Sunday, 16 August, 2026

Critical Zero-Day in Apache Struts Exploited in the Wild — Patch Immediately

August 16, 2026

A critical remote code execution vulnerability (CVE-2026-41321) in Apache Struts has been discovered actively exploited in the wild. The flaw, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary commands on affected servers through crafted Content-Type headers. Apache has released Read more…

Major Healthcare Data Breach Exposes 4.2 Million Patient Records

A significant data breach at MedSecure Health Systems has exposed the personal health information of approximately 4.2 million patients across 340 hospitals and clinics in North America. The breach, discovered on August 10, 2026, involved unauthorized access to the organizations Read more…

HackerOne Raises Bug Bounty Payouts: Maximum Rewards Now Up to $250K

HackerOne has announced a significant increase in maximum bug bounty payouts across its platform, with top-tier critical vulnerabilities now eligible for rewards up to $250,000 — a 67% increase from the previous $150,000 cap. The move comes as organizations increasingly Read more…

New Malware Strain “ShadowVault” Targets macOS Keychain and Browser Credentials

Security researchers have identified a sophisticated new macOS malware strain dubbed “ShadowVault” that specifically targets Keychain credentials, browser-stored passwords, cryptocurrency wallets, and SSH keys on Apple systems. Unlike previous macOS information stealers, ShadowVault employs a novel persistence mechanism that abuses Read more…

Burp Suite 2026.8 Released: AI-Powered Scan Engine and HTTP/3 Support

PortSwigger has released Burp Suite Professional 2026.8, featuring a major overhaul of the scanning engine with AI-assisted vulnerability detection and full HTTP/3 (QUIC) protocol support. Key Features AI-Assisted Scanning — Machine learning models trained on 500,000+ real-world vulnerabilities improve detection Read more…