud zero-day, an n8n sandbox escape, and active FastJSON2 exploitation against US firms, while Hugging Face published a CISO post-mortem of autonomous-AI intrusion revealing 17,000+ logged actions and lateral movement.
July 17, 2026
SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409 leveraging public PoC code, with CVE-2026-56155 remaining unfixed despite July patches. Nighthawk 1.0 C2 released with cross-platform UI and improved evasion capabilities including CET-compatible call-stack masking. AI agents can be compromised through data injection attacks that corrupt trusted facts, enabling attackers to trick agents into executing commands or clicking malicious links without direct prompt injection. Scattered Spider members received 5.5-year sentences for the 2024 Transport for London ransomware attack affecting 7 million users.
July 14, 2026
- Apple sued OpenAI over alleged trade-secret theft by former employees. @Dinosn
· AI & Model Security
- CrashStealer is a new macOS infostealer written in native C++ (not the usual AppleScript/Objective-C droppers) that poses as Apple's crash-reporting tool, validates the victim's login password locally, and uses a notarized dropper to pass Gatekeeper before harvesting credentials, keychain data, and crypto wallets. BleepingComputer, Jamf via The Hacker News
· Malware
in New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs
July 6, 2026
The Gentlemen ransomware crew exploited a zero-day in a signed Kontron driver to disable endpoint defenses via BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware. CVE-2026-46242 (Bad Epoll) now has a public proof-of-concept for a Linux kernel use-after-free that enables privilege escalation on 6.4+ kernels with 99% reliability. Medtronic is notifying 3.8 million individuals after a ShinyHunters data breach exposed personal and medical data. Multiple new red-team tools and offensive-security frameworks including T3MP3ST, goshs, and Knossos were released, alongside DOJ filings revealing how Microsoft telemetry helped the FBI identify alleged Scattered Spider member Peter Stokes via Windows Global Device ID correlation.
July 5, 2026
- Apple "Hide My Email" flaw exposes real addresses. A vulnerability that can unmask the real email behind Apple's relay-address feature has reportedly gone unpatched for over a year. 404 Media
· Vulnerabilities & Exploits
- India probes a Tata Electronics leak exposing unreleased iPhone 18 Pro details/prototypes — a notable Apple supply-chain security incident. Khaleej Times
· Data Breaches & Threat Intel
in Confidential Computing's Root of Trust May Be Unfixable
July 2, 2026
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
July 1, 2026
watchTowr Labs disclosed CVE-2026-8451, a pre-auth memory overread in Citrix NetScaler SAML handling that extends the CitrixBleed lineage, alongside five other patched flaws. A China-linked USB implant infected Japanese military networks for nearly a year via disaster-relief supply chains, while European defense targets faced spear-phishing campaigns abusing AWS Cognito for credential-less C2 infrastructure. Multiple AI agent safety bypasses emerged, including GuardFall (shell injection against coding agents), BioShocking (prompt injection stealing credentials), and poisoned MCP tool descriptions enabling data exfiltration without raising alerts.
June 23, 2026
- Tata Electronics breach claims Apple and Tesla trade secrets — an actor alleges exfiltration of sensitive partner data; claims are unverified. Yahoo/Reuters
· Data Breaches
in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces
June 22, 2026
- usbliter8, a novel BootROM/SecureROM exploit for Apple A12/A13 chips (iPhone XS, iPhone 11, Apple Watch 4/5, HomePod mini), was disclosed with a public PoC — the first unpatchable hardware-level iPhone exploit in six years. It chains a USB-controller hardware bug with a firmware configuration flaw to achieve application-processor boot-chain compromise; physical access plus a Raspberry Pi are required, and there is no software fix. Paradigm Shift writeup, PoC, CyberInsider.
· Offensive & Red Team
in Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR
June 21, 2026
Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.
June 19, 2026
- Apple patched CVE-2025-20701 (CVSS 8.8) in the Airoha Bluetooth SDK used by Beats Studio Buds, which allowed nearby attackers to pair without consent and eavesdrop via the microphone (The Hacker News).
· Vulnerabilities & Exploits
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk