Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Cyber Kendra ## Sitemaps [XML Sitemap](https://www.cyberkendra.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [Meta Announces Petal, a 1 Pbps Transatlantic Subsea Cable](https://www.cyberkendra.com/2026/09/meta-petal-petabit-subsea-cable.html): Meta has announced Petal, a subsea cable designed to carry 1 petabit per second (1 Pbps, or 1,000 terabits per second) over roughly 7,000 km (4,300 miles) between the United States and France. Meta says Petal will be the first cable to deliver petabit capacity across an ocean and the first subsea system to use multi-core optical fiber at scale. Petal is expected to enter service in 2029. - [WordPress Comment2Shell Flaw Turns Comments Into RCE](https://www.cyberkendra.com/2026/09/comment2shell-wordpress-cve-2026-93485-xss-rce.html): A single anonymous comment is enough to plant a script on a WordPress site and, if an administrator later opens that post, run code on the server. The flaw, named Comment2Shell and reported by security researcher Rafie Muhammad, was fixed in WordPress 7.1.1 on 17 September 2026. - [CVE-2026-66804: Dark Elevator Fix Left Windows Exposed](https://www.cyberkendra.com/2026/09/cve-2026-66804-dark-elevator-incomplete-fix.html): Microsoft's Dark Elevator patch was incomplete. CVE-2026-66804 abuses a dangling CrossDevice COM object to reach SYSTEM on Windows. - [Why Are Domain Renewal Fees So High? (And How to Pay Less)](https://www.cyberkendra.com/2026/09/why-are-domain-renewal-fees-so-high-and-how-to-pay-less.html): Domain names look cheap at first. Then the renewal email shows up and ruins the mood. That shock isn't an accident. Registrars often sell the first year at a discount, then charge more later because the domain now matters. A site, store, or email setup may depend on it. That changes the psychology fast. The low opening price gets attention. The renewal collects profit. Registry wholesale costs matter too, though registrar markups, support costs, and add-ons often push the final bill much higher than buyers expect. - [Google Opens Googlebook Pre-Orders at $899 With 5 Laptops](https://www.cyberkendra.com/2026/09/googlebook-price-specs-os.html): Googlebooks are officially here, and you can pre-order one right now. Google’s new line of premium laptops launched on September 21, 2026 with five models from Acer, ASUS, Dell, HP, and Lenovo, starting at $899 for the Acer Googlebook 14 and topping out at $1,299 for the ASUS Googlebook 14 and HP Googlebook 14. They hit US shelves on October 4, 2026, and buyers in Canada, the UK, Ireland, France, Germany, and Australia get them a day later. - [Download Windows 11 26H2 ISO](https://www.cyberkendra.com/2026/09/windows-11-26h2-iso-download.html): Microsoft has published Windows 11 26H2 Enterprise Evaluation ISOs, and the Windows 11 26H2 ISO can be downloaded free from Microsoft's servers as of 21 September 2026. The image installs build 26300.9457, includes the KB5129195 out-of-band (OOB, released outside the monthly schedule) update, and runs for 90 days without activation. - [GPT-6 Astra Cracks 108-Year-Old WWI German Radio Message](https://www.cyberkendra.com/2026/09/gpt-6-astra-decodes-1918-german-chiper-radio-message.html): GPT-6 Astra decoded a 1918 German ADFGVX radio message about ships at Sevastopol, using the key TRUPPENVERSCHIEBUNG. - [Google Releases AndroidX Security State 1.1.0 Stable](https://www.cyberkendra.com/2026/09/google-releases-androidx-security-state-1-1-0-stable.html): AndroidX Security State 1.1.0 is stable, letting Android apps and MDMs check component patch levels, pending updates and CVE fixes. - [Google Confirms Gemini Hacked Three Companies in Test](https://www.cyberkendra.com/2026/09/gemini-hacked-three-companies-irregular.html): Google confirms Gemini hacked three real companies in a May 2026 Irregular AI test, stopping each time. How it compares to Claude, OpenAI and Meta. - [Researchers Used Claude to Hack OpenAI Through an Image Flaw](https://www.cyberkendra.com/2026/09/researchers-used-claude-to-hack-openai-through-an-image-flaw.html): HEIF Heist chains libheif flaws like CVE-2026-32882 into RCE across OpenAI, Slack, Meta, Discourse, Next.js and GitHub Enterprise. - [How Google Broke TeamPCP From the Inside](https://www.cyberkendra.com/2026/09/how-google-broke-teampcp-from-the-inside.html): Google's Mandiant ran an undercover analyst inside TeamPCP, revoked stolen credentials at AWS and Microsoft, and tipped the FBI. - [How to Choose a Minecraft Server That Runs Smoothly](https://www.cyberkendra.com/2026/09/how-to-choose-a-minecraft-server-that-runs-smoothly.html): It's hard to enjoy a mining trip when broken blocks keep reappearing or your character snaps back down a tunnel. Players often call these problems "lag," but that term covers several different causes. Your device, your connection, and the server can all affect how Minecraft feels. - [Roblox to Run in Browser With No Download by End of 2026](https://www.cyberkendra.com/2026/09/roblox-browser-play-browser-offline-2026.html): Roblox will run in Chrome with no install by end of 2026 and add offline solo play by mid-2027. Confirmed RDC dates and limits. - [OpenAI Model Misalignment Reports: Six Cases Disclosed](https://www.cyberkendra.com/2026/09/openai-model-misalignment-reporting-framework.html): OpenAI published a framework for tracking, investigating, and disclosing model misalignment on 16 September 2026, along with six reports on unexpected or concerning behaviour observed in its models over the previous six months. The framework commits OpenAI to publishing each report soon after the behaviour is observed, even when the company has not yet explained or fixed it. - [cups2root: New CUPS Zero-Day Escalates lpadmin to Root](https://www.cyberkendra.com/2026/09/cups2root-cups-lpadmin-root-zero-day.html): cups2root is a new CUPS zero-day that escalates lpadmin users to root on Ubuntu — and it's built to work around AppArmor. No patch yet. - [A Security Checklist for AI-Assisted 3D Asset Pipelines](https://www.cyberkendra.com/2026/09/a-security-checklist-for-ai-assisted-3d.html): Generative AI is making it easier for game developers, animation teams, and digital artists to move from an idea to an initial 3D model. Instead of building every prototype from an empty scene, creators can begin with a written description and produce a model for visualisation or gameplay testing. - [How to Optimize Your Setup for Modern Warfare 4 FPS Dominance](https://www.cyberkendra.com/2026/09/how-to-optimize-your-setup-for-modern-warfare-4-fps-dominance.html): The fastest way to raise your frame rate in Call of Duty: Modern Warfare 4 is to set Graphics Quality to Custom, turn every ray tracing option off, drop Shadow Quality, Volumetric Quality and Particle Resolution to Low, set VRAM Scale Target to 80 (70 on an 8 GB card), cap your frame rate a few frames below your monitor's refresh rate, and let Background Shader Preloading finish before you queue into a match.  - [Telegram Proxy List: How to Find One That Works](https://www.cyberkendra.com/2026/09/telegram-proxy-list.html): Telegram publishes no proxy list of its own, and public proxy addresses die quickly, so a copied list is the weakest option. Working connections come from a tg://proxy link supplied by an operator you trust, a paid private proxy, or a server you run yourself (Telegram MTProxy page). - [Anthropic Threat Report Says AI Now Rebuilds Malware](https://www.cyberkendra.com/2026/09/anthropic-threat-report-says-ai-now.html): Anthropic published its fourth threat intelligence report on 10 September 2026, documenting misuse of its Claude models that the company's Threat Intelligence team detected and disrupted between December 2025 and August 2026. One case describes a suspected Russian espionage actor whose AI agents watched security products for detections of the actor's own malware, then rebuilt that malware in a loop until it stopped being detected. - [AI Agents for Sales: What’s Real and What’s a Demo](https://www.cyberkendra.com/2026/09/ai-agents-for-sales-whats-real-and.html): A recent Salesforce survey found that 54% of sellers say they've used AI agents in some form. That sounds like mass adoption until you see the next number: only 8% report any kind of autonomous workflow execution. The rest are using glorified autocomplete. - [LG Denies Smart TV Spying Claims, Confirms Network Scan](https://www.cyberkendra.com/2026/09/lg-denies-smart-tv-spying-claims.html): LG Electronics has denied claims that its smart TVs record conversations and profile home networks, telling Tom's Hardware on 9 September 2026 that "The claims made in the recently published video are not true." The company confirmed that its televisions scan local networks for other devices, describing it as a standard smart TV function. - [ShieldCrash Zero-Day Bypasses Microsoft’s ShieldBreak Patch](https://www.cyberkendra.com/2026/09/shieldcrash-zero-day-bypasses.html): Security researcher Nightmare Eclipse has released ShieldCrash, a proof-of-concept exploit that, on fully updated Windows machines, reads arbitrary files as SYSTEM by abusing Microsoft Defender. The code landed on GitHub roughly two hours after Microsoft's September Patch Tuesday, undoing a Defender fix that had been in the field for five days. - [German Police Read WhatsApp and Signal Without Breaking the Encryption](https://www.cyberkendra.com/2026/09/german-police-read-whatsapp-and-signal.html): German customs investigators have been reading WhatsApp, Signal, and Telegram messages since 1 August 2025 without breaking any encryption, using the messengers' own web and desktop clients. A classified Zollkriminalamt (ZKA) directive published by netzpolitik on 2 September 2026 shows the technique, called account cloning, moved from pilot project to permanent investigative tool after trials that began in late 2023. - [WeWorm: Zero-Click WeChat Worm Hijacks iOS and Android](https://www.cyberkendra.com/2026/09/weworm-zero-click-wechat-worm-ios-android.html): Security firm Calif has disclosed WeWorm, a zero-click worm that hijacks WeChat accounts via a regular voice call on both iOS and Android. The victim taps nothing — the account falls while the phone is still ringing, and the worm then calls that person's contacts to repeat the process. - [Why Facebook Ads Look Brighter Than Other Feed Posts](https://www.cyberkendra.com/2026/09/facebook-ads-brighter-hdr-feed.html): Facebook ads in the mobile feed are being rendered in HDR on phones that support it, which is why a sponsored post can look visibly brighter, punchier, and more saturated than a friend's photo sitting directly above it. The ad is not overlaying anything on your screen, and it is not changing your brightness setting — your display is pushing those specific pixels past normal SDR white because the ad creative carries high dynamic range data and the rest of your feed does not. - [ChatGPT, Claude, Grok Outage: Two Causes, Not One](https://www.cyberkendra.com/2026/09/chatgpt-claude-grok-outage-two-causes.html): Updated 5 September 2026: SpaceXAI has confirmed that the Grok outage of 3 September 2026 began at its Memphis compute center, and an OpenAI engineer says the ChatGPT failure that morning was a separate routing error. Neither company has published a full technical postmortem. - [FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor](https://www.cyberkendra.com/2026/09/falconflank-zero-day-hits-crowdstrike.html): A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The researcher — who also uses the aliases Nightmare-Eclipse, MSNightmare, and INFINITE NIGHTMARE — published working exploit code to GitHub on September 3, 2026, without giving CrowdStrike advance notice. - [ChatGPT, Claude and Grok Down in Rare Joint Outage](https://www.cyberkendra.com/2026/09/chatgpt-claude-grok-down-outage.html): Update, 5 September 2026: SpaceXAI has blamed its Memphis compute center for the Grok outage and apologised to affected compute partners, and an OpenAI engineer says ChatGPT's failure was a separate routing error. Full breakdown: ChatGPT, Claude, Grok Outage: Two Causes, Not One. - [Nvidia to Acquire Hugging Face for $12.9 Billion](https://www.cyberkendra.com/2026/09/nvidia-to-acquire-hugging-face-for-129.html): NVIDIA has agreed to acquire Hugging Face for $12,930,300,000, founder and CEO Jensen Huang announced on the company's blog on 3 September 2026. The deal hands the default home of open-source AI — more than 3 million models used by over 18 million developers — to the company that sells the GPUs most of those models run on. - [Stale GitHub Token Let ChainDrop Worm Poison Keyv, Cacheable](https://www.cyberkendra.com/2026/08/stale-github-token-let-chaindrop-worm.html): Jared Wray, founder and CEO of Hyphen AI and maintainer of the Keyv and Cacheable npm packages, has published a postmortem confirming that a stale full-access GitHub personal access token was the entry point for the ChainDrop supply chain worm. The August 31 disclosure is the first account from inside the compromise that tore through npm on August 4, 2026. - [PrettyPrague Zero-Day Exploit Hits Avast Antivirus](https://www.cyberkendra.com/2026/08/prettyprague-zero-day-exploit-hits.html): A security researcher known as Chaotic Eclipse has released a working proof-of-concept exploit for an unpatched privilege escalation vulnerability in Avast Antivirus, the consumer security suite owned by Gen Digital. The exploit, named PrettyPrague, abuses a flaw in the Avast Sandbox to dump the Windows SAM credential database and spawn a shell running as NT AUTHORITY\SYSTEM. - [Virtualizor Compromised via BGP Hijack, Hosts Hit Hard](https://www.cyberkendra.com/2026/08/virtualizor-compromised-via-bgp-hijack.html): A BGP hijack against Virtualizor's update infrastructure pushed a malicious package onto VPS hypervisors running the panel, handing attackers root on every node that installed it. Hosting provider DreamIT raised the alarm on LowEndTalk shortly after midnight on 31 August, and Virtualizor confirmed it later that day. - [Why Speed, Not Volume Decides Your Exposure Window](https://www.cyberkendra.com/2026/08/why-speed-not-volume-decides-your.html): Vulnerability exploitation timelines have been falling steadily for years. Frontier AI tools have made them collapse. The exposure window - the time between vulnerability disclosure and remediation - has all but disappeared.  - [cPanel Patches CVE-2026-65643 Root Code Execution Flaw](https://www.cyberkendra.com/2026/08/cpanel-patches-cve-2026-65643-root-code.html): cPanel has patched CVE-2026-65643, a flaw in its domain parking and addon domain functionality that lets an ordinary hosting customer write files anywhere on the server and escalate to root.  - [Next.js Patches Two Critical RCE Flaws in 15.5.24, 16.3.3](https://www.cyberkendra.com/2026/08/nextjs-patches-two-critical-rce-flaws.html): Vercel has patched two critical remote code execution flaws in Next.js: one that triggers when the framework optimizes an attacker-supplied AVIF image, and one that only fires when the server runs on a Windows filesystem. Both fixes shipped in Next.js 16.3.3 (Active LTS) and 15.5.24 (Maintenance LTS) on August 25, 2026, a day ahead of the scheduled release date. - [OpenAI Cyber Defense Letter Signed by 116 Companies](https://www.cyberkendra.com/2026/08/openai-cyber-defense-letter-signed-by.html): OpenAI published an open letter today, calling for a global surge in cyber defence, and 116 organisations signed it — Anthropic, Google, Microsoft, AWS, Cisco, IBM, CrowdStrike, Palo Alto Networks, Visa, and Mastercard among them. - [Core Lightning Vulnerabilities Prompt CLN Offline Warning](https://www.cyberkendra.com/2026/08/core-lightning-vulnerabilities-prompt.html): Blockstream’s Core Lightning team has told node operators to install an embargoed security build or shut their nodes down, after a run of AI-generated vulnerability reports landed on the project during August. The instruction went out in the Core Lightning Discord rather than in a public advisory, and Bitcoin developer and BIP maintainer Mark “Murch” Erhardt confirmed on Stacker News that a CLN maintainer had verified the message as genuine. - [Signal Contact Discovery Enclave Flaws Allow Code Execution](https://www.cyberkendra.com/2026/08/signal-contact-discovery-enclave-flaws.html): Security research firm V12 has disclosed two vulnerabilities in Signal's Contact Discovery Service that allowed the untrusted server host to break out of the Intel SGX enclave that protects users' address books. Researcher Nihal demonstrated both flaws on the same class of hardware Signal runs in production, extracting the enclave's private key and defeating the confidentiality guarantee that private contact discovery is built on. - [Using VPNs to Prevent IP Tracking and Network Targeting](https://www.cyberkendra.com/2026/08/using-vpns-to-prevent-ip-tracking-and.html): The internet of today is a world apart from the internet of the 2000s and even of the 2010s. New industries and new technologies yield new online risks, and changing legislation only serves to make it more difficult for web users to navigate the ‘net safely. - [How Critical Materials Shape the Cybersecurity Hardware Industry](https://www.cyberkendra.com/2026/08/how-critical-materials-shape.html): Cybersecurity is usually discussed in terms of software, encryption and digital threats, but every security system ultimately depends on physical technology. From secure servers to network appliances, the materials inside the hardware can influence its performance, availability, cost and reliability. - [Log4j Deserialization Bypass Is Real but Not Log4Shell](https://www.cyberkendra.com/2026/08/log4j-bug-report-pulled-researcher.html): A security researcher using the handle U-Sec (Wujie Security) published details of a deserialization filter bypass in Apache Log4j 2, reporting that the framework's FilteredObjectInputStream allowlist can be sidestepped with java.rmi.MarshalledObject to smuggle arbitrary objects past its class checks. - [GTA 6 Leaks: Rockstar Responds, Calls It Heartbreaking](https://www.cyberkendra.com/2026/08/gta-6-leaks-rockstar-responds-calls-it.html): Rockstar Games broke its silence on the Grand Theft Auto VI leaks on 26 August 2026, calling the situation "heartbreaking for our team" in a signed statement posted to social media. It is the studio's first public comment since a leaker calling itself CyberLeek began posting gameplay clips on 18 August. - [Mac mini M6 Price in India Starts at Rs 99,900](https://www.cyberkendra.com/2026/08/mac-mini-m6-mac-studio-m5-ultra-price-specs.html): Apple announced the new Mac mini with the M6 and M5 Pro chips and the new Mac Studio with M5 Max and the all-new M5 Ultra on 25 August 2026. Pre-orders opened the same day in 30 countries and regions, including India, with deliveries from 22 September 2026. - [BGMI Lite Pre-Registration Starts August 25](https://www.cyberkendra.com/2026/08/bgmi-lite-pre-registration-starts.html): BGMI Lite is finally moving from announcement to action. KRAFTON India had opened pre-registration for Battlegrounds Mobile India Lite on August 25, 2026, giving Android users in India their first official way to sign up ahead of the game's full launch later this year. - [Top 5 OSINT Services for UK Businesses in 2026](https://www.cyberkendra.com/2026/08/top-5-osint-services-for-uk-businesses.html): A fraud team we heard about nearly signed a six-figure supplier contract with a company that, as it turned out, didn't exist past a website and a LinkedIn page. One afternoon of digging found the gap. That's the entire pitch for open source intelligence services — public information, properly investigated, before it costs you. - [How YouTube Channels Get Taken Over](https://www.cyberkendra.com/2026/08/how-youtube-channels-get-taken-over.html): Channel takeovers follow a pattern that has barely changed in years. A creator receives a sponsorship offer, downloads a file to review the product, and loses the channel within the hour. The attacker renames it, streams a cryptocurrency scam, and the original owner spends weeks trying to get support to answer. - [T-Mobile Cut Cable to Eject Salt Typhoon Hackers](https://www.cyberkendra.com/2026/08/t-mobile-cut-cable-to-eject-salt.html): T-Mobile ended its months-long hunt for Salt Typhoon in November 2024 by driving to a data center and physically cutting the network cable feeding a compromised router. Jeff Simon — the carrier's chief security officer during the campaign and now its chief information officer — disclosed the previously unreported details in an interview with Bloomberg News. - [Elementor Pro RCE Flaw CVE-2026-32475 Hits Form Uploads](https://www.cyberkendra.com/2026/08/elementor-pro-rce-flaw-cve-2026-32475.html): A critical flaw in Elementor Pro lets an unauthenticated visitor upload a PHP file through an ordinary contact form and execute it on the server. Researcher Tin Pham, also known as TF1T, reported the bug to Patchstack, and Elementor shipped the fix in version 4.2.2 on 19 August 2026. - [7 Reasons Enterprises Are Adopting Autonomous Endpoint Management Tools in 2026](https://www.cyberkendra.com/2026/08/enterprise-autonomous-endpoint-management-adoption.html): Endpoint operations now span office networks, homes, branch sites, cloud workloads, and devices that connect irregularly. Periodic inventory and manually sorted queues cannot always keep pace with software changes, new vulnerabilities, configuration drift, and employee issues across that estate. - [GTA 6 Gameplay and Map Leak: All the New Details](https://www.cyberkendra.com/2026/08/gta-6-leak-rockstar-takes-down-gameplay.html): Two Grand Theft Auto VI gameplay clips and a full map of Leonida leaked online on 18 August 2026, and Rockstar Games started issuing DMCA takedowns within hours. Between them, the videos show a six-star wanted level, a stamina bar during fistfights, fuel and engine gauges on cars, and a karma system that judges Jason for his actions. - [Amazon Scans and Destroys Rare Books for AI Training – Report](https://www.cyberkendra.com/2026/08/amazon-scans-and-destroys-rare-books.html): Amazon is buying printed books in bulk, cutting the bindings off, scanning the pages for AI training data and discarding the paper, according to a 404 Media investigation published on 17 August 2026. Reporter Emanuel Maiberg confirmed the operation by hiding an Apple AirTag inside one book in a 1,000-title order and tracking it across the United States. - [Apple Patches 122 Flaws including macOS Screen Sharing Flaw (CVE-2026-65400)](https://www.cyberkendra.com/2026/08/apple-patches-122-flaws-including-macos.html): Apple shipped four security updates on August 17, 2026, fixing 122 vulnerabilities in iOS 18.7.10 and iPadOS 18.7.10, 29 in iOS 26.6.1 and iPadOS 26.6.1, and 28 in macOS Tahoe 26.6.2. None of the flaws in this batch are known to have been exploited — but a separate macOS bug Apple patched eleven days earlier is being used right now to plant cryptominers on internet-facing Macs. - [Copilot Autofix Bug Exposed Snowflake’s Internal Jira](https://www.cyberkendra.com/2026/08/copilot-autofix-snowflake-jira-github-actions.html): Wiz Research's autonomous "Red Agent" found and exploited a script injection flaw in Snowflake's public snowflake-connector-net repository, using nothing but a crafted GitHub issue title to steal credentials for Snowflake's internal Jira.  - [GitHub Down as Outage Hits Actions, API and Copilot](https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html): Status: MOSTLY RECOVERED — COPILOT STILL DOWN. At 16:59 UTC GitHub declared the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks, and all seven are back to Operational. Copilot was not named in that update and is still marked as a Major Outage. The incident remains open while GitHub monitors for stability. - [Microsoft’s SCCM Hotfix Fixes Only One of Four RCE Bugs](https://www.cyberkendra.com/2026/08/microsofts-sccm-hotfix-fixes-only-one.html): Security researcher Omri Baso has disclosed a remote code execution chain in Microsoft Configuration Manager (SCCM/ConfigMgr) that lets an ordinary Active Directory user seize SYSTEM control of a Primary Site Server — and every client it manages. Microsoft has patched only one link in that chain, CVE-2026-47301, leaving the full path to code execution open until a later release. - [Apple Warns iPhone Users of Mercenary Spyware Attacks](https://www.cyberkendra.com/2026/08/apple-threat-notification-mercenary-spyware.html): Apple sent a fresh round of mercenary spyware threat notifications to users in 110 countries on Thursday, and for the first time, the warning lands as a push alert on the iPhone Lock Screen instead of an email that can sit unread for a week. Apple confirmed the round's scale to TechCrunch and published a revised support page describing the new delivery method the same day. - [Namecheap Outage Hits Hosting, DNS and Private Email](https://www.cyberkendra.com/2026/08/namecheap-outage-hits-hosting-dns-and.html): Websites, business email, and DNS for a large slice of Namecheap's customer base went dark on 13 August 2026 after the cooling system at the Phoenix data center hosting the company's core infrastructure failed. By Namecheap's own count, more than 5,000 servers were taken offline — not by the failure itself, but by a deliberate shutdown to stop hardware cooking in a data hall that had lost its chillers. - [Trezor Says ShipMonk Breach Exposed 13,689 Customers](https://www.cyberkendra.com/2026/08/trezor-says-shipmonk-breach-exposed.html): Nearly 14,000 people who bought a Trezor hardware wallet this summer now have their names and home addresses sitting in the hands of an unknown attacker — a list that identifies them, by address, as crypto holders. - [CVE-2026-63520: SharePoint RCE Patched by Microsoft](https://www.cyberkendra.com/2026/08/cve-2026-63520-sharepoint-rce-patched.html): Rapid7 and Microsoft have disclosed CVE-2026-63520, a remote code execution flaw in Microsoft SharePoint that completes an unauthenticated exploit chain Rapid7 Labs built for Pwn2Own Berlin. Senior Principal Security Researcher Stephen Fewer found it using an AI agent workflow, and Microsoft shipped the fix in its August 11 update cycle. - [LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms](https://www.cyberkendra.com/2026/08/litellm-breach-434000-cicd-pipelines-exposed.html): Two threat intelligence firms have published victim data from the March 2026 LiteLLM supply chain attack, and the scale is far beyond anything known when the malicious packages were pulled. CloudSEK counts more than 2,500 potentially exposed organisations and roughly 434,000 CI/CD pipelines, while Hudson Rock says it independently obtained the attackers' raw exfiltration archive and attributed 118,829 CI runner dumps to 2,488 corporate domains. - [ShieldBreak PoC Bypasses Microsoft’s RoguePlanet Defender Fix](https://www.cyberkendra.com/2026/08/shieldbreak-poc-bypasses-microsofts.html): Security researcher Nightmare Eclipse has released ShieldBreak, a proof-of-concept exploit that defeats the patch Microsoft shipped five weeks ago for a Windows Defender privilege escalation flaw. - [Anthropic to Watermark All Claude-Generated Text](https://www.cyberkendra.com/2026/08/anthropic-claude-text-watermarking-eu-ai-act.html): Anthropic has detailed plans to mark content generated by its Claude models, embedding invisible watermarks directly into generated text and attaching cryptographically signed provenance metadata to generated files. - [YouTube Now Wants 8,000 Watch Hours for Monetisation](https://www.cyberkendra.com/2026/08/youtube-now-wants-8000-watch-hours-for.html): Most of the attention on YouTube's August 10 announcement went to the double-entry bar for newcomers. The change with longer teeth applies to the three million creators already inside the YouTube Partner Program (YPP). - [Microsoft Leaves Windows Passkey Prompt Spoofing Unfixed](https://www.cyberkendra.com/2026/08/microsoft-leaves-windows-passkey-prompt.html): Three weeks before Microsoft makes passkeys the default sign-in method for Entra ID, new research shows that the Windows dialog protecting them can be faked well enough to fool the people who build security products for a living — and that Microsoft has decided the underlying weakness isn't worth patching. - [Windows 11 Kernel 0day PoC Drops Before Patch Tuesday](https://www.cyberkendra.com/2026/08/windows-11-kernel-0day-poc-drops-before.html): An anonymous researcher has published proof-of-concept (PoC) code for what they describe as an unpatched local privilege-escalation flaw in Windows 11, posting the writeup online just a day before Microsoft's August Patch Tuesday. If the claims hold, a standard user on a fully updated Windows 11 25H2 machine could use the bug to push code toward SYSTEM-level control — the highest privilege on the box. - [DeadLock Ransomware Puts Its Negotiation Portal On-Chain](https://www.cyberkendra.com/2026/08/deadlock-ransomware-puts-its.html): Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one. - [Researchers Buy ‘No Reply’ Domains and Get Company Data](https://www.cyberkendra.com/2026/08/researchers-buy-no-reply-domains-and.html): Fifteen dollars is roughly what it costs to start reading email your company thinks nobody receives. Two security researchers who quietly bought placeholder domains — the ones enterprise systems fall back on when an address is retired or an alert needs a fake sender — have collected hundreds of thousands of misdirected corporate messages, and their own scanning suggests hundreds of similar domains are already sitting on live inboxes. - [Metabase Zero-Day Exposes Framework, Tally Customer Data](https://www.cyberkendra.com/2026/08/metabase-zero-day-exposes-framework.html): Two companies told customers this week that their personal data had been stolen. Neither was breached directly. The attacker walked in through the analytics dashboard, which was both wired to their production databases. - [Public Exploit Lands for WordPress XSS2Shell Core Flaw](https://www.cyberkendra.com/2026/08/public-exploit-lands-for-wordpress.html): A working proof-of-concept exploit for "XSS2Shell" is now circulating publicly, raising the stakes on a WordPress Core flaw that turns a single failed login into attacker-controlled JavaScript — and, against an administrator, full server takeover.  - [Meta AI Breach Turns Spotlight on Testing Firm Irregular](https://www.cyberkendra.com/2026/08/meta-ai-breach-turns-spotlight-on.html): Meta confirmed on Wednesday that one of its AI models reached the open internet and hacked a third-party service during a security evaluation. It is the third such admission from a major AI lab in weeks — and the second traced back to the same testing vendor. - [Zapscape KVM Flaw Lets Guest VMs Seize Host Root](https://www.cyberkendra.com/2026/08/zapscape-kvm-flaw-lets-guest-vms-seize.html): Security researcher Hyunwoo Kim closed out his KVM escape trilogy today with Zapscape (CVE-2026-64561), and this time he shipped the whole thing.  - [The New Attack Surface: How Cybercriminals Are Using AI to Target Developers](https://www.cyberkendra.com/2026/08/the-new-attack-surface-how.html): Cybercriminals are increasingly targeting developers in attacks. One of the major factors behind the trend is access. Developers often work on a wide range of internal and external projects. Compromising a developer's system can give a cybercriminal a way into the wider infrastructure. - [Mac Malware Checks Your GPU Before Showing Its Lure](https://www.cyberkendra.com/2026/08/mac-malware-checks-your-gpu-before.html): The crews behind a long-running macOS scam have started doing something defenders usually do: vetting who is on the other end of a connection before committing to an attack. - [Researchers Chain WordPress RCE to Fileless Linux Root](https://www.cyberkendra.com/2026/08/researchers-chain-wordpress-rce-to.html): Security researchers have shown that the critical wp2shell WordPress flaw doesn't have to stop at a web shell — it can be chained all the way to full Linux root, without writing a single file to disk. More striking, they assembled the entire chain with an AI coding agent in under an hour. - [Blogger Malware Lockout: What Happened and What to Do](https://www.cyberkendra.com/2026/08/bloggers-malware-glitch-dont-touch-your.html): What follows is the full record: what happened, why restored blogs kept getting locked a second time, and how to make sure a platform-side classifier can never take your archive offline again. - [Gmail to End “Send As” for Outlook and Yahoo Addresses](https://www.cyberkendra.com/2026/08/gmail-to-end-send-as-for-outlook-and.html): Google has put a date on the retirement of one of Gmail's oldest power-user features. Starting January 2027, the "Send as" option that lets you fire off a message from a Yahoo, Outlook, or custom-domain address without leaving your Gmail inbox will stop working — on the web and in the Android and iPhone apps alike. - [Human Reviewer Caught AI Agent’s Malware Pull Request](https://www.cyberkendra.com/2026/08/human-reviewer-caught-ai-agents-malware.html): The thing that stopped an AI agent from poisoning a public open-source project last month wasn't a firewall, a classifier, or a sandbox. It was one suspicious developer who decided to detonate a strange script in a throwaway container before trusting it. - [Phishers Abuse Service Workers to Hijack Microsoft Logins](https://www.cyberkendra.com/2026/08/phishers-abuse-service-workers-to.html): A phishing campaign documented by Kaspersky turns an ordinary browser feature into a credential-stealing proxy, letting attackers walk away with Microsoft 365 session tokens even after the victim clears multi-factor authentication. - [Cloudflare Gives AI Agents a Wallet and a Spending Cap](https://www.cyberkendra.com/2026/08/cloudflare-gives-ai-agents-wallet-and.html): Cloudflare has started handing out wallet handles to its customers, and the pitch sounds like a convenience feature: let your AI agent buy the API it needs without pinging you for a credit card. Read the fine print, though, and the more interesting product is the ceiling.  - [cPanel Bug Hands Database Root to Any Hosting Customer](https://www.cyberkendra.com/2026/08/cpanel-bug-hands-database-root-to-any.html): For three months, the cPanel security story has been about attackers forcing the front door. The vendor's newest release flips that script: this time, the person holding the keys is a paying customer on the same box as everyone else. - [npm Worm Hits keyv and cacheable, Spreads to 400 Packages](https://www.cyberkendra.com/2026/08/npm-worm-hits-keyv-and-cacheable.html): A self-propagating worm tore through the npm registry on Tuesday morning, trojanizing the widely used keyv and cacheable caching libraries and spreading to more than 400 packages within hours. Wiz Research, Socket, and Microsoft Threat Intelligence are all tracking the campaign, which is still live at the time of writing. - [GitHub Source Code Allegedly Up for Sale Again](https://www.cyberkendra.com/2026/08/github-source-code-allegedly-up-for.html): The internal source code stolen from GitHub in May is allegedly back on the market, and this time the seller is showing samples to prove it. - [Is It Possible to Track Brand Mentions in AI Search?](https://www.cyberkendra.com/2026/08/is-it-possible-to-track-brand-mentions.html): Yes. It is possible to track brand mentions in AI search, and you can start today at no cost. - [macOS Screen Sharing Bug Handed Hackers Root, No Password](https://www.cyberkendra.com/2026/08/macos-screen-sharing-bug-handed-hackers.html): A critical vulnerability in Apple's Screen Sharing service let unauthenticated attackers take over a targeted Mac over the network — reading and writing files as root with no password, no username, and no user interaction. In the researchers' tests, a single pipelined connection could drop a root shell in under 60 seconds.  - [How to Track Brand Mentions in AI Search — And Why Your Logs Are Lying](https://www.cyberkendra.com/2026/08/how-to-track-brand-mentions-in-ai-search.html): Ask any marketer how to track brand mentions in AI search, and you will get the same answer: pick a tool, feed it prompts, and watch the dashboard. Ask a security engineer the same question, and you get a different one: how do you know any of that data is real? - [Which Zero-Trust Steps Harden Low-Code Deployments?](https://www.cyberkendra.com/2026/08/which-zero-trust-steps-harden-low-code.html): Low-code and no-code platforms have moved from experimental side projects to core business tools. Marketing teams build customer portals, finance departments automate approvals, and operations staff assemble dashboards without waiting for traditional development cycles. This speed carries a hidden cost, since every rapidly built application widens the attack surface.  - [Coldcard Sweeps Hit $89M as Attacker Rewrites Playbook](https://www.cyberkendra.com/2026/08/coldcard-sweeps-hit-89m-as-attacker.html): A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC — close to $89 million — drained from 4,585 addresses since Thursday. - [Azure Cosmos DB Flaw Gave Up Keys to Every Database](https://www.cyberkendra.com/2026/07/azure-cosmos-db-flaw-gave-up-keys-to.html): Microsoft has closed a vulnerability chain in Azure Cosmos DB that would have let anyone with a throwaway test account read and write data in every database on the service — including the internal ones behind Entra ID, Teams, and Copilot. - [Claude AI Uploaded Malware to PyPI During a Safety Test](https://www.cyberkendra.com/2026/07/claude-ai-uploaded-malware-to-pypi.html): For about an hour earlier this year, a working piece of malware sat on PyPI, the public registry that virtually every Python developer pulls from. Fifteen real machines downloaded and executed it.  - [Windows Event Log Bug Lets Hackers Run Code Remotely](https://www.cyberkendra.com/2026/07/windows-event-log-bug-lets-hackers-run.html): A newly disclosed Windows vulnerability gives attackers a surprisingly quiet path to code execution on machines they should have no business touching — and all they need is a set of stolen low-privilege credentials. - [Microsoft Ties Windows Volume Activation to TPM Chips](https://www.cyberkendra.com/2026/07/microsoft-ties-windows-volume.html): The server sitting in your company's rack, quietly activating every Windows machine on the network, is about to need a hardware background check. Microsoft is rebuilding Key Management Service activation around Trusted Platform Module attestation, and the practical effect for IT teams is blunt: some existing KMS hosts will simply stop qualifying for the job. - [KindaRails2Shell – Critical Rails Flaw Leaks Secrets — Patching Isn’t Enough](https://www.cyberkendra.com/2026/07/kindarails2shell-critical-rails-flaw.html): Ruby on Rails shipped emergency releases on July 29 for a critical vulnerability that lets an unauthenticated attacker read arbitrary files from a server — but the line administrators keep skipping is buried further down the advisory. Upgrading closes the hole. It does not unsteal anything already taken. - [AI Cracks NIST Post-Quantum Finalist in 60 Hours](https://www.cyberkendra.com/2026/07/ai-cracks-nist-post-quantum-finalist-in.html): The list of post-quantum signature schemes that looked unbreakable until they weren't just got one name longer. Rainbow fell to a laptop in a weekend. SIKE fell in about an hour. HAWK — the last lattice-based candidate standing in NIST's additional signatures competition — fell this week to an AI model that spent 60 hours on the problem and roughly $100,000 in API credits. - [Rogue OpenAI Agent Used JFrog Zero-Day to Escape Sandbox](https://www.cyberkendra.com/2026/07/rogue-openai-agent-used-jfrog-zero-day.html): The missing piece in this month's autonomous AI breach finally has a name: JFrog Artifactory. - [WhatsApp Web Now Does Video Calls, No App Required](https://www.cyberkendra.com/2026/07/whatsapp-web-now-does-video-calls-no.html): The browser version of WhatsApp has spent a decade as the compromise option — fine for typing, useless the moment someone wanted to talk. That ended today. WhatsApp announced that users can now make and receive audio and video calls, one-on-one and group, directly from WhatsApp Web with no app download required. - [Apple kills iPhone Upgrade Program for Klarna leases](https://www.cyberkendra.com/2026/07/apple-kills-iphone-upgrade-program-for.html): Apple today launched Apple Upgrade, a US leasing program for iPhone, iPad, Mac, and Apple Watch provided by Klarna. It replaces the iPhone Upgrade Program and iPhone Payments, both of which Apple has stopped offering to new customers as of today. - [AI Agent Finds Firefox JIT Flaw That Also Broke Tor](https://www.cyberkendra.com/2026/07/ai-agent-finds-firefox-jit-flaw-that.html): Mozilla has patched a JavaScript engine bug that let attackers run code inside Firefox's renderer process, and the Tor Project has now backported the fix to the browser its users rely on for anonymity. - [Apple MIE Bypassed by Two macOS Kernel Bugs](https://www.cyberkendra.com/2026/07/apple-mie-bypassed-by-two-macos-kernel.html): Security firm Calif has released technical details of the two macOS vulnerabilities it used to break Apple's Memory Integrity Enforcement (MIE) — and rather than save the exploit for its Black Hat talk, the company is handing the bugs to the public as an open contest for human and AI researchers alike. - [Microsoft’s Cyber AI Beats Frontier Models at Half the Cost](https://www.cyberkendra.com/2026/07/microsofts-cyber-ai-beats-frontier.html): Microsoft's answer to AI-powered attackers isn't a bigger model. It's a smaller, cheaper one that already knows what it's hunting for. - [UnAuth vBulletin RCE Exploit Goes Public Weeks After Patch](https://www.cyberkendra.com/2026/07/unauth-vbulletin-rce-exploit-goes.html): A working exploit for a critical vBulletin flaw is now circulating in the open, handing unauthenticated attackers a direct route to running PHP code on forum servers — no account, no login required. The uncomfortable part: the fix has been sitting on vBulletin's patch server for nearly a month, so any administrator who skipped it is now racing a public proof-of-concept. ## Pages - [Blog](https://www.cyberkendra.com/blog) - [Image To PDF](https://www.cyberkendra.com/image-to-pdf) - [Home](https://www.cyberkendra.com/) - [Safelink](https://www.cyberkendra.com/safelink): Wait for a while... - [Image Creator](https://www.cyberkendra.com/image-creator): const socialMediaIds = ['website', - [Reverse Image Search](https://www.cyberkendra.com/reverse-image-search): Find visually similar photos on your mobile with Reverse Image Search by Google - [Image to PDF Converter](https://www.cyberkendra.com/image-to-pdf-converter): } - [Track SMS Sender Codes in India – Free Tool](https://www.cyberkendra.com/sms-tracker): Have you ever noticed those cryptic codes like "VD-SBICRD" or "JK-RTRNDS" when you receive SMS messages from banks, retailers, or other businesses?  - [AdSense Earnings Calculator](https://www.cyberkendra.com/adsense-earnings-calculator) - [Printable Calendar](https://www.cyberkendra.com/printable-calendar): United StatesIndiaJapanChina - [Nepali Date Converter](https://www.cyberkendra.com/nepali-date-converter): IndiaNepalUnited StatesUnited KingdomJapanAustralia - [Internet Speed Test](https://www.cyberkendra.com/internet-speed-test): 0.0 Mbps - [JWT Decoder](https://www.cyberkendra.com/jwt-decoder): JWT Decoder JSON Web Tokens Decoder Warning: JWTs are credentials, which can grant access to resources. Be careful where you paste them! We do not record tokens, all validation and debugging is done on the client side. Decode Header Payload Signature - [Morse Code Decoder and Encoder Tool](https://www.cyberkendra.com/morse-code-decoder-and-encoder-tool): Morse Code Encoder/Decoder - [Hamster Kombat Daily Combo 7 August [Daily Updated]](https://www.cyberkendra.com/hamster-kombat-daily-combo-cards): Check out our Daily updated Hamster Game Keys and Cipher Codes. - [Hamster Kombat: Daily Cipher Codes August 7 [Daily Updated]](https://www.cyberkendra.com/hamster-kombat-daily-cipher-codes): Check out our Daily updated Hamster Game Keys and Combo Cards. - [Safelink Generator](https://www.cyberkendra.com/safelink-generator): Original URL Generate Generated URL - [Bookmark](https://www.cyberkendra.com/bookmark): Add your favorite articles to the list. Simply click the on any bookmark icon button to get started. - [Free Image to WebP Converter Online — No Upload, No Quality Loss](https://www.cyberkendra.com/webp-compressor-and-converter): Click on Image to Download it. - [AI Content Detector](https://www.cyberkendra.com/ai-content-detector): } - [Random IP Generator](https://www.cyberkendra.com/random-ip-generator): body { - [All Post](https://www.cyberkendra.com/all-post) - [Log4Shell 💣- Advisory – Resource & Cheat Sheet](https://www.cyberkendra.com/log4shell): On December 9, 2021, A critical remote code execution vulnerability impacting at least Apache Log4j 2 (versions 2.0 to 2.14.1) was recently announced by Apache. This vulnerability is designated by Mitre as CVE-2021-44228 with the highest severity rating of 10.0. The vulnerability is also known as Log4Shell or LogJam by security researchers. If exploited, this vulnerability allows adversaries to potentially take full control of the impacted system. - [XSS Cheat Sheet](https://www.cyberkendra.com/xss-cheat-sheet):  When XSS entry point in HTML attribute has blacklisted symbols, like Round Brackets / Parentheses (), Single Quotes ' ' , Space " " or any other character - you can try these Payloads for Bypass. - [Site Map](https://www.cyberkendra.com/site-map-2) - [Who’s Got Pwned 😟 – Breached List](https://www.cyberkendra.com/data-breached-list): (2019) Canava (2019) Canvan, an online graphic-design tool suffered a massive data breach on May 2019. Over 139 Million registered users data stolen but financial data are safe. Breach Date: 24 May 2019 Hacked Accounts: 139 million Hacked Data: Usernames, Real Names, email address, city and country data. Flipboard (2019) Flipboard was a popular news aggregator service that have suffered from the data breach, where users data were stolen. Breach Date: May 2019 Hacked Accounts: Unknown Hacked Data: Usernames and Password (hashed). Advisory: Link StackOverflow (2019) Popular question and answering site, Stack Overflow have reported a security breach where they confirmed that attackers have gained accessed to its production system Breach Date: 11 May 2019 Hacked Accounts: Unknown Hacked Data: IP address, names, emails. Advisory: Link Binance (2019) Binance, one of the largest cryptocurrency exchanges in the world suffered data breach were company had a loss of $41 million in Bitcoin. Its appeared to be the largest crypto hack. Breach Date: 7 May 2019 Hacked Accounts: Unknown Hacked Data: 7,000 bitcoins (worth $40 million), Users information, API keys, two-factor authentication codes. Wyzant (2019) Wyzant—an online marketplace that makes it easy for parents and students to connect with private tutors, in-person and online, in over 250 different subjects—has suffered a data breach exposing "certain personal identification information" for its customers. Breach Date: 27 April 2019 Hacked Accounts: Unknown Hacked Data: First name, Last name, email address, zip code Docker Hub (2019) Docker Hub, one of the largest cloud-based library of Docker container images, has suffered a data breach after an unknown attacker gained access to the company's single Hub database. Breach Date: 25 April 2019 Hacked Accounts: 190,000 Hacked Data: Users Name, Password (hashed), Github and Bitbuckets Tokens. Docker Hub (2019) Docker Hub, one of the largest cloud-based library of Docker container images, has suffered a data breach after an unknown attacker gained access to the company's single Hub database. Breach Date: 25 April 2019 Hacked Accounts: 190,000 Hacked Data: Users Name, Password (hashed), Github and Bitbuckets Tokens. Microsoft Outlook (2019) Unknown hacker or group of hackers had compromised Microsoft Support agent portal, and accessed customers informations. Breach Date: 1 January 2019 to 28 March 2019 Hacked Accounts: Not Disclose Hacked Data: Users informations and credentials. Facebook (2019) Cybersecurity firm UpGuard found couple of opened Amazon cloud severs which was having more than 146 GB of datasets of facebook users. Breach Date: 1 January 2019 to 28 March 2019 Hacked Accounts: 540 Million Hacked Data: Users comments, likes, reactions, account names, Facebook user IDs, checked-in locations,names, plaintext passwords and email addresses. VFEmail(2019) Hackers hacked into the database of VFEmail and wipe out all its database leaving nothing behind. Breach Date: 11 February 2019 Hacked Accounts: All Database Wipe out Hacked Data: Database hacked and deleted. Airbus (2019) One of the Airbus system was beached which mainly deals with the data of professional contact and IT identification details. Breach Date: Hacked Accounts: Unconfirmed Hacked Data: Employee Data - [About Us](https://www.cyberkendra.com/about-us): Cyber Kendra is a website that provides information on the latest trends, news, and updates in cybersecurity. It’s a resourceful platform for those interested in cybersecurity, ethical hacking, and technology news. The website features articles on various topics, including security vulnerabilities, exploits, hacking news, and other related subjects. - [Contact Us](https://www.cyberkendra.com/contact-us): carecyberkendra@gmail.com - [Disclaimer](https://www.cyberkendra.com/disclaimer-2): The information provided on Cyber Kendra is for general informational and educational purposes only. All content is written and approved by our authors. We make no representations or warranties of any kind, express or implied, about the completeness or suitability with respect to any blog posts or articles on this site for any purpose. Any reliance you place on such information is therefore strictly at your own risk. - [Privacy Policy](https://www.cyberkendra.com/privacy-policy): Privacy Policy for www.cyberkendra.com If you require any more information or have any questions about our privacy policy, please feel free to contact us by email at carecyberkendra@gmail.com. - [Thank You Message](https://www.cyberkendra.com/thank-you-message): Thank you for taking time and writing to us. We will respond to your email as soon as possible. Till then enjoy reading Cyber Kendra