Issue #211 - August 10, 2026
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Source: BleepingComputer
Researchers demonstrated that Windows Plug and Play can install exploitable vendor packages as SYSTEM when presented with emulated USB hardware. Some chains required no user interaction, while another worked through RDP USB redirection without physical hardware. Recommended protections include restricting device installation and disabling unnecessary Plug and Play redirection.
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Source: BleepingComputer
Cloudflare says it mitigated more than 800 network-layer DDoS attacks exceeding 1 Tbps during the second quarter, up from 130 in the first. Attacks between 500 Gbps and 1 Tbps also increased sharply. DNS floods and reflection or amplification techniques accounted for a growing share of observed activity.
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
Source: The Hacker News
Researchers identified 737 Chrome VPN and proxy extensions that accumulated more than 75,000 installations, with hundreds impersonating established privacy brands. Most routed browser sessions through common SOCKS5 infrastructure, exposing traffic metadata and unencrypted requests. Investigators found 221 extensions removed from the Chrome Web Store while 516 remained active.
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
Source: SecurityWeek
CloudSEK estimates that malicious LiteLLM releases linked to the Trivy compromise exposed more than 2,500 organizations and 434,000 CI/CD pipelines. The packages could access cloud keys, tokens, credentials, and runtime data. Researchers cautioned that reconstructed exposure does not prove every listed organization was successfully compromised.
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
Source: Dark Reading
An actively exploited, maximum-severity SQL injection flaw in Metabase can provide remote administrative access and expose connected database credentials and records. Metabase automatically updated cloud instances, but publicly reachable self-hosted deployments remain at risk until patched. Disclosures from n8n and Kilo Code illustrate the vulnerability's potential downstream impact.



