Blogs & insights
Latest Dark Nuvens blogs
AI is changing the game and so are the risks
Artificial Intelligence (AI) is transforming businesses operations, from automating tasks to analysing data faster than any human can. With every...
Close your cybersecurity gaps before attackers find them
We all know that in today’s fast-moving digital world, it’s not a matter of if your systems will be prodded by cybercriminals, it’s when. From...
No business is too small: Why hackers are interested in you
Think your business is too small to be hacked? Think again. In 2024, 70% of organisations globally suffered a significant cyber attack, and small...
Bridging the cyber skills gap: Outsourcing your cybersecurity needs
Cybercrime is rising fast, but skilled professionals who can defend against it are in short supply, especially across Africa. Building a full-time...
Caught in the web: How cyber ‘spiders’ harvest your personal information
Ever heard of cyber spiders? They’re not the creepy kind but are just as dangerous. Cyber spiders are bots used by criminals to scan the internet,...
The Hacker News feed
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attackby info@thehackernews.com (The Hacker News) on August 11, 2026 at 8:10 pm
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only
- Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsingby info@thehackernews.com (The Hacker News) on August 11, 2026 at 7:36 pm
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Clientby info@thehackernews.com (The Hacker News) on August 11, 2026 at 7:08 pm
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commandsby info@thehackernews.com (The Hacker News) on August 11, 2026 at 6:36 pm
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCEby info@thehackernews.com (The Hacker News) on August 11, 2026 at 4:47 pm
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's









