N8n fixes an 8.7-rated sandbox escape that lets workflow editors run OS commands as the n8n process.
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
BleepingComputer learned of the campaign from a reader, who told us threat actors are creating random Steam accounts to post what appears to be helpful fixes for people’s posts about games crashing, lost inventory items, and other technical issues.
The threat actors reply to posts, telling other members to open PowerShell as an administrator and run a command to fix the issue. However, when executing the command, it quietly downloads an XMRig miner executable and launches it on the computer.
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
The vulnerability, tracked as CVE-2026–16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.
VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices.
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot’ malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism.
Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm.
A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
Tracked as CVE-2026–54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates.
“An authenticated attacker could manipulate attributes associated with a machine account and obtain a certificate from Active Directory Certificate Services that allows authentication as that machine via PKINIT,” Microsoft explained.
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.
The complaint, filed on July 24 in California, alleges that Apple failed to adequately review and monitor applications distributed through the App Store while promoting the marketplace as a safe and trusted source for software.
Plaintiffs James Ramirez, Christopher Ellis, and Jalen Delgado say the malicious application impersonated the legitimate Sparrow Bitcoin wallet and instructed them to enter their seed phrases.
The effects of extreme space weather may be larger than previously thought, research in the journal Nature reveals. The paper, titled “Regression to the mean can explain saturation of geomagnetic storms,” is led by Dr. Nithin Sivadas of NASA’s Goddard Space Flight Center and co-authored by Dr. Maria Walach from Lancaster University.
Space weather—caused by fluctuating electric fields in Earth’s magnetic field and upper atmosphere—can affect technologies on and around Earth in several ways. Extreme geomagnetic storms are among the less frequent but more severe forms of space weather.
Extreme geomagnetic storms are temporary disturbances in the plasma and magnetic field around Earth that can disrupt global satellite communications, cause extensive power outages and affect how much radiation astronauts and pilots are exposed to.
Gene editing is a highly precise and powerful technology that allows scientists to insert, delete, modify or replace DNA bases in living organisms. It has a variety of uses, including correcting disease-causing mutations and improving crops. Tools like CRISPR act as molecular scissors that target specific places in a genome to make these changes. But the technology is not perfect and can accidentally edit the wrong pieces of DNA or RNA.
In research published in Nature, scientists describe a new framework that uses AI to make these tools more accurate. Hoi Yee Chu and Alan S.L. Wong of the University of Hong Kong published a News and Views piece in the same journal on the significance of this research.
Recycled materials promise a cleaner future, but recycled content alone does not necessarily make a product sustainable. At Georgia Tech’s Daedalus Lab, assistant professor Christos Athanasiou and postdoctoral researcher Danqi Sun are working to provide greater certainty to designers and engineers by rethinking how materials are tested for their fracture characteristics.
Their article in Science Advances details a new testing protocol that reduces costs, increases speed and simulates real-world conditions.
Materials shape nearly every part of modern life, from packaging and consumer products to bridges and medical devices. Choosing the right material involves balancing durability, cost, manufacturability and environmental impact. Yet those decisions are not always guided by a clear understanding of how materials age and fail under real-world conditions, especially for recycled materials like plastics.
Researchers linked higher plasma TMAO to prevalent atrial fibrillation in 5,090 people and found that TMAO or choline supplementation accelerated AF onset, progression, atrial remodeling, and electrical dysfunction in mice. Inhibiting gut microbial TMA production lowered circulating TMAO and delayed AF in mice, identifying a potential therapeutic pathway that now requires human testing.