<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CosmicBytez Labs</title>
    <link>https://labs.cosmicbytez.ca</link>
    <description>IT &amp; Cybersecurity Intelligence - News, Security Alerts, HOWTOs, and Project Guides</description>
    <language>en-ca</language>
    <lastBuildDate>Sat, 15 Aug 2026 17:02:53 GMT</lastBuildDate>
    <atom:link href="https://labs.cosmicbytez.ca/api/rss" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://labs.cosmicbytez.ca/images/icon.png</url>
      <title>CosmicBytez Labs</title>
      <link>https://labs.cosmicbytez.ca</link>
    </image>
    
    <item>
      <title><![CDATA[Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-15-hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-15-hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw</guid>
      <description><![CDATA[Operation Klonen: Brazilian and German authorities arrest 7 suspects behind a €30M bank fraud exploiting a third-party payment processor vulnerability at Commerzbank.]]></description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>cybercrime</category>
      <category>banking</category>
      <category>fraud</category>
      <category>supply-chain</category>
      <category>arrest</category>
      <category>third-party-risk</category>
    </item>
    <item>
      <title><![CDATA[How Anthropic Plans to Watermark Claude's AI-Generated Text]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-15-how-anthropic-plans-to-watermark-claudes-ai-generated-text</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-15-how-anthropic-plans-to-watermark-claudes-ai-generated-text</guid>
      <description><![CDATA[Anthropic begins embedding invisible SynthID-Text watermarks and C2PA metadata into all Claude outputs globally, driven by EU AI Act Article 50 compliance.]]></description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Anthropic</category>
      <category>Claude</category>
      <category>AI</category>
      <category>watermarking</category>
      <category>EU-AI-Act</category>
      <category>SynthID</category>
      <category>C2PA</category>
    </item>
    <item>
      <title><![CDATA[New Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-15-new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-15-new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes</guid>
      <description><![CDATA[FortiGuard Labs uncovers Evooo1Bot, a Mirai-derived Linux botnet exploiting 8 CVEs to compromise routers and convert them into persistent SOCKS5 relay proxies.]]></description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>botnet</category>
      <category>Linux</category>
      <category>router</category>
      <category>Mirai</category>
      <category>SOCKS5</category>
      <category>threat-intel</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-63700: Dell Wyse Management Suite Privilege Escalation]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-63700</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-63700</guid>
      <description><![CDATA[Dell patches a high-severity privilege escalation flaw in Wyse Management Suite allowing local attackers to achieve full system compromise.]]></description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>Dell</category>
      <category>Wyse</category>
      <category>privilege-escalation</category>
      <category>enterprise</category>
      <category>patch</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-72819: Grav CMS RCE via ZIP Upload Bypass in Flex Objects Plugin]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-72819</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-72819</guid>
      <description><![CDATA[Grav CMS before 2.0.13 allows authenticated users to achieve RCE by bypassing filename validation with PHP-laden ZIP files.]]></description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>Grav CMS</category>
      <category>Remote Code Execution</category>
      <category>File Upload</category>
      <category>PHP</category>
      <category>Flex Objects</category>
    </item>
    <item>
      <title><![CDATA[Cyera's $1B Oasis Security Acquisition Is All About AI Agent Control]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-cyeras-oasis-security-buy-is-all-about-ai-agent-control</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-cyeras-oasis-security-buy-is-all-about-ai-agent-control</guid>
      <description><![CDATA[Cyera acquires Oasis Security for $1 billion to unify data security and identity into a single AI agent control plane.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Identity</category>
      <category>Data Security</category>
      <category>Mergers and Acquisitions</category>
      <category>Agentic AI</category>
    </item>
    <item>
      <title><![CDATA[Data Analyst Sent to Prison for Stealing Data, Extorting Employer]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-data-analyst-sent-to-prison-for-stealing-data-extorting-employer</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-data-analyst-sent-to-prison-for-stealing-data-extorting-employer</guid>
      <description><![CDATA[A former contractor at Brightly Software was sentenced to two years in federal prison for a $2.5 million extortion scheme targeting his employer.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Insider Threat</category>
      <category>Cybercrime</category>
      <category>Legal</category>
    </item>
    <item>
      <title><![CDATA[France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-france-investigates-tax-authority-breach-after-hacker-claims-600000-victims</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-france-investigates-tax-authority-breach-after-hacker-claims-600000-victims</guid>
      <description><![CDATA[French authorities confirmed unauthorized access to DGFiP systems in late June after an attacker used stolen credentials, with a hacker claiming 600,000 records exposed.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>France</category>
      <category>Government</category>
      <category>Tax Authority</category>
      <category>DGFiP</category>
      <category>Identity Theft</category>
    </item>
    <item>
      <title><![CDATA[Hackers Exploiting Unpatched GeoServer Zero-Day With SQL Injection to RCE]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-hackers-exploiting-unpatched-geoserver-zero-day</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-hackers-exploiting-unpatched-geoserver-zero-day</guid>
      <description><![CDATA[Active exploitation attempts targeting an unpatched GeoServer zero-day began within hours of public disclosure. No patch available — restrict access now.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>GeoServer</category>
      <category>SQL Injection</category>
      <category>RCE</category>
      <category>Active Exploitation</category>
      <category>Geospatial</category>
    </item>
    <item>
      <title><![CDATA[In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-in-other-news-rapid7-layoffs-hacking-a-boeing-737-refrigeration-system-vulnerabi</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-in-other-news-rapid7-layoffs-hacking-a-boeing-737-refrigeration-system-vulnerabi</guid>
      <description><![CDATA[Weekly roundup: Rapid7 cuts staff, researcher hacks Boeing 737 systems, North Korean IT worker breaches federal agency, DEF CON drama.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Security Roundup</category>
      <category>Rapid7</category>
      <category>Aviation Security</category>
      <category>North Korea</category>
      <category>ICS Security</category>
      <category>DEF CON</category>
    </item>
    <item>
      <title><![CDATA[Max Severity SAP Commerce Cloud Flaw Now Targeted in Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks</guid>
      <description><![CDATA[A critical RCE vulnerability in SAP Commerce Cloud, patched just days ago, is already being actively exploited in the wild.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Vulnerability</category>
      <category>Cloud Security</category>
      <category>SAP</category>
      <category>Security Updates</category>
    </item>
    <item>
      <title><![CDATA[Over 1,000 Charities Hit by Beacon CRM Data Breach]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-over-1000-charities-hit-by-beacon-crm-data-breach</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-over-1000-charities-hit-by-beacon-crm-data-breach</guid>
      <description><![CDATA[Over 1,000 UK charities affected after Beacon CRM suffered a data breach traced to an exposed AWS access key in public JS files.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>AWS</category>
      <category>CRM</category>
      <category>Nonprofits</category>
      <category>Cloud Security</category>
      <category>Secrets Management</category>
    </item>
    <item>
      <title><![CDATA[Scottish Government Suffers Potentially Widening Data Breach at Prosecutor's Office]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-scottish-govt-suffers-potentially-widening-data-breach-at-prosecutors-office</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-scottish-govt-suffers-potentially-widening-data-breach-at-prosecutors-office</guid>
      <description><![CDATA[A third-party breach at Scotland's Crown Office and Procurator Fiscal Service may extend to multiple government agencies that shared the same vendor.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Scotland</category>
      <category>Government</category>
      <category>Supply Chain</category>
      <category>Third Party</category>
      <category>COPFS</category>
    </item>
    <item>
      <title><![CDATA[Shell Investigates 'Potential Incident' After Clop Data Theft Claims]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-shell-investigates-potential-incident-after-clop-data-theft-claims</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-shell-investigates-potential-incident-after-clop-data-theft-claims</guid>
      <description><![CDATA[Oil giant Shell is investigating after Clop ransomware gang claimed to have stolen 89GB of data from the company.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Cybercrime</category>
      <category>Data Breach</category>
    </item>
    <item>
      <title><![CDATA[Ukraine Shuts Down 94 Fraudulent Call Centers, Seizes Millions in Cash]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-14-ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-14-ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash</guid>
      <description><![CDATA[Ukrainian authorities dismantled 94 fraud call centers running investment scams and bank credential theft operations across multiple cities.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ukraine</category>
      <category>Cybercrime</category>
      <category>Fraud</category>
      <category>Call Center</category>
      <category>Law Enforcement</category>
      <category>SBU</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-12949: Critical Account Takeover in WordPress Wishlist Member Plugin]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-12949</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-12949</guid>
      <description><![CDATA[Critical CVSS 9.8 flaw in WordPress Wishlist Member plugin allows unauthenticated account takeover in versions up to 3.34.1.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>Account Takeover</category>
      <category>Authentication Bypass</category>
      <category>Plugin Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-15413: WordPress 'Link Factory' Plugin Is an Intentional Backdoor (CVSS 10.0)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-15413</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-15413</guid>
      <description><![CDATA[The Link Factory WordPress plugin is a supply-chain backdoor. Operator-controlled REST API lets attackers run arbitrary commands. Remove it immediately.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>Backdoor</category>
      <category>Supply Chain</category>
      <category>CWE-912</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-17482: Critical RCE in IBM Documentation Offline]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-17482</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-17482</guid>
      <description><![CDATA[IBM Documentation Offline versions 1.0.0–1.4.1 contain a critical path traversal flaw allowing remote code execution with a CVSS score of 9.8.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>IBM</category>
      <category>Remote Code Execution</category>
      <category>Path Traversal</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-28154: Reflected XSS in WooCommerce WordPress Themes]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-28154</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-28154</guid>
      <description><![CDATA[High-severity reflected XSS in Samex and M.Anh WooCommerce themes allows attackers to inject malicious scripts via crafted URLs.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Vulnerability</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>XSS</category>
      <category>WooCommerce</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-59500</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-59500</guid>
      <description><![CDATA[Maximum severity CVE in Priority ERP's portal addon allows unauthenticated remote attackers to bypass authentication entirely. Patch immediately.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>ERP</category>
      <category>Authentication Bypass</category>
      <category>Priority ERP</category>
      <category>CWE-287</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-59504: Priority Portal Generator Client-Side Security Bypass (CVSS 9.1)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-59504</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-59504</guid>
      <description><![CDATA[Critical flaw in Soft Solutions' Priority ERP portal addon lets remote attackers bypass server-side security controls. Upgrade to Priwall v3.]]></description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>ERP</category>
      <category>Security Bypass</category>
      <category>Priority ERP</category>
      <category>CWE-602</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-adobe-cvss-10-coldfusion-campaign-classic</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-adobe-cvss-10-coldfusion-campaign-classic</guid>
      <description><![CDATA[Adobe's August 2026 patch cycle fixes 3 maximum-severity RCE vulnerabilities across ColdFusion and Campaign Classic. Priority 1 — patch within 72 hours.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Adobe</category>
      <category>ColdFusion</category>
      <category>Campaign Classic</category>
      <category>RCE</category>
      <category>patch tuesday</category>
      <category>critical vulnerability</category>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[Akira Hackers Disable EDR with Safe Mode, Steal Data but Fail to Encrypt]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt</guid>
      <description><![CDATA[An Akira affiliate rebooted a compromised system into Safe Mode to blind EDR tools, exfiltrated data via s5cmd, then failed to encrypt due to memory errors.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Akira</category>
      <category>EDR Bypass</category>
      <category>Safe Mode</category>
      <category>Cybercrime</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title><![CDATA[Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks</guid>
      <description><![CDATA[Apple warned iPhone users in 110 countries of mercenary spyware attacks. Enable Lockdown Mode and update iOS immediately if you receive an alert.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Apple</category>
      <category>Spyware</category>
      <category>iOS</category>
      <category>Pegasus</category>
      <category>Threat Intelligence</category>
      <category>Zero-Click</category>
    </item>
    <item>
      <title><![CDATA[737 Chrome VPN Extensions Caught Routing Traffic Through Attacker Proxies]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-chrome-vpn-extensions-proxy-routing</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-chrome-vpn-extensions-proxy-routing</guid>
      <description><![CDATA[Socket researchers found 737 fake Chrome VPN extensions silently routing 75,000+ users through SOCKS5 proxies on port 1082, enabling full AiTM interception.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Chrome</category>
      <category>browser extensions</category>
      <category>VPN</category>
      <category>supply chain</category>
      <category>AiTM</category>
      <category>malware</category>
      <category>SOCKS5</category>
    </item>
    <item>
      <title><![CDATA[Critical VMware vCenter RCE Flaw Exploited for Reverse SSH Access]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access</guid>
      <description><![CDATA[CVE-2026-59310 is under active exploitation just 5 days after disclosure, with 361 victims across 47 countries receiving reverse SSH backdoors.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>VMware</category>
      <category>vCenter</category>
      <category>RCE</category>
      <category>CVE</category>
      <category>Exploitation</category>
      <category>APT</category>
      <category>Reverse Shell</category>
    </item>
    <item>
      <title><![CDATA[FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-fbi-hackers-using-social-engineering-to-breach-accounts-and-steal-explicit-conte</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-fbi-hackers-using-social-engineering-to-breach-accounts-and-steal-explicit-conte</guid>
      <description><![CDATA[The FBI warns hackers are breaching social media accounts to steal explicit content via credential stuffing, impersonation, and fake clone sites.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>social-engineering</category>
      <category>fbi</category>
      <category>phishing</category>
      <category>account-takeover</category>
      <category>sextortion</category>
    </item>
    <item>
      <title><![CDATA[Germany Moves to Give Spy Agencies Hacking and Sabotage Powers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-germany-moves-to-give-spy-agencies-hacking-and-sabotage-powers</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-germany-moves-to-give-spy-agencies-hacking-and-sabotage-powers</guid>
      <description><![CDATA[Germany's cabinet approves sweeping intelligence reform granting the BND and BfV unprecedented hacking, sabotage, and disinformation powers.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>government</category>
      <category>intelligence</category>
      <category>cybersecurity-policy</category>
      <category>germany</category>
      <category>surveillance</category>
    </item>
    <item>
      <title><![CDATA[Hackers Breach Govt Webmail While Running Parallel Crypto Fraud]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-hackers-breach-govt-webmail-while-running-parallel-crypto-fraud</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-hackers-breach-govt-webmail-while-running-parallel-crypto-fraud</guid>
      <description><![CDATA[China-linked Jewelbug injected malicious JS into 15 govt webmail tenants while simultaneously operating a 44-server industrial crypto fraud empire.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>APT</category>
      <category>Espionage</category>
      <category>Cryptocurrency Fraud</category>
      <category>China</category>
      <category>Webmail</category>
      <category>Supply Chain</category>
      <category>Data Breach</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Patches LegacyHive Windows Zero-Day That Grants Admin Privileges]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-microsoft-patches-legacyhive-windows-zero-day-vulnerability</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-microsoft-patches-legacyhive-windows-zero-day-vulnerability</guid>
      <description><![CDATA[CVE-2026-62832 in Windows User Profile Service lets local users hijack registry hives and escalate to admin. Patch now via August Patch Tuesday.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Vulnerability</category>
      <category>Microsoft</category>
      <category>Windows</category>
      <category>Privilege Escalation</category>
      <category>Patch Tuesday</category>
    </item>
    <item>
      <title><![CDATA[Ukraine Dismantles 94 Fraudulent Call Centers, Seizes $2M and a Kilogram of Gold]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash</guid>
      <description><![CDATA[Ukraine's National Police and SBU shut down 94 investment fraud call centers across 9 regions, seizing $2M, luxury cars, and 5,200+ SIM cards.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cybercrime</category>
      <category>Fraud</category>
      <category>Ukraine</category>
      <category>Call Center Scam</category>
      <category>Law Enforcement</category>
    </item>
    <item>
      <title><![CDATA[Venture Firm Team8 Secures Additional $365 Million]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-venture-firm-team8-secures-additional-365-million</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-venture-firm-team8-secures-additional-365-million</guid>
      <description><![CDATA[Team8 closes $365M across Fund III and a follow-on pool, pushing total AUM to nearly $2 billion as the firm bets on AI-native enterprise security.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>cybersecurity</category>
      <category>venture-capital</category>
      <category>funding</category>
      <category>ai-security</category>
      <category>team8</category>
    </item>
    <item>
      <title><![CDATA[Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-13-who-vets-ais-code-the-scale-challenge-facing-open-source-ingestion</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-13-who-vets-ais-code-the-scale-challenge-facing-open-source-ingestion</guid>
      <description><![CDATA[With 85% of enterprises using AI coding tools but only 9% deploying AI-specific security controls, open source ingestion faces a critical vetting gap.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>ai-security</category>
      <category>open-source</category>
      <category>supply-chain</category>
      <category>software-development</category>
      <category>slopsquatting</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-11325: Cloudflare pages-action GitHub Actions RCE]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-11325</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-11325</guid>
      <description><![CDATA[High-severity RCE in cloudflare/pages-action exposes CI/CD credentials. Migrate to wrangler-action before Sept 18, 2026 sunset.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>GitHub Actions</category>
      <category>Cloudflare</category>
      <category>CI/CD</category>
      <category>RCE</category>
      <category>credential-theft</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-14182: WooCommerce Email Verification Bypass Allows Account Takeover]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-14182</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-14182</guid>
      <description><![CDATA[A CVSS 9.8 type juggling flaw in Customer Email Verification for WooCommerce lets unauthenticated attackers take over any customer account.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>WordPress</category>
      <category>WooCommerce</category>
      <category>CVE-2026-14182</category>
      <category>Account Takeover</category>
      <category>Type Juggling</category>
      <category>Web Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-19001</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-19001</guid>
      <description><![CDATA[Critical CVSS 9.8 buffer overflow in the MongoDB BI Connector ODBC Driver may allow remote code execution via long metadata names.]]></description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>MongoDB</category>
      <category>Buffer Overflow</category>
      <category>RCE</category>
      <category>Database Security</category>
    </item>
    <item>
      <title><![CDATA[Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-cisco-asa-ftd-vpn-dos-cve-2026-20349</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-cisco-asa-ftd-vpn-dos-cve-2026-20349</guid>
      <description><![CDATA[CVE-2026-20349 (CVSS 8.6) in Cisco ASA and FTD allows unauthenticated remote attackers to crash SSL VPN devices via crafted HTTP requests — no workaround exists.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cisco</category>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>VPN</category>
      <category>Firewall</category>
      <category>Denial of Service</category>
    </item>
    <item>
      <title><![CDATA["City-Forum" Data-Theft Attacks Target Salesforce and ServiceNow Portals]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-city-forum-data-theft-attacks-target-salesforce-servicenow-portals</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-city-forum-data-theft-attacks-target-salesforce-servicenow-portals</guid>
      <description><![CDATA[A 17-month stealth campaign uses custom Go tooling to scrape enterprise data from misconfigured Salesforce and ServiceNow guest-user portals.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cloud Security</category>
      <category>Salesforce</category>
      <category>ServiceNow</category>
      <category>Data Theft</category>
      <category>Misconfiguration</category>
    </item>
    <item>
      <title><![CDATA[DeadLock Ransomware Uses Blockchain to Resist Infrastructure Takedown]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-deadlock-ransomware-blockchain-infrastructure</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-deadlock-ransomware-blockchain-infrastructure</guid>
      <description><![CDATA[DeadLock ransomware stores its C2 configuration in Polygon smart contracts, making law enforcement takedowns ineffective against its 80+ victim operation.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Blockchain</category>
      <category>Cybercrime</category>
      <category>Threat Intelligence</category>
      <category>Infrastructure</category>
    </item>
    <item>
      <title><![CDATA[Hackers Exploit Critical Adobe Commerce Flaw to Hijack Customer Accounts]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts</guid>
      <description><![CDATA[Active exploitation of CVE-2026-71362 in Adobe Commerce and Magento is underway, with attackers targeting customer account takeover on e-commerce storefronts.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Adobe Commerce</category>
      <category>Magento</category>
      <category>CVE-2026-71362</category>
      <category>E-Commerce Security</category>
      <category>Account Takeover</category>
      <category>Exploitation</category>
      <category>Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-lazarus-exploits-windows-zero-day-to-gain-system-access-and-deploy-backdoor</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-lazarus-exploits-windows-zero-day-to-gain-system-access-and-deploy-backdoor</guid>
      <description><![CDATA[Lazarus Group weaponized a Windows afd.sys kernel flaw to reach SYSTEM, deploy the FudModule rootkit killing 94 EDR channels, and drop new backdoors.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Lazarus Group</category>
      <category>Windows</category>
      <category>Kernel Exploit</category>
      <category>Rootkit</category>
      <category>Backdoor</category>
      <category>CVE-2026-68820</category>
    </item>
    <item>
      <title><![CDATA[Lazarus Hackers Exploited Windows Zero-Day to Target Defense Firms]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms</guid>
      <description><![CDATA[North Korea's Lazarus Group weaponized CVE-2026-68820 in Operation Dream Job, hitting defense and aerospace firms across four countries for five weeks.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Lazarus Group</category>
      <category>North Korea</category>
      <category>Windows</category>
      <category>CVE-2026-68820</category>
      <category>Nation-State</category>
      <category>Defense Sector</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Plugs Nearly 400 Security Holes in August 2026 Patch Tuesday]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-microsoft-plugs-nearly-400-security-holes</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-microsoft-plugs-nearly-400-security-holes</guid>
      <description><![CDATA[Microsoft's August 2026 Patch Tuesday addresses 398 CVEs including a WinSock zero-day actively exploited in the wild and two publicly disclosed flaws.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Patch Tuesday</category>
      <category>Microsoft</category>
      <category>Windows</category>
      <category>Zero-Day</category>
      <category>CVE</category>
      <category>Vulnerability Management</category>
    </item>
    <item>
      <title><![CDATA[SAP Commerce Cloud RCE Flaw Lets Unauthenticated Attackers Execute Arbitrary Code]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-sap-commerce-cloud-rce-cve-2026-58231</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-sap-commerce-cloud-rce-cve-2026-58231</guid>
      <description><![CDATA[CVE-2026-58231 scores CVSS 10.0 in SAP Commerce Cloud Data Hub Adapter — patch immediately as unauthenticated RCE with full system compromise is possible.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>SAP</category>
      <category>CVE</category>
      <category>RCE</category>
      <category>Vulnerability</category>
      <category>Cloud Security</category>
      <category>Security Updates</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[Signal Adds Automatic Key Verification to Thwart Man-in-the-Middle Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks</guid>
      <description><![CDATA[Signal launched Automatic Key Verification on August 12, 2026, using key transparency audited by Cloudflare and Trail of Bits to defeat MITM attacks.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Signal</category>
      <category>Encryption</category>
      <category>Privacy</category>
      <category>Key Transparency</category>
      <category>MITM</category>
      <category>Security</category>
    </item>
    <item>
      <title><![CDATA[Wesco Confirms Security Incident After ExfilSquad Claims 2.6M Record Theft]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-08-12-wesco-confirms-security-incident-after-exfilsquad-claims-data-theft</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-08-12-wesco-confirms-security-incident-after-exfilsquad-claims-data-theft</guid>
      <description><![CDATA[Fortune 500 distributor Wesco confirmed a breach of its cloud CRM after ExfilSquad published 2.6M allegedly stolen records when ransom talks failed.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Extortion</category>
      <category>CRM</category>
      <category>ExfilSquad</category>
      <category>Supply Chain</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title><![CDATA[PicketLink SAML Authentication Bypass — Forged Assertions Accepted Without Validation]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-10579</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-10579</guid>
      <description><![CDATA[CVE-2026-10579 (CVSS 9.8): PicketLink Federation's SAML handler accepts forged assertions, allowing unauthenticated remote attackers to authenticate as any user.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SAML</category>
      <category>Authentication Bypass</category>
      <category>Java</category>
      <category>Critical</category>
      <category>NVD</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-18961: WordPress VentraConnect Plugin Authentication Bypass]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-18961</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-18961</guid>
      <description><![CDATA[High-severity auth bypass in the VentraConnect Social Login plugin allows unauthenticated attackers to take over any WordPress account.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>Authentication</category>
      <category>Plugin Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[TypeBot OAuth Credential Takeover via Low-Privilege Collaborator]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-48765</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-48765</guid>
      <description><![CDATA[TypeBot versions before 3.17.0 allow a read-only collaborator to extract and overwrite workspace OAuth credentials, enabling full account takeover.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>TypeBot</category>
      <category>OAuth</category>
      <category>CVE-2026-48765</category>
      <category>Privilege Escalation</category>
      <category>Credential Takeover</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[SonicWall GMS Unauthenticated Command Injection RCE]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-66147</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-66147</guid>
      <description><![CDATA[A critical unauthenticated command injection flaw in SonicWall GMS 9.5.1 and earlier allows remote attackers to execute arbitrary code via crafted requests.]]></description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>SonicWall</category>
      <category>GMS</category>
      <category>CVE-2026-66147</category>
      <category>RCE</category>
      <category>Command Injection</category>
      <category>Critical</category>
    </item>
  </channel>
</rss>