top of page
Untitled design.png

Weekly INK

Each week we compile an advisory on the latest threats, trends and newsworthy topics from the cyber security industry affecting small and medium enterprises. Join our subscribers below and help us prevent cybersecurity breaches.

watermark4.png

Issue #211 - August 10, 2026

Aug 10
2 min read

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Source: BleepingComputer

Researchers demonstrated that Windows Plug and Play can install exploitable vendor packages as SYSTEM when presented with emulated USB hardware. Some chains required no user interaction, while another worked through RDP USB redirection without physical hardware. Recommended protections include restricting device installation and disabling unnecessary Plug and Play redirection.




DDoS attacks over 1 Tbps surged fivefold in the second quarter

Source: BleepingComputer

Cloudflare says it mitigated more than 800 network-layer DDoS attacks exceeding 1 Tbps during the second quarter, up from 130 in the first. Attacks between 500 Gbps and 1 Tbps also increased sharply. DNS floods and reflection or amplification techniques accounted for a growing share of observed activity.




737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

Source: The Hacker News

Researchers identified 737 Chrome VPN and proxy extensions that accumulated more than 75,000 installations, with hundreds impersonating established privacy brands. Most routed browser sessions through common SOCKS5 infrastructure, exposing traffic metadata and unencrypted requests. Investigators found 221 extensions removed from the Chrome Web Store while 516 remained active.




Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

Source: SecurityWeek

CloudSEK estimates that malicious LiteLLM releases linked to the Trivy compromise exposed more than 2,500 organizations and 434,000 CI/CD pipelines. The packages could access cloud keys, tokens, credentials, and runtime data. Researchers cautioned that reconstructed exposure does not prove every listed organization was successfully compromised.




Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

Source: Dark Reading

An actively exploited, maximum-severity SQL injection flaw in Metabase can provide remote administrative access and expose connected database credentials and records. Metabase automatically updated cloud instances, but publicly reachable self-hosted deployments remain at risk until patched. Disclosures from n8n and Kilo Code illustrate the vulnerability's potential downstream impact.




 
 

Help us Prevent Breaches.

We will never share or sell your information. Unsubscribe at any time.

Email: *

Received.

bottom of page