Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief — August 11, 2026

China-Linked Group Deploys New Ransomware via N-able Exploit

Microsoft has attributed a new ransomware campaign to Storm-1175, a China-linked threat actor, deploying StormEncryptor ransomware against organizations after likely exploiting CVE-2026-18577 in N-able N-central remote monitoring and management software. The campaign represents a notable shift as Chinese state-nexus actors have historically focused on espionage rather than ransomware deployment. Separately, a new ransomware variant called DeadLock has been observed systematically disabling Windows Defender, backup systems, and event logs before file encryption, demonstrating increasingly sophisticated anti-detection and anti-recovery capabilities.

Zero-Day Exploitation and Critical Infrastructure Targeting

Metabase confirmed active exploitation of a critical zero-day vulnerability allowing unauthenticated attackers to gain full administrator access to the business intelligence platform. The company has not disclosed the scope of exploitation or whether the flaw was used in targeted attacks. Meanwhile, officials from the Maine Water Utilities Association reported that water infrastructure systems across the state face constant probing attempts from threat actors using AI-driven scanning tools and phishing campaigns, highlighting persistent targeting of U.S. critical infrastructure.


Sources: The Hacker News · IT Security News · Cybersecurity News · Portland Press Herald

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

Tech industry is buzzing after a Claude agent hacked into a gym | TechCrunch

... hacking case in the country, the actual hack took place months ago. The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on...

Read more →

AI Moves From Cheating in Theory to Hacking the Real World - BankInfoSecurity

Among the many lessons learned from the OpenAI sandbox escape/Hugging Face hack and the more recent Claude "accidental" escape is that artificial ...

Read more →

Employee computers hacked in Levi cyberattack - HRD America

Clothing company Levi Strauss & Co. has disclosed that it experienced a cybersecurity incident that led to the access and extraction of certain ...

Read more →

Demoralized developer's desperate hack came back to haunt him on LinkedIn

A script that shouldn't have worked, on a project that never ended, for a company that hardly cared.

Read more →

Metabase Zero-Day RCE Exploit (CVSS 10.0)

An exploited Metabase zero-day with a CVSS 10.0 SQL injection vulnerability allows unauthenticated attackers to reach administrator access, steal conn...

Read more →
Cybersecurity icon

Big Cyber

Bipartisan Bill Introduced to Reauthorize the Rural and Municipal Cybersecurity Grant Program

Legislation recently introduced in the U.S. Senate would reauthorize the Rural and Municipal Utility Advanced Cybersecurity (RMUC) Grant and ...

Read more →

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The vulnerabilities have since been flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited in the wild.

Read more →

FBI investigating North Korean remote IT staffer working for US agency

Justin Doubleday covers cybersecurity, homeland security and the intelligence community for Federal News Network. ... Cybersecurity Read more.

Read more →

North Korea's hackers using AI for attacks, cybersecurity firm says - Al Jazeera

Hacking group Kimsuky using AI-generated documents in spear-phishing attacks, South Korean cybersecurity firm says.

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.