Blogs & insights
Latest Dark Nuvens blogs
AI is changing the game and so are the risks
Artificial Intelligence (AI) is transforming businesses operations, from automating tasks to analysing data faster than any human can. With every...
Close your cybersecurity gaps before attackers find them
We all know that in today’s fast-moving digital world, it’s not a matter of if your systems will be prodded by cybercriminals, it’s when. From...
No business is too small: Why hackers are interested in you
Think your business is too small to be hacked? Think again. In 2024, 70% of organisations globally suffered a significant cyber attack, and small...
Bridging the cyber skills gap: Outsourcing your cybersecurity needs
Cybercrime is rising fast, but skilled professionals who can defend against it are in short supply, especially across Africa. Building a full-time...
Caught in the web: How cyber ‘spiders’ harvest your personal information
Ever heard of cyber spiders? They’re not the creepy kind but are just as dangerous. Cyber spiders are bots used by criminals to scan the internet,...
The Hacker News feed
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Costby info@thehackernews.com (The Hacker News) on July 28, 2026 at 6:07 am
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flawby info@thehackernews.com (The Hacker News) on July 28, 2026 at 4:43 am
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Frameworkby info@thehackernews.com (The Hacker News) on July 27, 2026 at 6:10 pm
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruptionby info@thehackernews.com (The Hacker News) on July 27, 2026 at 5:16 pm
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flawby info@thehackernews.com (The Hacker News) on July 27, 2026 at 2:40 pm
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version









