Post

Cybersecurity Newsfeed - 26/08/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 26/08/26

Cybersecurity Newsfeed

📅 26/08/26

🛡️ Vulnerabilities

  • Gitea Code Injection Flaw Added to CISA KEV (CVE-2026-60004): The Cybersecurity and Infrastructure Security Agency added CVE-2026-60004 to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. The code injection vulnerability affects Gitea, an open-source self-hosted Git service, allowing attackers to execute arbitrary code and gain control over exposed assets. Federal agencies are required to prioritize remediation under BOD 26-04. More info

  • Zimbra SNMP Command Injection (CVE-2026-73570): Over 270 Zimbra Collaboration Suite servers have been compromised in ongoing attacks exploiting a high-severity command injection vulnerability in the SNMP monitoring component. The flaw allows unauthenticated remote attackers to execute arbitrary code on servers with SNMP notifications enabled. CERT Polska and CISA issued urgent remediation advisories. More info

  • Unpatched Calix GS7 Router UPnP Flaw (CVE-2026-75501): An unpatched missing authentication flaw affects Calix GS7 XGS (GS5239XG) residential routers running EXOS/6.6.47 firmware. The router exposes its UPnP WANIPConnection SOAP service on TCP port 5000, allowing unauthenticated attackers to create permanent port-forwarding rules and bypass NAT to expose internal devices directly to the public internet. More info

🎯 Adversaries

  • AnonyMousKIT Uses AI Voice Agents to Bypass Activation Lock: A phishing-as-a-service platform called AnonyMousKIT uses AI-powered voice agents and fake Apple support pages to bypass Activation Lock on stolen iPhones. Operatives contact victims to trick them into disclosing passcodes, Apple IDs, and 2FA codes using over 500 connected domains and automated call bots. More info

  • Mirage2FA Campaign Hits Over 4,500 Domains: The Mirage2FA phishing-as-a-service campaign has targeted over 4,500 organizational email domains in the U.S. and Europe. Utilizing adversary-in-the-middle (AiTM) techniques, the campaign steals passwords and session cookies to bypass two-factor authentication on Microsoft 365 logins. More info

  • E4del and PINHOLE RATs Weaponize FTP Server Banners: Threat actors are deploying E4del and PINHOLE remote access trojans by utilizing FTP server banners as dead drop resolvers. Embedded command payloads in protocol response strings trigger execution via Windows Shortcut files, WebDAV, and Early Bird APC injection. More info

  • Fake Minecraft WeedHack Malware Persists After C2 Takedown: The WeedHack malware-as-a-service campaign continues targeting Minecraft players through SEO poisoning, AI-built landing pages, and lookalike websites despite primary C2 servers being offline. File-hosting platforms and EtherHiding smart contracts are used to distribute infostealers. More infoMore info
  • 24 npm Packages Abuse UNPKG Mirrors for Phishing: Security researchers uncovered 24 npm packages that abuse UNPKG mirrors to host fake Cloudflare CAPTCHA verification pages. The packages serve HTML files via UNPKG links to execute redirects to fake authentication portals or fetch encrypted URLs from public KV store APIs. More infoMore info
  • Identity Verification Checkpoints Become Primary Attack Surface: Threat actors are shifting focus to identity verification checkpoints during employee onboarding and account recovery. Tactics include submitting fraudulent documentation via fake remote workers and using synthetic media or deepfake voice cloning to trick helpdesks into forcing password resets. More info

  • Cryptographic Context Injection Bypasses AI Safety Guardrails: Researchers identified an attack method called Cryptographic Context Injection that bypasses safety guardrails in AI assistants such as Grok and Gemini. By hiding prompt injection instructions inside encrypted payloads, the AI decrypts and executes the hidden commands as trusted inputs. More info

  • Silent Patching Practices Blind Defenders: Software vendors silently patching vulnerabilities without issuing CVEs or advisory documentation leave security administrators without necessary risk context. While silent fixes fail to stop skilled attackers from reverse-engineering binaries, they deprive defenders of details needed for detection signatures and patch prioritization. More info

💥 Breaches & Leaks

  • LACMA Discloses Data Breach Exposing SSNs and Health Data: The Los Angeles County Museum of Art disclosed a data breach following suspicious network activity detected in July 2025. Investigations finalized in February 2026 confirmed unauthorized access compromised full names, dates of birth, Social Security numbers, driver’s licenses, and health insurance information. More info

  • Hospital Operator Nutex Health Reports Data Theft: Healthcare provider Nutex Health disclosed a data breach in an SEC filing after detecting unauthorized data exfiltration from company servers across its 28 medical facilities in 12 states. Forensic teams are currently assessing the extent of compromised patient, employee, or financial data. More info

📚 Others

  • Microsoft PowerToys Adds Window Hopper and Workspace Features: Microsoft released Windows PowerToys version 0.101.2362.0, introducing a utility called Window Hopper that enables users to switch exclusively between open windows of the currently active application. The update also adds multi-monitor brightness synchronization and Command Palette enhancements. More info

  • WhatsApp Enhances Two-Step Verification and Passkey Support: WhatsApp updated its account security features by expanding passkey support across multiple Android and iOS devices on a single account. Two-step verification now supports long, complex alphanumeric passwords instead of standard six-digit PINs, alongside expanded caller context displays. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.