Cybersecurity Brief

Breaches, vulnerabilities, and security news.

Cadence: Daily
Length: 2 minutes

Subscribe, Combine, Customize

Subscribe to this podcast
?Receive all episodes to this podcast in the apps below or anywhere that supports RSS.
Combine these episodes into your pod
?All episodes from this podcast will be fed into your own.
Sign up to add to your own podcast
Customize this pod with your own sources
?Use this if you want a brand new podcast with its own episodes using different sources.
Sign up to customize this pod

Sources

Episodes

Cybersecurity Brief August 14: GeoServer Zero-Day Probed as Apple Alerts Users in 110 Countries
Created: August 14th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Friday August 14th. A newly disclosed, unpatched GeoServer zero-day is already drawing active exploitation attempts. The SQL-injection flaw can potentially lead to remote code execution on the open-source geospatial platform. Researchers say attackers began probing internet-exposed systems within hours of public disclosure on Wednesday. Organizations using GeoServer should immediately identify exposed instances, restrict public access where possible, monitor logs for suspicious requests and database errors, and prepare to apply a vendor fix as soon as one becomes available. [1]

Apple has issued a new round of mercenary-spyware threat notifications to users in 110 countries. The company did not name a specific spyware vendor or attacker, but said these exceptionally sophisticated operations typically target people because of their work or identity, including journalists, activists, diplomats, and political figures. Recipients should treat an Apple notification as urgent: update devices, preserve evidence, seek specialized support, and avoid assuming a factory reset alone fully resolves the risk. [2]

Researchers have also identified more than 3,000 recruitment-themed phishing URLs in a campaign dubbed RecruitTrap. The operation impersonates recruiters and interview scheduling processes at more than 50 organizations. Its fake login windows use Browser-in-the-Browser techniques to make credential prompts appear legitimate, and some attacks relay multi-factor-authentication prompts in real time. Marketing professionals appear to be a major target, likely because their accounts can reach advertising platforms, social channels, customer data, and corporate email. Verify interview links independently, and use phishing-resistant authentication where available. [3]

Finally, a new White House memo directs the National Coordination Center to develop a program under which vetted U.S. companies could conduct federally authorized surveillance or disruptive cyber operations against foreign criminal groups. The proposal raises substantial oversight and attribution questions, but it signals a policy shift toward using private-sector offensive capability against transnational cybercrime. [4]

The common thread is that identity remains the primary battlefield: stolen credentials, high-value professional accounts, targeted spyware, and even government-backed disruption all center on who can access systems and who can be trusted. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...d @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa [system administrator] database, it's naturally possible to achieve RCE," the researcher said. The threat intelligence and exposure management platform said it began to observe exploitation attempts within hours of public disclosure, and that it has seen hundreds of attempts originating from a small pool of IP addresses. "Currently, we're seeing attackers probe to identify vulnerable systems across the internet, triggering errors and not proceeding further," Jake Knot...
    
    ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
    Aug 13, 2026
    Hacking News / Cybersecurity News
    
    Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud se...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...ted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021. "The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today," the tech giant said . "As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions." Typically, such notifications are sent to people who may have been individually targeted because of "who they are or what they do," including journalists, activists, politicians, and diplomats. They tend to focus on a very small number of speci...
    
    AI Is Flooding Security with Bugs Nobody ProvedSANSVulnerability / Artificial intelligenceStephen Sims on why unproven AI f...
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...ages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap , said it identified more than 3,000+ phishing URLs over two months. The campaign impersonated real recruiters and recruitment processes associated with more than 50 organizations across 14 sectors . Marketing professionals accounted for the majority of observed targets. The focus on marketing roles appears deliberate. Compromised marketing accounts can provide access to advertising platforms, corporate social media profiles, customer data, email, and other business-critical services. Read the full report here: https://www.ctm360.com/reports/recruittrap-browser-in-the-browser-bitb-recruitment-scam...
    
    Apple Warns Users in...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...ion Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens," the memo reads . To that end, the NCC has been tasked with setting up a program that allows authorized companies to conduct two types of operations against TCOs upon obtaining approval: cyber surveillance operations, which can access sensitive data without authorization from the owner or operator, and cyber effects operations, which can result in disruption, denial, degradation, or destr......
  5. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...to Expose Them Before Hiring
    Aug 13, 2026
    Cyber Espionage / Threat Intelligence
    
    Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access. When the Threat Gets Hired A recent joint investigation by Mauro Eldritch ( BCA LTD ), Heiner García ( NorthScan ), and ANY.RUN showed what this looks like from inside the operation. Researchers deliberately hired suspected DPRK developers linked to Lazarus Group and gave...
Sources
Cybersecurity Brief August 13: WindRelay Android NFC Fraud, North Korean IT Workers, and Chrome VPN Risks
Created: August 13th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Thursday August 13th. A newly identified Android malware family called WindRelay is being used to turn victims’ phones into live NFC relays for contactless-payment fraud. Group-IB says attackers pair it with the SpyNote remote-access trojan, typically delivered through phishing texts, calls, or malicious apps installed outside Google Play. Once SpyNote gains Android Accessibility permissions, the fraudsters can silently install and operate WindRelay without screen sharing. The malware captures card data through NFC and relays it in real time, potentially allowing criminals to make payments elsewhere. Android users should avoid sideloaded apps, be wary of banking or delivery messages pushing urgent installations, and review Accessibility permissions for unfamiliar services. [1]

A second concern is the continuing infiltration of organizations by North Korean remote IT workers. New reporting highlights how this threat bypasses the traditional perimeter: fraudulent applicants can pass interviews, receive legitimate corporate credentials, and gain access from inside the business. The FBI is reportedly investigating a suspected North Korean worker who held a role at a U.S. federal agency. Companies should strengthen hiring verification, scrutinize inconsistencies in identity documents and work histories, watch for unusual remote-access patterns or shared devices, and coordinate HR, IT, and security teams before granting broad access to new hires. [2]

Yesterday, researchers disclosed 737 Chrome VPN and proxy extensions that route browser traffic through a common SOCKS5 proxy infrastructure. Many targeted Russian-speaking users seeking censorship circumvention, and 274 impersonated established privacy brands, including Proton VPN, NordVPN, Surfshark, and ExpressVPN. More than 75,000 installations were recorded. The risk is straightforward: a browser extension that carries all browsing traffic can observe, alter, or redirect sensitive sessions. Users should remove untrusted VPN extensions, install software only from verified publishers, and favor reputable standalone VPN clients over lookalike browser add-ons. [3]

The broader trend is that attackers increasingly exploit trusted access: a phone’s accessibility controls, a new employee’s credentials, or a browser privacy tool. Security controls need to evaluate behavior and permissions continuously, not merely trust the label on an app, identity, or extension. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [4]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...eing deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in the wild in late August 2025. "SpyNote's Accessibility Service access lets the fraudster sideload and activate the NFC app silently, with no screen sharing ever triggered," researchers Alexander Grabko, Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić said . These attacks typically work by luring prospective targets via phishing, smishing, or vishing scams into sideloading a malicious app. Once installed, the threat actor abuses SpyNote's remote access to install the NFC relay malware without any further user interaction. To lend credibility to the sch...
    
    North Ko...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...iders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access. When the Threat Gets Hired A recent joint investigation by Mauro Eldritch ( BCA LTD ), Heiner García ( NorthScan ), and ANY.RUN showed what this looks like from inside the operation. Researchers deliberately hired suspected DPRK developers linked to Lazarus Group and gave them what looked like ordinary virtual desktops. In reality, they were controlled ANY.RUN Sandboxes, capturing their activity in real t...
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...f 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, and Google's Outline, per Socket. The censorship circumvention extensions "route the user's entire browser session through SOCKS5 proxies operated by a single provider," security researcher Kush Pandya said . "520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure." The vast majority of...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić said . These attacks typically work by luring prospective targets via phishing, smishing, or vishing scams into sideloading a malicious app. Once installed, the threat actor abuses SpyNote's remote access to install the NFC relay malware without any further user interaction. To lend credibility to the sch...
    
    North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
    Aug 13, 2026
    Cyber Espionage / Threat Intelligence
    
    Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Ko...
Sources
Cybersecurity Brief August 12: Microsoft Patches Exploited Windows Zero-Day as LiteLLM Leak Threatens Thousands
Created: August 12th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Wednesday August 12th. Microsoft’s August Patch Tuesday delivers fixes for at least 398 vulnerabilities, including 42 rated critical and one zero-day already being exploited. The active flaw, CVE-2026-68820, is a privilege-escalation bug in the core Windows afd.sys networking driver. It is not an initial-access vulnerability, but attackers who gain a limited foothold through phishing or malware could use it to take broader control of a device. Organizations should prioritize this month’s Windows updates, especially on endpoints handling email, remote access, or privileged administration. [1]

There is also a new concern around Microsoft Defender. A researcher has released a proof of concept called ShieldBreak, claiming a bypass of Microsoft’s patch for the previously disclosed RoguePlanet flaw. The technique could potentially produce SYSTEM-level access. Microsoft has not confirmed active exploitation of this new bypass, but defenders should monitor Defender and Windows update guidance closely, and investigate unusual privilege escalation or security-tool behavior. [2]

In AI security, researchers disclosed a weakness affecting reasoning APIs from OpenAI, Anthropic, and Google. They found that encrypted hidden-reasoning objects could be replayed across sessions and, in testing, decoded by weaker models in the same provider family. The potential consequences include exposure of internal reasoning, sensitive information embedded in traces, and hidden prompt injections. The lesson for developers is straightforward: do not treat AI session artifacts or “hidden” reasoning as a secure container for secrets. Keep credentials out of prompts, logs, traces, and agent memory wherever possible. [3]

Finally, a new analysis of March’s malicious LiteLLM package releases suggests the supply-chain incident may have exposed secrets associated with thousands of organizations. The attackers’ packages were live for only about 40 minutes, but could harvest cloud credentials, SSH keys, Kubernetes tokens, and database passwords. The published dataset is not a confirmed victim list, yet organizations using LiteLLM should check for the affected releases and rotate any credentials reachable from those systems. [4]

The trend is that AI is accelerating both vulnerability discovery and the complexity of defending software ecosystems. Fast patching, careful secret management, dependency controls, and strong detection of privilege changes are becoming inseparable priorities. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]

Source Evidence
  1. Krebs on Security
    ...Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
    
    Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
    Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 — an Active Directory Federation Services bug — and CVE-2026-56164, a Microsoft Sharepoint vulnerability.
    CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to g...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...e, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak . The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet . RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them to run arbitrary code or perform unauthorized actions. Although it was first disclosed by the researcher in June 2026, a patch for the vulnerability was not released by Microsoft until almost a month later. The tech giant described it as a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"). Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to ad......
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...luding API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing, even handed to a weaker model in the same provider family to make it reveal the hidden content. The team behind the paper Stealing Reasoning Traces from Proprietary LLM APIs demonstrated four abuse paths: stealing proprietary reasoning for model distillation , extracting private data from other users' published traces, recovering harmful content concealed behind a safe visible answer, and hiding prompt injections inside opaque reasoning blocks. Across 6,708 public agent trajectories, the team decoded 315,320 thinking blocks. After excluding benchmark sources, it counted 704...
    
    AI Is Flooding Security with Bugs Nobody ProvedSANSVulnerability / Artificial intellig...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...ses sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more than 2,500 organizations. Those totals are not a victim count. CloudSEK told The Hacker News the material came from confidential intelligence sources and consists of captured loot and log files it assessed as belonging to the campaign, not data gathered from the organizations it names. The files were taken, in other words. CloudSEK has published the dataset as a public lookup , searchable by name or domain and filterable by confidence. Each row gives an organization's name and domain, a count of secrets e...
  5. Recent tweets from @briankrebs
    ...s://t.co/8GTlIRtbiw
    Posted: 2022-12-21T02:02:13.000Z
    Tweet: https://x.com/briankrebs/status/1605383104918458368
    Links: https://www.youtube.com/watch?v=T1XgFsitnQw
    
    Hey @elonmusk, by your own rules proclaimed ~48hrs ago, don't you need a poll to propose policy changes to how polls are done? https://t.co/QNjwMLvlvp https://t.co/kSJb4cUkgK
    Posted: 2022-12-21T01:56:24.000Z
    Tweet: https://x.com/briankrebs/status/1605381640255320065
    Links: https://x.com/briankrebs/status/1605381640255320065/photo/1, https://twitter.com/CNN/status/1605299543804895234
    
    ...aaand, just like that, the policy doesn't exist anymore. Does the CEO? https://t.co/PNuMUWowCl
    Posted: 2022-12-19T05:20:09.000Z
    Tweet: https://x.com/briankrebs/status/1604708140817293312
    Links: https://help.twitter.com/en/rules-and-policies/social-platforms-policy
    
    FYI, the only reason I'm still here is to to make fun of the...
Sources
Cybersecurity Brief August 11: BdThemes, Quectel, and N-able Flaws Fuel Major Cybersecurity Risks
Created: August 11th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Tuesday August 11th. A supply-chain compromise at WordPress plugin vendor BdThemes has prompted WordPress to temporarily disable downloads of the company’s plugins, including Element Pack, which has more than 100,000 active installations. Researchers say attackers did not alter code in the official WordPress repository. Instead, they poisoned a remotely hosted JSON feed used by a promotional banner component, allowing the attackers to create unauthorized WordPress administrator accounts. That is an important reminder that third-party risk includes every remote service a plugin contacts, not just the package code itself. Site owners should check for unexpected administrator accounts, update or disable affected BdThemes plugins, and review logs for suspicious changes. [1]

Researchers also disclosed that a malicious SIM card can execute attacker-chosen commands on some cellular modems used in industrial routers, electric-vehicle chargers, and vehicle telematics systems. Tests found the capability enabled in six of eight cellular modules, predominantly Quectel hardware, and researchers demonstrated code execution on a commercial EV charger. The attack requires physical insertion or replacement of the SIM card; knowing a device’s phone number is not enough. Still, it highlights that cellular-connected operational technology needs physical controls alongside software patching. Operators should track affected modem models, restrict access to SIM slots, and validate devices after field servicing. [2]

Yesterday, Microsoft warned that China-linked group Storm-1175 deployed a new ransomware strain called StormEncryptor, likely after exploiting a recently disclosed N-able N-central authentication-bypass flaw. The group previously used Medusa ransomware. Organizations using N-central should urgently apply vendor fixes, investigate unusual administrator activity, and limit management-platform exposure, because remote-management tools offer attackers a direct path to many endpoints. [3]

The larger trend is that trusted management layers are under pressure: WordPress plugins, SIM-enabled devices, and remote administration software can all become high-leverage entry points. Security teams should prioritize inventories, strong vendor-update processes, least privilege, and monitoring for unexpected account creation or device behavior. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [4]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said . "Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component." The list of affected plugins is below - Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] - 100,000+ active installs Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator [live-copy-paste] - 6,000+ active installs Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it switched on in 9 of them, and used it to run their own code on a commercial EV charger. Six of the eight cellular modules they tested accepted the command. Only 3 of 18 phones did: the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9. No iPhone or Pixel was among them. The exposure is in machine-to-machine hardware. Five of the six were Quectel parts, three of them pulled from an EV charger, an industrial router, and a car's telematics control unit. Knowing the victim's number is not enough: every attack starts with a hostile card already in the slot, swapp...
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...ners found problems, security teams prioritized them, and engineers fixed what mattered most. AI puts that model under pressure. If teams can suddenly create many times more code, security can also end up with many more components, dependencies, findings, and fixes to manage. More scanning alone does no...
    
    China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
    Aug 10, 2026
    Ransomware / Cybercrime
    
    Microsoft has disclosed that Storm-1175 , a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor . The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted in a seri...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...d From 30 Days to 30 MinutesRecoAI Security / SaaS SecurityDownload the 11-step checklist CISOs use to close exposure windows first.
    
    BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
    Aug 11, 2026
    Supply Chain Attack / Vulnerability
    
    Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said . "Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component." The list of affected plugins is below - Element Pack Addons for Elementor – Elementor Widgets, E...
Sources
Cybersecurity Brief August 10: Head Mare Poisons TrueConf Installers With PhantomCore Backdoor
Created: August 10th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Monday August 10th. Today’s lead story is active exploitation of unpatched TrueConf videoconferencing servers used by Russian organizations. Kaspersky says the Head Mare threat group exploited a chain of flaws to replace legitimate TrueConf client installers with poisoned versions carrying the PhantomCore backdoor. The affected server releases include several 5.3, 5.4, and 5.5 versions. This is a particularly dangerous supply-chain-style attack: users may believe they are installing trusted conferencing software while receiving remote-access malware instead. Organizations running TrueConf should identify exposed servers, patch immediately, validate client-installation files, and review server logs and endpoints for suspicious activity. [1]

Also today, researchers warned about malicious Visual Studio Code extensions impersonating Solidity development tools. The extensions, called Solidity Pro, were designed to steal browser-wallet data, source-control tokens, API keys, SSH keys, and Telegram bot credentials. Earlier versions downloaded encrypted Python payloads; newer versions include a more complete information stealer and send captured data through a Telegram bot. The packages have been removed from Open VSX, but a related GitHub repository remained online at publication. Developers should remove these extensions, rotate any credentials accessible from affected machines, and treat unfamiliar editor extensions with the same scrutiny as production dependencies. [2]

In a more forward-looking development, Python’s widely used cryptography library now supports NIST-standard post-quantum algorithms, including ML-KEM for key establishment and ML-DSA for digital signatures. The practical significance is not that quantum computers are breaking encryption today. It is that developers can begin testing crypto-agile designs now, before migration becomes urgent. Teams should inventory where they use cryptography, ensure algorithms can be swapped without rebuilding entire applications, and plan for long-lived sensitive data that could be harvested now and decrypted later. [3]

The broader trend is that software trust boundaries are under pressure from both directions: attackers are compromising the tools developers and users rely on, while defenders must prepare core systems for rapid technological change. Signed software, extension allowlists, credential rotation, patch discipline, and crypto agility are becoming essential operational habits. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [4]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain in the TrueConf videoconferencing server to replace the original TrueConf client installers with poisoned versions that deliver the PhantomCore backdoor and remote access trojan (RAT) into susceptible systems. The vulnerabilities, tracked as KLCERT-26-057 and KLCERT-26-058, enable arbitrary code execution with elevated privileges. The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier. The attack chain is as follows - Attackers connect to the TrueCon...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository for " web3devtoolsx/solidity-pro " continues to remain accessible as of writing. According to Yeeth Security , early iterations of the extensions – from 1.0.0 through v2.4.x – were found to beacon to Cloudflare Workers endpoints to retrieve an encrypted Python payload and execute it. Subsequent versions starting with v3.0.0, on the other hand, have shifted to a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The captured data is then exfiltrated via a Telegram bot u...
    
    AI Is Flooding Security with Bugs Nobody ProvedSANSVulnerability / Artificial intelligenceStephen...
  3. Schneier on Security
    ...aphy is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography.
    Remember, the reason to do this now is because there’s no emergency. And because you will make your systems crypto agile, which is always a good idea.
    
    
    
    Tags: cryptography, encryption, open source, quantum computing
    
    
    
    
    Posted on August 10, 2026 at 7:02 AM •
    2 Comments
    
    
    
    
    
    
    Friday Squid Blogging: Arctic Bobtail Squid Video
    Nice video of the Arctic bobtail squid.
    As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
    Blog moderation policy.
    
    
    
    Tags: squid, video
    
    
    
    
    Posted on August 7, 2026 at 5:07 PM •
    21 Comments
    
    
    
    
    
    
    Adversarial Clothin...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...abilities, tracked as KLCERT-26-057 and KLCERT-26-058, enable arbitrary code execution with elevated privileges. The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier. The attack chain is as follows - Attackers connect to the TrueConf server on TCP port 4307, which is open by default. Upon successful conn...
    
    Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
    Aug 10, 2026
    Malware / Cybercrime
    
    Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository for...
Sources
Cybersecurity Brief August 9: H96 TV Boxes Fuel Ad Fraud as LG Targets Proxy Apps
Created: August 9th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Sunday August 9th. Yesterday, Bitsight researchers reported that H96 Android TV streaming boxes are being used in a large ad-fraud operation. The devices appear to disguise themselves as mobile phones, then generate ad clicks on AI-generated websites. Researchers traced two apps found on the boxes to a China-based company and found that the fraud infrastructure collected hardware details and installed-app lists from tens of thousands of devices. The practical takeaway: avoid unofficial “fully loaded” streaming boxes that promise unlimited content for a one-time fee. They can turn a home internet connection into infrastructure for fraud and other abuse. [1]

That finding adds urgency to LG’s new response to residential-proxy software in smart-TV apps. LG says it will work with developers to remove proxy functionality from webOS apps, and suspend apps that do not comply. Prior research found proxy software in more than 42 percent of apps in LG’s TV store. These programs can rent out a television’s network connection to third parties, often with little meaningful user understanding. Review apps on smart TVs and streaming devices, remove unfamiliar games or utilities, and keep entertainment devices on a separate network from work systems and sensitive personal devices. [2]

In cybercrime news, two suspected Scattered Spider members pleaded guilty in the United Kingdom over the August 2024 attack on Transport for London. Thalha Jubair and Owen Flowers admitted conspiring to access the transit agency’s systems and cause a risk of serious harm. Flowers also admitted involvement in attacks on two U.S. healthcare providers. The case underscores the continuing danger of social engineering, SIM swapping, and stolen employee credentials—the group’s preferred ways to enter major organizations. [3]

The broader trend is that consumer technology is becoming both a target and a tool. Cheap connected devices, permissive app ecosystems, and weak identity controls give criminals low-cost access to powerful infrastructure. Device inventory, network segmentation, phishing-resistant authentication, and careful software sourcing are increasingly essential basics. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [4]

Source Evidence
  1. Krebs on Security
    ...nds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.
    Pedro Falé is a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96.
    An H96 TV streaming device currently advertised for sale on Amazon.
    Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funne...
  2. Krebs on Security
    ...examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.
    Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended.
    “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “...
  3. Krebs on Security
    ...n, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.
    Owen Flowers (left) 18, and Thalha Jubair, 20. Image: UK National Crime Agency (NCA).
    Thalha Jubair, 20, of East London and 18-year-old Owen Flowers of Walsall admitted conspiring to commit unauthorized acts against Transport for London computer systems and causing risk of serious damage to human welfare. According to a report from the BBC, Flowers alone admitted to being part of a conspiracy to hack into U.S. based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.
    Jubair is also wanted by U.S. law enforcement agencies. In September 2025, prosecutors in New Jersey unsealed an i...
  4. Krebs on Security
    ...ding cybercriminal and espionage groups.
    “These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,” Google’s GTIG wrote. “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.”
    Google said it disabled Google accounts and services used by NetNut for malware command and control, and that it shared technical intelligence on NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement and research firms. The company also disabled apps known to bundle NetNut’s various SDKs.
    Omer Weiss, legal counsel for NetNut parent Alarum Technolo...
Sources
Cybersecurity Brief August 8: Black Hat Research Exposes CSS Email Attacks Across Gmail and Outlook
Created: August 8th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Saturday August 8th. New research presented yesterday at Black Hat shows that carefully crafted CSS inside emails can break out of a message’s visual boundary and interfere with webmail interfaces. PortSwigger researcher Gareth Heyes demonstrated proof-of-concept attack chains affecting combinations of Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, AOL Mail, and specific browsers. Potential outcomes include convincing fake sign-in screens, stolen login tokens, hijacked interface actions, and prompt-injection attacks against AI tools that read email. No malicious exploitation has been reported, but public proof-of-concepts remain available. Webmail providers need to harden message rendering; meanwhile, users should be especially skeptical of sign-in prompts or unexpected interface behavior originating from an email. [1]

Yesterday also brought a major software supply-chain warning: researchers identified nearly 800 malicious packages published to npm. The packages use typo-squatted or randomly generated names and instruct developers to import them with the standard require function, rather than relying on the lifecycle scripts developers are increasingly trained to distrust. The result is a cross-platform downloader that fetches remote-access and information-stealing malware for Windows, macOS, or Linux. Development teams should scrutinize unfamiliar dependencies, pin and review packages before adoption, and use repository controls that block known malicious components. [2]

In breach news, Levi Strauss said yesterday that hackers accessed employee computers and corporate data. The company has not yet detailed the scope or the nature of the data involved. Still, the incident is another reminder that a compromise of an employee endpoint can become a broader corporate-data event. Organizations should ensure endpoint detection, phishing-resistant authentication, and least-privilege access extend to employee workstations, not only servers and cloud applications. [3]

And water-sector defenders are building more community support: a water-utilities group yesterday announced a partnership with a DEF CON offshoot to create the Water Watch Center. It follows recent cyber incidents affecting U.S. water systems and reflects growing recognition that smaller operators need practical, specialized security help. [4]

The broader trend is that trust is being abused at every layer: email displays, developer ecosystems, employee devices, and essential services. Strong validation, segmentation, and rapid reporting remain the common defenses. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ..., Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth Heyes presented the work at Black Hat USA 2026. One Outlook/Firefox chain spoofs a Microsoft sign-in screen and captures the password a recipient types. A Yahoo/AOL paste race can expose a Medium email-login token and let an attacker sign in as the victim. A Gmail/Cowork chain can exfiltrate a Slack token after prompt injection and user interaction. The paper presents proof-of-concept research and does not report malicious exploitation. Public PoCs remain available as of August 8. The researcher said Fastmail fixed two CSS mutation bugs and a Proton Mail proxy bypass stopped working when he re...
    
    AI Threat Readiness 101WizCloud Security /...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul McCarty said . Unlike other npm-oriented software supply chain attacks that make use of lifecycle hooks like preinstall or postinstall to trigger the execution of malicious code, the newly identified packages come with a README that instructs developers to load them with require(), a built-in function to import modules, local files, and third-party packages. The attack leads to the execution of a downloader named WEL1DROPPER , which, when executed, identifies the host operating system and processor architecture and fetches a compatible payload from one of the three Cloudflare Workers...
    
    Growing Up The Hard Way
    Aug 07, 2026
    Security Compliance / Softwa...
  3. Cyber Security News | The Record from Recorded Future News
    ...raised cyber scam compound issue with XiJonathan Greig| August 6th, 2026BriefsUS cyber ambassador nominee Cassady confirmed in SenateAugust 7th, 2026Military device manufacturer discloses cyber incident to SECAugust 7th, 2026Levi Strauss says hackers breached employee computers, accessed corporate dataAugust 7th, 2026French rugby club Stade Français restores systems after cyberattack, probes data leakAugust 7th, 2026Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigateAugust 6th, 2026Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundationsAugust 3rd, 2026Biotech giant Amgen says patient data stolen from third-party cloud systemsAugust 3rd, 2026Semiconductor chip titan Analog Devices reports data breachJuly 30th, 2026Laundry Bear’s webmail hackers had more in store after February, report saysJuly...
  4. Cyber Security News | The Record from Recorded Future News
    Water utilities group partners with DEF CON offshoot for Water Watch CenterJonathan Greig| August 7th, 2026New Mexico judge orders Meta to pay $567 million in kids online safety caseSuzanne Smalley| August 7th, 2026Levi Strauss says hackers breached employee computers, accessed corporate dataDaryna Antoniuk| August 7th, 2026French rugby club Stade Français restores systems after cyberattack, probes data leakDaryna Antoniuk| August 7th, 2026Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigateJonathan Greig| August 6th, 2026Belarusian cybercriminal behind Ransom Cartel gets 16...
  5. Krebs on Security
    ...others to maintain mature and well-tested key management capabilities,” the report notes.
    CISA also admitted it can do better when it comes to responding to security incident notifications from external parties. The postmortem stresses that clear and distinct reporting channels are essential to ensure that incidents affecting the organization itself are handled differently from those involving its products or customers.
    “In CISA’s case, these channels were not well defined, leading the security researcher to try multiple avenues – including emailing the contractor, submitting through CISA’s vulnerability disclosure platform (which is intended for vulnerabilities impacting the broader cybersecurity community), and ultimately involving a reporter,” reads the analysis written by Preston Werntz and Brad Libbey, the acting chief information officer and acting chief informa...
Sources
Cybersecurity Brief August 7: FBI Seizes NetNut Domains as Linux SCTPhantom and Rockwell Risks Emerge
Created: August 7th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Friday August 7th. The FBI says it has seized hundreds of domains tied to NetNut, a residential-proxy service linked by multiple researchers to the Popa botnet. Google says the proxy network was widely used by criminals and espionage groups to mask malicious traffic, including password-spraying attacks. The underlying risk is not abstract: compromised consumer devices can become exit nodes that relay attackers’ activity and may expose other systems on the same home network. Disconnect and replace suspicious, unofficial Android TV boxes and streaming devices, and keep IoT gear separated from work and sensitive personal systems. [1]

Linux administrators also have an urgent local privilege-escalation patch to prioritize. Researchers disclosed CVE-2026-64564, or SCTPhantom, a use-after-free flaw in Linux SCTP networking code that has existed since 2008. Tencent researchers demonstrated root access on affected systems and a container escape to the underlying host. It is not a remote bug, but it matters greatly on multi-user servers, shared hosting, and container platforms. Fixed kernels released August 3rd include versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148. [2]

Also today, PortSwigger described an AI-assisted system that tested 30,000 authorized websites for HTTP desynchronization weaknesses and identified roughly 700 potentially vulnerable targets before deeper validation. The research also uncovered an Apache Traffic Server zero-day. These flaws can cause front-end and back-end systems to disagree about request boundaries, potentially enabling request smuggling, cache poisoning, or exposure of other users’ responses. Organizations should track Apache’s fix, review reverse-proxy configurations, and test critical web applications for desync exposure. [3]

Finally, yesterday Forescout reported more than 4,400 internet-exposed Rockwell industrial controllers worldwide, including 22 in cities hit by recent U.S. water-utility attacks. It found no evidence those devices were breached, but emphasized that exposed controllers can be disrupted without exploiting a software flaw. [4]

The trend is clear: unmanaged edge devices, exposed control systems, and small configuration gaps are giving attackers disproportionate leverage. Asset inventory, segmentation, prompt patching, and minimizing direct internet exposure remain the practical defenses. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]

Source Evidence
  1. Krebs on Security
    ...rced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].
    Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.
    Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connecti...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ..., permission slips for half the places it wanted to go. What it did not get was a nice, slow, storybook ...
    
    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
    Aug 07, 2026
    Linux / Vulnerability
    
    A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update. Tracked as CVE-2026-64564 and named SCTPhantom by its finders, the flaw was disclosed publicly on August 6, two days after the kernel CVE team assigned it. No public exploit code had surfaced at the time of writing, and The Hacker News found no entry for t...
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...rs. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found roughly 700 vulnerable targets before deeper validation and RQP research. Kettle said those findings involved banks, government infrastructure, security products, and an airport. The research produced new desync triggers, a dual-matching Content-Length pattern, and a "dangling-byte" technique designed to make response queue poisoning (RQP) more reliable. RQP can potentially make a front end lose track of which back-end response belongs to which user, potentially exposing another user's resp...
    
    The State of Shadow AI in 2026 (And How Attackers Are Taking Advantage)Push SecurityShadow AI / Browser SecurityAI adopt...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...ontrollers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims. Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment. Neither the government alerts nor Forescout's analysis explains how the attackers found, selected, or initially accessed their targets. Water and wastewater utilities in at least seven states have reported incidents since July 27 , the FBI and EPA said in a July...
    
    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
    Aug 06, 2026
    Vulnerability / Blockchain
    
    Coinspect has id...
  5. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware. This suggests that the threat actor h...
    
    ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
    Aug 06, 2026
    Hacking News / Cybersecurity News
    
    Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical. Just ordinary systems trusting slightly too much, slightly too early. The full list follows. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
    
    Over 4,4...
Sources
Cybersecurity Brief August 6: ENDLESSDOORS Backdoor Found in 21 Zbtlink Router Firmware Images
Created: August 6th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Thursday August 6th. Researchers have disclosed a factory-installed backdoor in at least 20 Zbtlink router models. The implant, dubbed ENDLESSDOORS, appears in all 21 firmware images examined, spanning more than two years. It runs with root privileges, disguises itself as a Linux kernel worker process, and repeatedly contacts command-and-control infrastructure. Organizations and consumers using these routers should identify affected equipment, isolate it from sensitive networks, and seek vendor guidance or replacement hardware. A backdoor shipped in firmware is a supply-chain problem, not something a routine password change can solve. [1]

Also today, researchers disclosed flaws in AI-agent infrastructure from AWS, Google, and Vercel that could let attackers trigger an agent’s tools without a model authorizing the action—and in some cases without the model running at all. That means prompts, filters, and model-level guardrails may never get a chance to intervene. AWS has fixed its managed service, while Google and Vercel released updates. Teams building agents should patch quickly and enforce authorization at the tool layer, not rely solely on what the AI model is supposed to permit. [2]

In cybercrime news, Connor Riley Moucka pleaded guilty yesterday over the Snowflake customer-account breaches that affected at least 165 organizations and exposed data on at least 100 million people. The case reinforces a painful lesson: investigators say the attackers used old credentials stolen by infostealer malware, where passwords had not been rotated and multi-factor authentication was disabled. Cloud platforms remain only as secure as the identities accessing them. Review dormant accounts, require phishing-resistant MFA, and rotate credentials that may have appeared in past infostealer collections. [3]

Finally, reported cyberattacks on U.S. water systems expanded to 12 states yesterday, as South Dakota and Georgia announced incidents. Attribution remains preliminary and confirmed physical damage has been limited, but the campaign is a reminder that operational-technology environments need segmentation, monitored remote access, and practiced incident response. [4]

The common thread is that security controls cannot sit at the surface. Whether it is router firmware, AI tools, cloud identities, or water infrastructure, trust boundaries need independent verification and layers of defense. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...are
    
    Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The "phone home" implants have been codenamed ENDLESSDOORS . "ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said. "Uploaded to GitHub on January 1...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...d Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
    Aug 06, 2026
    DevSecOps / Vulnerability
    
    Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit (ADK) for Python, and the Vercel AI SDK harness packages for the Codex and OpenCode coding agents. AWS has fixed the managed service, Google addressed the issues in ADK 2.5.0, and Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28. These are not i...
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts . The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales. He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest. What got the attackers in was old passwords. The credentials had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off. No exploit, no flaw in the platform. The Justice Department has never named the company, in Wednesday's announcement or in the October 2024 indictment,...
  4. Schneier on Security
    ...he car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.
    
    
    
    Tags: Bluetooth, cars, hacking, patching, vulnerabilities
    
    
    
    
    Posted on August 5, 2026 at 5:42 AM •
    5 Comments
    
    
    
    
    
    
    Iran Cyberattacks Against Minnesota Water Systems
    Attribution is preliminary, and so far it seems no real damage.
    And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.
    “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
    No word on whether he bel...
  5. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...threats and risks.
    
    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
    Aug 06, 2026
    IoT Security / Malware
    
    Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The "phone home" implants have been codenamed ENDLESSDOORS . "ENDLESSDOORS, at its core,...
Sources
Cybersecurity Brief August 5: CISA Flags Langflow, Tomcat, N-able Flaws; Gitea Fixes Critical File Read
Created: August 5th, 2026 - 04:55 PT
Script

Here is today's Cybersecurity Brief for Wednesday August 5th. CISA today added three vulnerabilities to its Known Exploited Vulnerabilities catalog, a signal that defenders should treat them as urgent. The flaws affect Langflow, Apache Tomcat, and N-able N-central. The most severe is a Langflow code-injection bug that can give unauthenticated attackers remote code execution on default deployments; it was fixed in version 1.10.1. Organizations should identify exposed instances, patch immediately, and review logs for suspicious access. Federal agencies must act by CISA deadlines, but the risk applies far beyond government. [1]

Also today, self-hosted Gitea users have an especially serious update to install. Gitea version 1.27.1 fixes a critical file-read vulnerability, rated 9.8, that lets an unauthenticated attacker use crafted Org-mode markup in a public repository to read files accessible to the service account. Researchers warn that stolen configuration data, including an internal token, could potentially be chained into code execution. If you operate Gitea yourself, upgrade now and rotate sensitive tokens that may have been exposed. [2]

GitGuardian also reported today that leaked n8n automation-platform API tokens are providing real access to live systems. Researchers found more than 4,500 tokens exposed in public GitHub commits; among reachable instances, 321 accepted at least one leaked credential. Since n8n often connects cloud accounts, code repositories, databases, AI services, and support platforms, one token can expose far more than a workflow. The fix is not a software patch: scan repositories and commit history for secrets, revoke exposed tokens, and narrow each automation credential’s permissions. [3]

Finally, a newly disclosed Linux kernel flaw called OVSwrap can let local users gain root privileges on systems with the Open vSwitch datapath available and unprivileged user namespaces enabled. A public exploit reportedly supports hundreds of kernel builds. Linux teams should track vendor fixes and consider whether unprivileged user namespaces are necessary in their environments. [4]

The pattern is clear: attackers are increasingly succeeding through exposed administration surfaces, leaked credentials, and defaults—not exotic malware. Asset inventory, rapid patching, secret scanning, and least privilege remain the fastest ways to reduce today’s risk. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]

Source Evidence
  1. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...rs swi...
    
    CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
    Aug 05, 2026
    Vulnerability / Patch Management
    
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1) CVE-2026-34486 (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026...
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774 , rated Critical with a CVSS score of 9.8, and received its formal advisory on August 2. Gitea 1.27.1 also patches CVE-2026-60004 , a separate remote code execution bug covered in a prior THN report . Gitea said Cloud instances would be upgraded automatically during the release maintenance window. Self-hosted administrators should move to 1.27.1 immediately. The file-read bug is not direct one-request remote code execution. Gitea says it can become command execution if an attacker reads app.ini , extracts INTERNAL_TOKEN , injects a Git hook through the internal logger, and triggers that hook during an anonymous clone. That chain is described in Gite...
    
    AI Threat Readiness 101WizCloud Security / AI S...
  3. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896 instances reachable at the time of testing, 321 accepted at least one leaked token. That means leaked credentials provided authenticated access to 36% of the reachable instances we tested, or roughly 26% of all hostnames identified in the commits. The implications extend well beyond n8n. Organizations use the automation platform to connect databases, source code repositories, cloud environments, artificial intelligence services, customer support platforms, and other internal systems. A sufficiently privileged n8n token can expose workflow definitions and execution data, allow attackers to us...
    
    Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrati...
  4. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...atapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim Manizada on July 28, 2026. The bug sits in the kernel datapath, not the userspace ovs-vswitchd daemon. In a technical write-up , Manizada said an attacker needs "no existing OVS bridge, no running ovs-vswitchd, no host-level CAP_NET_ADMIN." On affected systems where the OVS kernel datapath is available and unprivileged user namespaces are enabled, an ordinary user can create private user and network namespaces with unshare -Urn, gain CAP_NET_ADMIN inside that namespace, and reach the vulnerable flow-installation path. If the openvswitch module i...
  5. The Hacker News | #1 Trusted Source for Cybersecurity News
    ...njects a Git hook through the internal logger, and triggers that hook during an anonymous clone. That chain is described in Gite...
    
    AI Threat Readiness 101WizCloud Security / AI SecurityLearn the four pillars of AI threat readiness and how security teams can reduce risk faster with detection, validation, and remediation built for today's threat landscape.
    
    Leaked n8n API Tokens Exposed Live Instances to Credential Theft
    Aug 05, 2026
    AI Security / DevSecOps
    
    GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896 instances reachable a...
Sources

<- Back to library