ZCyberNews — Cybersecurity & Tech Intelligence
HelloNet Campaign Hijacks ViPNet Update System to Deploy Malicious
Kaspersky details HelloNet APT campaign targeting Russian government, energy, and transport sectors via ViPNet update system DLL sideloading since May 2026.
See more updates →4 min read
Water Utilities Partner With DEF CON Offshoot for Cyber Help
NRWA and DEF CON Franklin launch Water Watch Center to deliver threat intel and MDR services to small water utilities serving under 10,000 people, as attacks hit 12+ states.
CVE-2026-18577
CISA Adds Exploited N-able N-central Flaw to KEV Catalog
CVSS 8.2 · IT management, managed service providers
CISA adds CVE-2026-18577 (CVSS 8.2) to KEV after active exploitation; incomplete patch for CVE-2026-18556 in N-able N-central. Patch now.
Read →More from today
See all →- 4dMalwareToken Jacking: Cybercriminals Steal AI API Keys for Gray Market Resale
- 5dMalwareAlmost Half of Malware Samples Communicate Direct to IP
- 6dAI SecurityFrontier AI Finds 14,090 Zero-Days in OSS in 2 Months
- 6dMalwareGitHub Pages, Cloudflare Workers Fuel MFA-Bypass Phishing
- 1wAI SecurityOpenAI Models Escape Sandbox, Attack Hugging Face
Threat Intel

HelloNet Campaign Hijacks ViPNet Update System to Deploy Malicious
Kaspersky details HelloNet APT campaign targeting Russian government, energy, and transport sectors via ViPNet update system DLL sideloading since May 2026.
Cavern Manticore: Iran-Linked Modular C2 Framework Exposed
Check Point Research tracks Cavern Manticore, an Iran MOIS-linked APT targeting Israeli govt and IT sectors with a modular .NET C2 framework.
ModeloRAT Campaign Abuses Microsoft Teams for Enterprise Intrusion
Rapid7 dissects an April 2026 intrusion where a fake IT Support Teams message delivered ModeloRAT via Dropbox, leading to privilege escalation, credential theft, and lateral...
Vulnerabilities
8.2
high
CISA Adds Exploited N-able N-central Flaw to KEV Catalog
CVE-2026-18577
9.0
critical
CVE-2026-45408: Shell Injection in Dokku PaaS Lets Authenticated
CVE-2026-45408
9.8
critical
CVE-2019-25763: WordPress Beaver Builder Plugin Authentication Bypass
CVE-2019-25763
Malware
Token Jacking
MALWARE
Token Jacking: Cybercriminals Steal AI API Keys for Gray Market Resale
Aug 6 · HIGH
Phorpiex
MALWARE
Almost Half of Malware Samples Communicate Direct to IP
Aug 5 · HIGH
Aitm
MALWARE
GitHub Pages, Cloudflare Workers Fuel MFA-Bypass Phishing
Aug 4 · HIGH
Industry News
Water Utilities Partner
WATER UTILITIES
Water Utilities Partner With DEF CON Offshoot for Cyber Help
Aug 8 · INFO
Analog Devices Breach
ANALOG DEVICES
Analog Devices Breach: Chip Maker Says Data Exfiltrated
Jul 31 · HIGH
CISA Postmortem Reveals
CISA
CISA Postmortem Reveals GitHub Credential Leak Lasted Six Months
Jul 13 · HIGH
Tools & Techniques

Metasploit Adds Vim Plugin Persistence, Exploits for Three CVEs
Rapid7's Metasploit Framework adds Vim plugin persistence, exploits for CVE-2025-6793 (Marvell QConvergeConsole), CVE-2024-48760 (GestioIP), and CVE-2023-30253 (Dolibarr).
Signal Adds In-App Warnings to Block Russian-Linked Phishing Attacks
Signal introduced new in-app confirmations and warnings to counter phishing attacks linked to Russian state hackers who abused the Linked Device feature to hijack high-profile...
Anthropic Launches Claude Security for AI-Driven Exploit Defense
Anthropic released Claude Security, a defensive AI suite to counter autonomous exploit tools like Mythos that weaponize zero-days in minutes. Targets enterprise SOCs.
AI Security
AI Security
AI SECURITY
Frontier AI Finds 14,090 Zero-Days in OSS in 2 Months
Aug 4 · CRITICAL
OpenAI
PROVIDER
OpenAI Models Escape Sandbox, Attack Hugging Face
Aug 3 · HIGH
AI Security Report 2026
AI SECURITY
AI Crosses From Assistant to Operator in Live Attacks, Check Point
Jul 14 · INFO
Stay Updated
Get the latest cybersecurity news delivered to your inbox.