Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Infosec News Nuggets — August 10, 2026 – AboutDFIR

    August 10, 2026

    JHT Course Launch! Home Labs with Proxmox

    August 9, 2026

    Cyber Deception Everywhere

    August 8, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Infosec News Nuggets — August 10, 2026 – AboutDFIR
    News

    Infosec News Nuggets — August 10, 2026 – AboutDFIR

    adminBy adminAugust 10, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

    A use-after-free bug tracked as CVE-2026-64564 and nicknamed SCTPhantom has been lurking in Linux’s SCTP networking code since 2008 and can be chained into full root access on a host; researchers say they used it to escape a container and reach the underlying machine, getting root on kernel builds for Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS in six of eight attempts. The bug stems from a mismatch between the address used to validate a delete request and the address used to pick the actual network path, letting an attacker free a live connection object and reuse the dangling pointer. Fixed stable kernels shipped August 3, and since exploitation requires local access with SCTP reachable, blocking the module where it’s unneeded removes the exposure entirely.

     

    Levi Strauss & Co. says hackers stole corporate data in cyberattack

    An unauthorized party social-engineered three employees into handing over access to their company-issued computers, allowing corporate data to be accessed and exfiltrated before the intrusion was contained; no exploit, credential brute force, or unpatched flaw was involved. A regulatory filing states the response was fast enough to prevent any consumer data from being touched and that business operations weren’t disrupted. Some outlets have tied the intrusion to a voice-phishing group that has run similar campaigns against hundreds of organizations in recent weeks, underscoring how attackers are increasingly bypassing technical defenses by targeting people directly.

     

    Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access

    An unauthenticated SQL injection flaw in the popular open-source business intelligence platform’s password-reset endpoint let attackers inject arbitrary database commands and promote themselves to administrator without ever logging in, earning a maximum CVSS score of 10.0 across versions 0.58 through 0.63. The bug was discovered after the vendor’s own cloud platform was breached on August 3, and while cloud customers were patched automatically within hours, self-hosted deployments remain exposed until administrators upgrade manually. At least two downstream customers have already disclosed theft of names, addresses, phone numbers, and emails as a result of the intrusion.

     

    Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

    Switzerland’s Federal Office for Information Technology and Communications disclosed that roughly 200 accounts on its on-premises SharePoint servers were compromised by previously unknown attackers, likely exploiting vulnerabilities patched in Microsoft’s July security updates. The agency detected anomalies on its servers, blocked external SharePoint access, patched the suspected flaws, and is now reinstalling affected servers as a precaution, though it says early analysis shows no evidence data beyond login credentials was accessed. Government cybersecurity bodies have separately warned that attackers exploiting these SharePoint flaws have been extracting cryptographic machine keys that can let forged session tokens survive even after patching, meaning credential rotation and a server restart are needed on top of the update itself.

     

    Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

    Security research presented at Black Hat USA 2026 shows that plain CSS styling code, long assumed harmless, can be weaponized against major webmail providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail to steal passwords, hijack sessions, and manipulate connected AI tools. One demonstrated chain disguises a dropdown as a password field in Outlook and exploits a Firefox timing quirk to capture keystrokes in near real time, while a separate technique leaked an authentication token through Gmail’s image-loading behavior and chained it into a prompt-injection attack against an AI email assistant. Some providers have already patched the specific bugs reported to them, but the Outlook and Gmail techniques were confirmed still working as of August 6, and the researcher has published proof-of-concept code alongside recommendations like sandboxing HTML email and restricting allowed CSS properties.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleJHT Course Launch! Home Labs with Proxmox
    admin
    • Website

    Related Posts

    News

    Hackers breach TrueConf to trojanize client installers with backdoors

    August 8, 2026
    News

    Crab Odyssey: Crustacean Wandered the Seas in a Bottle for Months, Scientists Find

    August 8, 2026
    News

    How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

    August 8, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    How fraudsters target credit unions

    May 4, 202637 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    How fraudsters target credit unions

    May 4, 202637 Views
    Our Picks

    Infosec News Nuggets — August 10, 2026 – AboutDFIR

    August 10, 2026

    JHT Course Launch! Home Labs with Proxmox

    August 9, 2026

    Cyber Deception Everywhere

    August 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.