A Unisoc Modem Flaw Turns an Answered Video Call Into Android Kernel Access
Researchers published the second stage of an exploit chain that crosses from modem firmware into the Android kernel. The...
ASEAN edition · Tue, 18 Aug 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
Researchers published the second stage of an exploit chain that crosses from modem firmware into the Android kernel. The...
OpenAI, Anthropic and Google return reasoning to clients as encrypted blocks. Researchers replayed those blocks into che...
CVE-2026-20349 lets an unauthenticated attacker reload a Cisco ASA or FTD firewall through the remote-access SSL VPN. Th...
Z.ai's model edges Mythos 5 by 0.7 points on vulnerability detection and trails it by 23.6 on exploit development. The s...
GPT-5.6-Cyber completes 95 per cent of exploit-chain prompts against 1.5 per cent for the general model it is built on....
Two poisoned LiteLLM releases were live on PyPI for forty minutes in March. CloudSEK has now mapped roughly 434,000 capt...
Three different totals are circulating for the same Patch Tuesday, and all are defensible. The one number that matters i...
Birmingham researchers surveyed 26 devices and found nine expose an interface that lets the SIM issue modem commands. Th...
Every vulnerability CISA catalogued in the first week of August carried a three-day federal deadline. We measured the ca...
No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the admin dash...
Klaviyo's signup form was misconfigured so third-party marketing trackers captured what users typed, including passwords...
Ransomware crews are now chaining two SonicWall SMA1000 flaws that CISA gave federal agencies three days to fix. If your...
CERT Polska has documented the first real-world use of a private APN as a route into operational technology. Thirty wind...
Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence tool they u...
Water systems in at least twelve US states have been broken into, with attackers changing controller passwords and IP ad...
China's Cybersecurity Review Office opened a formal review into Palo Alto Networks products on 6 August — seven months a...
MIT researchers showed that Spectre v2 mitigations can be stepped around on current Intel and AMD processors, breaking K...
N-able patched a critical authentication bypass in N-central, attackers found a path the patch did not block, and a seco...
Two flaws score 9.8. The 9.3 lets an attacker with admin rights inside a virtual machine execute code on the host beneat...
Three flaws in CatchPulse, the worst letting an unprivileged local user bypass policy enforcement. Reported 26 June, pat...
CVE-2026-34486 exists because of the fix for CVE-2026-29146. CSA reports active exploitation, and the catalogue lists th...
CVE-2026-9198 gives unauthenticated remote code execution on default Langflow deployments. CISA allowed three days; CSA...
A Singapore Land Authority test dataset created in 1998 was meant to hold only mock records. It held real names, NRIC nu...
CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediation window...