An ASUS vulnerability (CVE-2026-19397) lets a nearby attacker take over a host, while an Armoury Crate flaw leaks NTLM hashes. Update now.
Related Posts:
September 2026 SAP Security Patch Day Fixes Critical Flaws
Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502)
SonicWall SMA 1000 Vulnerabilities Exploited in Wild (PoC)
The post ASUS Patches Control Center Express and Armoury Crate Flaws appeared first on Daily CyberSecurity.
Pegasus spyware infected a Serbian activist through a zero-click iMessage exploit, part of Serbia's largest spyware wave. Update iOS now.
Related Posts:
Node.js Malware Attacks Target Tech and Finance Sectors
Python NodeStealer Adds Keylogging and Screen Capture Spyware
Packagist Themes iOS Spyware Steals Crypto Wallet Seeds
The post Pegasus Spyware Hits Serbian Student Activist via Zero-Click iMessage appeared first on Daily CyberSecurity.
An ASUS Control Center vulnerability, CVE-2026-75754 (CVSS 10), gives unauthenticated attackers a root shell. Update to v3.1.0.9 now.
Related Posts:
CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild
MikroTrick PoC: RouterOS Admin Rights Exploited In Wild
AI Agent Coordination: The Unprecedented OpenAI Breakout
The post CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE appeared first on Daily CyberSecurity.
FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.
A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada.
The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idsca
FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.
A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada.
The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idscan.net, a New Orleans-based identity verification company whose clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and the financial services firm Jack Henry.
“On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.” wrote Krebs. “The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.”
The record total was also increasing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing active exfiltration from a live breach they claim has been running for over a year.
Krebs found his own driver’s license in the database after a source alerted him to the service. The operators had posted his Virginia license as a free sample on the Russian cybercrime forum Exploit. Each record contains six images of the license, showing the front and back in visible, infrared, and ultraviolet light, with a timestamp. Krebs’ timestamp matched a June 2025 flight and car rental.
He then checked nine friends and relatives, and everyone who found their license confirmed traveling or renting a car around the same date. His license and his mother’s, who rented a Hertz car with him that day, had timestamps just seconds apart.
Security researcher Zach Edwards, whose license also appeared in Nexus, narrowed the source further. His timestamp matched a trip to Las Vegas for DEF CON in August. He hadn’t rented a car, but he had shown his license at a marijuana dispensary: Planet13, a multi-state chain. In 2022, idscan.net published a press release announcing an exclusive identity verification partnership with Planet13’s dispensaries nationally. The company now serves more than 1,000 marijuana dispensaries in 19 states, and its own documentation confirms that its technology scans IDs with both infrared and ultraviolet light, precisely the format of the images appearing in Nexus.
Idscan.net performs more than 21 million verifications per month at more than 20,000 locations globally. Its client list spans car rentals, retailers, hotels, financial services, and dispensaries, which explains both the volume and the geographic spread of the records. The dataset also includes marijuana dispensary cards and records marked with the notation “CAC,” which may refer to Common Access Cards, the government-issued credentials used to enter federal buildings and secure facilities. If confirmed, that would significantly expand the security implications beyond consumer identity theft.
The database reportedly contained the driver’s licenses of U.S. Defense Secretary Pete Hegseth and the FBI’s assistant director, but not FBI Director Kash Patel’s.
Idscan.net said Krebs’ findings would help its internal investigation but gave no further details. The company later said it was working with law enforcement and forensic experts. Soon after the story became public, the Nexus service went offline.
Identity verification systems that require driver’s licenses are spreading sensitive data across an expanding network of third-party vendors, and oversight mechanisms haven’t kept pace. Every bar, hotel, car rental counter, dispensary, and age-verification system that scans an ID is creating a copy of that image in a system whose security posture the cardholder has no way to assess.
The idscan.net incident, if confirmed at the reported scale, would be among the largest exposures of government-issued identity document images ever recorded.
Krebs reports that Nexus shut down after his article, while the FBI opened an investigation after learning that stolen IDs may include licenses belonging to FBI agents.
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections.
A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, tracing it to an iMessage zero-click exploit and identifying high-confidence indicators of compromise between December 2025
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections.
A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, tracing it to an iMessage zero-click exploit and identifying high-confidence indicators of compromise between December 2025 and January 2026, with the possibility of additional infections not ruled out.
“In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware.” reads the report published by Citizen Lab. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. “
The attack required no action from the victim, which makes zero-click attacks especially dangerous. Citizen Lab said the Pegasus infection could stay hidden while giving the attacker full access to the phone, including messages, photos, notes, microphone, and camera. Apple later fixed this specific exploit through security updates in iOS 18.4.1.
“We believe that the zero-click exploit used in this attack targeted Apple iMessage, and has subsequently been patched by Apple as of iOS 18.4.1.” continues the report. “A zero-click infection with Pegasus spyware would not have been visible to the target, and would give the Pegasus attacker total access to the device. Pegasus allows an attacker to do anything that a user can do, ranging from accessing private data like notes, pictures and even encrypted messages. Pegasus also has the ability to covertly enable the phone’s microphone and camera.”
This one confirmed infection sits inside something considerably bigger. The SHARE Foundation has documented at least 14 individuals targeted with advanced spyware since early 2026, spanning student movement members, civil society activists, an opposition member of parliament, and a local councilor, which the organization is calling the largest documented surveillance wave in Serbia’s history. Twelve people approached SHARE’s digital forensics team in August after receiving Apple’s own threat notifications, warnings the company sends when it detects likely state-sponsored spyware targeting; eleven of those devices remain presumed infected pending further forensic confirmation.
The timing lines up uncomfortably well with Serbia’s political calendar. This surveillance wave coincides with local elections held on March 29, 2026, and stretches toward planned early parliamentary elections in October, following months of student-led anti-government and anti-corruption protests.
“These notifications and forensic confirmation highlight the aggressive mercenary spyware targeting of the peaceful pro-democracy movement with mercenary spyware ahead of key 2026 election cycles.” continues the report.
Targeting activists and opposition figures specifically in the run-up to elections isn’t subtle, and it fits a pattern Serbia has shown before.
Serbia has a history of using commercial spyware. Citizen Lab previously documented Pegasus targeting civil society and the use of Cellebrite tools to install the locally developed NoviSpy on activists’ phones. In this case, SHARE Foundation and Amnesty Tech found a new version of NoviSpy on a student activist’s Android phone after Serbian authorities seized it during police questioning.
Amnesty International’s Security Lab head, Donncha Ó Cearbhaill, connected the dots plainly between state custody and spyware installation.
“The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities” he said.
If you’ve received an Apple Threat Notification, whether in Serbia or anywhere else, the Citizen Lab’s guidance is unambiguous: treat it as a presumed infection and get expert help immediately rather than waiting to see if anything seems wrong. Individuals in Serbia should contact the SHARE Foundation directly, and anyone elsewhere can reach Access Now’s Digital Security Helpline, which supports journalists, human rights defenders, and other high-risk civil society targets worldwide. Anyone who suspects they might be a target based on their work or public role should also turn on Lockdown Mode, Apple’s built-in feature that significantly narrows what a zero-click exploit can actually reach, and keep every device updated, since the patch that closed this specific hole has already existed for well over a year for anyone who installed it.
“We believe that the zero-click used in this attack has been rendered ineffective by a patch from Apple in recent iOS versions. We urge everyone, especially those facing increased risks because of who they are or the work they do, to keep all devices updated.” concludes the report. “Click HERE for instructions on how to keep your iPhone up to date.”
A Virtualizor supply-chain attack used a 33-hour BGP hijack to deliver malicious updates, planting root backdoors on VPS hosts. Back up your data now.
Related Posts:
HOOKEDGE Malware: BlueDelta Hits EU Diplomatic Targets
Dark Caracal Deploys New GoCaracal Malware Framework
Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT
The post Virtualizor Supply-Chain Attack: BGP Hijack Plants Backdoors appeared first on Daily CyberSecurity.
A Microsoft Defender false alarm wrongly warns that antivirus is turned off after the latest update. Defender still works, and a fix is coming.
Related Posts:
Windows 11 Relieves OneDrive Nags
Windows 11 KB5120998 Bugs Emerge
Windows 11 26H2 Enters Release Preview Channel
The post Microsoft Defender False Alarm: “Antivirus Is Turned Off” appeared first on Daily CyberSecurity.
SilkParasite APT ran China-nexus cyberespionage across Central Asia, using 7 custom RATs, DLL sideloading, and AI-assisted malware.
Related Posts:
FBI Seizes QScan and QTRouter Platforms Run by China State Hackers
Operation CameraSwarm: 14,500 Dahua Cameras Compromised Across Ukraine and Russia
Core Werewolf Deploys New CoreRAT Malware Against Russian Targets
The post SilkParasite APT Hits Central Asian Governments With 7 RATs appeared first on Daily CyberSecurity.
Seqrite links Operation QUICSILVER to a China-nexus actor deploying the QUICAgent Go backdoor against Myanmar government targets via a VHD lure.
Related Posts:
Cisco Talos Exposes UAT-10147 Agentic AI Attacks
Operation ASTERIX: Crypto Scam Used AI and Fake Wallets
arrayref Rust Crate Hijacked in Supply Chain Attack With DPRK Infrastructure Overlap
The post Operation QUICSILVER Targets Myanmar Government With Go Backdoor appeared first on Daily CyberSecurity.
Google is giving eligible US college students a free year of Google AI Pro, worth $19.99 a month, including 5TB storage and 4x Gemini usage limits.
Related Posts:
Telegram Applies for .gram Domain to Give Every User Their Own TLD
GitHub Outage Postmortem: Retry Storm and Copilot Auth Overload Explained
OpenAI Astra Security Model: Pausing Development for Safety
The post Google Offers US College Students a Free Year of Google AI Pro appeared first on Daily CyberSecurity.
Microsoft released a patch for the Microsoft Defender scan failure issue. Learn how a flawed update stopped threat services and how to fix this severe error.
Related Posts:
Microsoft Removes Windows 11 Drag Tray
Microsoft Removes WMIC from Default Windows 11 Installs
Windows 11 WinRE Gains Automatic Wi-Fi Reconnection for Cloud Rebuild
The post Microsoft Defender Scan Failure: A Flawed Update appeared first on Daily CyberSecurity.
Microsoft released a patch for the Microsoft Defender scan failure issue. Learn how a flawed update stopped threat services and how to fix this severe error.
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help.
The post Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss appeared first on TechRepublic.
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help.
CVE-2026-71479, a CVSS 9.1 integer overflow in New API billing, is exploited in the wild to self-credit balances. Update to rc.18 now.
Related Posts:
CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups
The post CVE-2026-71479: New API Integer Overflow Exploited in the Wild appeared first on Daily Cyb
Federal court records show how far the FBI’s Pegasus review progressed — and why new US spyware reporting will still leave major gaps in government hacking transparency.
The post FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight appeared first on TechRepublic.
Federal court records show how far the FBI’s Pegasus review progressed — and why new US spyware reporting will still leave major gaps in government hacking transparency.
Apple has issued mercenary spyware attack warnings to users across 110+ countries, urging immediate security action and device hardening.
Related Posts:
Gunra Ransomware Hits Critical Infrastructure, CISA Warns
ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
Fake Zoom Installer Drops Overlord RAT on macOS
The post Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries appeared first on Daily CyberSecurity.
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documen
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them. Targets confirmed in France, Germany, Brazil, and India.
“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility. Check Point reported the issue to Microsoft, which released a fix before this research was published” reads the report published by Check Point Research. “Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”
The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of Patch Tuesday, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets. Check Point reported the issue to Microsoft on July 28, Microsoft confirmed it three days later, and the fix shipped two weeks after that. The zero-day in this campaign and the zero-day under active exploitation are the same bug.
The attack runs through two parallel infection chains. In the first, victims download an encrypted archive containing a legitimate signed PDF viewer and a malicious DLL. The DLL displays a convincing Lockheed Martin job description while silently loading MISTPEN, a lightweight downloader that communicates through Microsoft Graph API and OneDrive. MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys ForestTiger, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit, FudModule 3.1, which can now tamper with Windows Smart App Control to bypass software verification.
“The second chain is more recent and shares several characteristics with a campaign described by ESET against the UAV sector in 2025. Victims are instructed to download SecurityPDF, a trojanized PDF viewer, from one of several websites impersonating Enveil, a legitimate privacy technology company with no actual connection to the attack. Once installed, the modified viewer inspects any PDF opened through it for a hidden marker.” continues the report. “When the marker is present, the application decrypts and launches an embedded payload that loads the Troy backdoor directly into memory.”
Troy is a single DLL implant that supports 17 operator commands covering file operations, shell access, process termination, in-memory DLL injection, and configuration updates. Its name comes from a PDB path embedded in the binary that Check Point also observed in earlier Lazarus samples. Enveil has no connection to the campaign; its brand was simply borrowed because it sounds credible to defense sector professionals.
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell. RelayShell functions as a relay rather than a traditional backdoor, exchanging commands and responses through simple text files. In at least one confirmed case, an already-breached French organization was used to send phishing messages to new victims — the attackers borrowed the company’s reputation to get past filters. Check Point identified at least 17 unique server identifiers in this relay network, with operators connecting through commercial VPNs to further obscure their location.
The most urgent action is applying the August 2026 Patch Tuesday update, which contains the CVE-2026-68820 fix. For organizations running public-facing Roundcube or CMS installations, the secondary risk is becoming part of the relay infrastructure rather than the intended target: the servers used in this campaign were compromised through leaked credentials and a known unpatched vulnerability, not anything exotic. The full indicators of compromise are in Check Point’s report.
“Given the combination of a zero day vulnerability that now have a patch, a new modular backdoor, and web based infrastructure designed to resemble legitimate traffic, security teams in these sectors should prioritize the August Patch Tuesday update, review the indicators of compromise published in Check Point Research publication, and apply the same level of scrutiny to unsolicited recruiting outreach that they would apply to any unverified download request.” concludes the report.
Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.
Related Posts:
UNC6671 Vishing Extortion Rebrands Across 5 Brands
Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
The post Lazarus Exploits Windows Zero-Day in Operation Dream Job Attacks appeared first on Daily CyberSecurity.
Cisco disclosed seven ClamAV vulnerabilities that let a remote attacker crash scanning via crafted files. Details are public. Patch now.
Related Posts:
CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw
CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day
Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public
The post Multiple ClamAV Flaws Let Remote Attackers Cause DoS appeared first on Daily CyberSecurity.
OnePlus 10T security support has ended. Here’s how owners can check their patch level, understand the risks, and decide when to replace the phone.
The post OnePlus 10T Is Out of Security Support: Should You Keep Using Yours? appeared first on TechRepublic.
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions.
The post OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades appeared first on TechRepublic.
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions.