βΌοΈ Rust supply chain attack hits three crates, including 245 million-download arrayref.
A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
Check your Cargo cache and pinned versions now: https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html
A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
Check your Cargo cache and pinned versions now: https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html
π14β‘4
β οΈ A CVSS 10.0 Entra ID flaw was exploited in the wild.
CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.
Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Read more: https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.
Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Read more: https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
π±10π₯4β‘1
π» Attackers are exploiting a GitLab flaw days after disclosure.
CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.
Running self-hosted GitLab? Patch now: https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.
Running self-hosted GitLab? Patch now: https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
π₯7π4β‘2
βΌοΈ Five CVSS 10.0 flaws affect Cisco Crosswork and Secure Workload.
Theyβre among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.
Read: https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html
Theyβre among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.
Read: https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html
π5π₯4
Wazuh now uses Claude to automate scheduled SOC reports.
Wazuh AI Analyst processes cloud security data through Amazon Bedrock and Claude, then reports on alerts, protected endpoints, active vulnerabilities, and security posture.
Teams can also plug Wazuh into self-hosted Llama 3 or Claude 3.5 Haiku.
See how it works: https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html
Wazuh AI Analyst processes cloud security data through Amazon Bedrock and Claude, then reports on alerts, protected endpoints, active vulnerabilities, and security posture.
Teams can also plug Wazuh into self-hosted Llama 3 or Claude 3.5 Haiku.
See how it works: https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html
π₯15π6π€3
β οΈ Android car head units are getting malware through built-in updaters.
Attackers abused DoFunβs update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Full details: https://thehackernews.com/2026/08/android-car-malware-spreads-through.html
Attackers abused DoFunβs update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Full details: https://thehackernews.com/2026/08/android-car-malware-spreads-through.html
π15π₯10π2π±2β‘1
βΌοΈ Attackers can weaponize Defenderβs own signed driver to delete security software at boot.
BTR.sys runs from Ring 0 before Defenderβs user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
See how it works: https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
BTR.sys runs from Ring 0 before Defenderβs user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
See how it works: https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
π₯10π6β‘2
βΌοΈ 14 npm packages drop RedC2 4.0 on Linux.
The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
Read - https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
Read - https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
π€15β‘1
β‘ TikTok will pay $400 million over child privacy allegations.
The U.S. case accused TikTok of knowingly allowing children under 13 to create accounts, collecting data from Kids Mode users, and failing to honor parental deletion requests.
Read the details: https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html
The U.S. case accused TikTok of knowingly allowing children under 13 to create accounts, collecting data from Kids Mode users, and failing to honor parental deletion requests.
Read the details: https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html
π29π14π5π€―3β‘1
β οΈ UAT-10147 is using AI to scale server attacks.
The group uses AI across exploitation and post-compromise activity, then deploys SPECTRE.
β On Windows, SPECTRE can blind EDR.
β On Linux, it loads a persistent kernel rootkit.
See how it works: https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html
The group uses AI across exploitation and post-compromise activity, then deploys SPECTRE.
β On Windows, SPECTRE can blind EDR.
β On Linux, it loads a persistent kernel rootkit.
See how it works: https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html
π10π8
π¨ Fake graduation invites are delivering a Go backdoor in Myanmar.
Recent Operation QUICSILVER samples use a malicious LNK inside a VHD, abuse Windows ftp.exe, then deploy QUICAgent, which communicates with its C2 over QUIC on UDP 443.
Read: https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html
Recent Operation QUICSILVER samples use a malicious LNK inside a VHD, abuse Windows ftp.exe, then deploy QUICAgent, which communicates with its C2 over QUIC on UDP 443.
Read: https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html
π₯9π2
Nearly half of enterprise AI chats use personal identities.
Akamai found 47.11% happen outside corporate-managed accounts, while the top 5% of users interact with AI at 12Γ the rate of the bottom half.
Shadow AI risk is concentrated among a small group of heavy users.
Read the findings: https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html
Akamai found 47.11% happen outside corporate-managed accounts, while the top 5% of users interact with AI at 12Γ the rate of the bottom half.
Shadow AI risk is concentrated among a small group of heavy users.
Read the findings: https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html
π5π€―2π1
βΌοΈ A critical Keycloak flaw could let attackers take over any account.
CVE-2026-18963 lets an unauthenticated attacker reset a userβs password without the emailed action token, including for admin accounts.
Read more: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
CVE-2026-18963 lets an unauthenticated attacker reset a userβs password without the emailed action token, including for admin accounts.
Read more: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
π₯8π€―6π1
π¨ Fake CAPTCHA prompts are delivering Amatera Stealer.
WordlistLoader powers the ClearFake ClickFix chain on compromised websites.
Separately, Microsoft Teams phishing delivers SynkLoader. Its fake Windows lock screen can capture login passwords.
Read: https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html
WordlistLoader powers the ClearFake ClickFix chain on compromised websites.
Separately, Microsoft Teams phishing delivers SynkLoader. Its fake Windows lock screen can capture login passwords.
Read: https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html
π6π₯2π1
β‘ Shipping code 10β50Γ faster? Security has to keep up.
AI coding is adding open-source dependencies faster, and remediation debt can pile up behind them.
See what 300 enterprise leaders found, where controls are falling short, and which governance models are working.
Join the webinar: https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html
AI coding is adding open-source dependencies faster, and remediation debt can pile up behind them.
See what 300 enterprise leaders found, where controls are falling short, and which governance models are working.
Join the webinar: https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html
π7
β‘ This week in cybersecurity:
π€ AI PLC Attacks
π¨ GitLab Exploited
π¦ npm Backdoors
π³ Zombie Card Fraud
π Auth Flow Hijacks
βοΈ Cloud Spectre Leak
πΈοΈ Windchill Web Shells
π± Android Kernel Flaw
π° Stripe Keys Leaked
π₯οΈ ScreenConnect Abuse
π£ DCRat Phishing
π Find My Tracking
π§ Audio Fingerprinting
Catch up on everything that mattered this week - https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html
π€ AI PLC Attacks
π¨ GitLab Exploited
π¦ npm Backdoors
π³ Zombie Card Fraud
π Auth Flow Hijacks
βοΈ Cloud Spectre Leak
πΈοΈ Windchill Web Shells
π± Android Kernel Flaw
π° Stripe Keys Leaked
π₯οΈ ScreenConnect Abuse
π£ DCRat Phishing
π Find My Tracking
π§ Audio Fingerprinting
Catch up on everything that mattered this week - https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html
π₯11π3π2
β οΈ Fake Minecraft clients are spreading Weedhack malware through search results.
Spoofed sites for Xenon, Nova, and other clients can outrank legitimate sources. Weedhack JARs can steal data and add Microsoft Defender exclusions.
How it spreads: https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html
Spoofed sites for Xenon, Nova, and other clients can outrank legitimate sources. Weedhack JARs can steal data and add Microsoft Defender exclusions.
How it spreads: https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html
π₯5π2π€―2π±1