Cybersecurity Newsfeed - 28/08/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 28/08/26
🛡️ Vulnerabilities
Critical Next.js RCE Flaws (CVE-2026-75604 & GHSA-2xp9-vwfh-vxw4): Vercel released emergency updates for Next.js fixing a Windows path traversal flaw and a heap buffer overflow in the libheif library triggered via AVIF image optimization. Both permit unauthenticated remote code execution. More info
CISA Adds 3 Flaws to KEV Catalog: CISA added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), and CVE-2026-66384 (JFrog Artifactory) to its KEV Catalog due to active exploitation. Federal agencies must remediate them per BOD 26-04 timelines. More info
CISA Adds 6 Flaws to KEV Catalog: CISA expanded its catalog with six additional active exploits, including Red Hat (CVE-2015-3246, CVE-2015-5287), MS SQL Server (CVE-2019-1068), Ajax.NET Professional (CVE-2021-23758), Linux Kernel (CVE-2022-0995), and Citrix NetScaler (CVE-2026-8452). More info
Critical Avada & Fusion Builder WordPress Flaw (CVE-2026-18431): An exploit chain rated CVSS 9.8 allows unauthenticated attackers to execute arbitrary PHP code on vulnerable WordPress sites. Emergency fixes were released in Avada 7.16.1. More info
Ubiquiti Maximum-Severity Patches: Ubiquiti patched three critical flaws allowing unauthenticated RCE or authentication bypass across UniFi Protect (CVE-2026-77537), UniFi OS (CVE-2026-77550), and UniFi Talk (CVE-2026-77554). More info
Active Exploitation Chain Targeting Microsoft SharePoint: Attackers are chaining CVE-2026-55040 (JWT authentication bypass) and CVE-2026-63520 (Business Connectivity Services RCE) to perform administrative enumeration and gain execution on SharePoint servers. More info
Amazon Kiro IDE Prompt Injection: A flaw in version 0.7.45 allows malicious repository files (
POWER.md) to hijack the AI agent and exfiltrate sensitive local files to external endpoints. The issue was fixed in version 0.8.140. More info- GPUThor Rowhammer Attack on NVIDIA GPUs: University of Toronto researchers demonstrated GDDR6 memory hammering on workstation GPUs (RTX A6000/A5000), bypassing ECC protection to cause memory corruption and host privilege escalation to root. More info
🎯 Adversaries
Dark Caracal Deploys GoCaracal Malware: Arctic Wolf Labs tied a Venezuelan communications breach to the Lebanon-nexus group Dark Caracal, who deployed a new Go-based implant with an Ethereum smart-contract C2 fallback mechanism. More info
TeamPCP Cybercrime Syndicate Arrests: Law enforcement in Australia and the US arrested two men for planting a self-spreading worm (Mini Shai-Hulud) in open-source repositories, compromising over 1,000 organizations. More info
FBI Disrupts China-Linked “QTFY” Proxy Infrastructure: The FBI seized domain infrastructure used by QTFY, a quartermaster group operating reconnaissance platforms (QScan) and proxy networks (QTRouter) targeting US government entities. More info
NovaCookies Phishing-as-a-Service: A new AiTM phishing kit advertised on Telegram abuses DocuSign notification emails and OAuth redirects to bypass MFA and hijack Microsoft 365 sessions. More info
SLEEPWALKER Stealth Memory Backdoor: Researchers detailed a passive Windows backdoor that side-loads into
ERAAgent.exeasdpapi.dll. It remains silent until triggered by a specific encrypted network packet. More infoMobile Tech Support Scam Fake Apple Pay Interface: Malicious websites are mimicking Apple Pay and Face ID components while leveraging the Web Speech API to read out fake charge alerts and pressure victims into calling fraudulent support lines. More info
AnonyMousKIT Phishing Targets Lost Apple Devices: An automated phishing kit uses AI voice agents, SMS, and email lures impersonating Apple Support to trick victims into revealing passcodes and MFA tokens to bypass Activation Lock. More info
📈 Trends
Unit 42 Warns of Agentic AI Acceleration: Palo Alto Networks highlighted that threat actors are leveraging autonomous AI frameworks across attack chains, allowing single attackers to compromise tens of enterprise applications in hours. More info
Apple AI Rollout Meets EU Regulatory Friction: EU Digital Markets Act requirements are forcing changes to Apple’s ecosystem, causing delays for features like Siri AI while pushing reliance on Google Gemini models on Private Cloud Compute. More info
Android 17 Integrates Encrypted Client Hello (ECH): Google announced platform-level support for ECH in Android 17 to encrypt SNI domain metadata, alongside ECH GREASE implementation and mandatory Certificate Transparency. More info
HTTP Terminator AI Framework Discovers Smuggling Vectors: PortSwigger unveiled an open-source AI tool that autonomously identifies novel HTTP request desync vectors against modern web infrastructure. More info
Evolution of Modern SOCs to AI Hypothesis Engines: Security operations are transitioning away from manual queue triage toward asynchronous agentic AI engines that test threat hypotheses across raw network telemetry automatically. More info
Snowflake Enforces Phase 3 Service Account Security: Snowflake has deprecated legacy password authentication for non-human accounts, requiring migration to SERVICE user types, OAuth, or Workload Identity Federation. More info
💥 Breaches & Leaks
ShinyHunters Leaks 13M Carhartt Records: Following a failed $3.3M extortion attempt linked to a Databricks environment compromise, ShinyHunters published 50GB of stolen customer and employee data. More info
ATF Confirms Standalone System Incident After QILIN Claims: The Bureau of Alcohol, Tobacco, Firearms and Explosives disconnected a segregated standalone system following extortion claims by the Qilin ransomware gang. More info
Boston Scientific Operations Disrupted by Cyberattack: A cyber incident detected on August 25 impacted global order processing and shipping services, forcing the medical device maker to deploy external response teams. More info
📚 Others
- Meta Agrees to $17B Child Safety Lawsuit Settlement: Resolving a multi-state attorney general lawsuit over teen mental health and privacy, Meta agreed to mandate daily screen time limits and default safety controls on Instagram and Facebook. More info
