Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:19 26/08/2026 UTC
Last updated: 04:04 26/08/2026 UTC

Latest updates

Browse →

Los Angeles County Museum of Art (LACMA) customer data exposed after Los Angeles County Museum of Art (LACMA) breach

Data Leak

Updated: 26.08.2026 00:58 · First: 26.08.2026 00:58 · 📰 1 src / 1 articles · H score: 23

LACMA disclosed a data breach that may have exposed customer and employee information, including Social Security numbers, government ID numbers, partial financial account numbers, and medical information. The museum detected suspicious activity on July 11, 2025, and later confirmed its network was compromised. The newly identified exposure scope raises identity-theft and privacy risk for impacted individuals.

Los Angeles County Museum of Art (LACMA) hit by cyberattack

Incident

Updated: 26.08.2026 00:58 · First: 26.08.2026 00:58 · 📰 1 src / 1 articles · H score: 16

The Los Angeles County Museum of Art (LACMA) disclosed a breach that exposed customer and employee information, including sensitive personal and medical data. The museum said it detected suspicious activity on July 11, 2025 after it had begun four days earlier. An investigation later confirmed the network was compromised. The exposure increases identity theft and fraud risk for impacted individuals.

AnonyMousKIT voice-AI phishing campaign against Apple device owners

Campaign

Updated: 25.08.2026 23:25 · First: 25.08.2026 23:25 · 📰 1 src / 1 articles · H score: 30

A campaign run by AnonyMousKIT used voice AI personas to phish Apple device owners and steal passcodes, expanding a documented operation that made 200 calls from August 2025 to May 2026. The activity matters because the fake Apple contact flow can lead to Apple Account takeover, Activation Lock bypass, and device resale. SOCRadar also found the operation had a global footprint, with heavier targeting in Brazil and several other countries.

AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network

Threat Actor Meta

Updated: 25.08.2026 23:25 · First: 25.08.2026 23:25 · 📰 1 src / 1 articles · H score: 36

Researchers uncovered AnonyMousKIT, a phishing-as-a-service ecosystem that automates stolen-iPhone unlocking and expands credential theft across a reseller network, increasing the risk of Activation Lock bypass and Apple ID compromise. The operation has been active since early 2024 and extends beyond device theft into access to iCloud backups and Keychain data. Its footprint spans 506 domains and 168 storefront brands, showing a scaled underground service rather than a single phishing site. The use of voice AI agents and global targeting, with heavy concentration in Brazil, raises the likelihood of repeated abuse against both consumer and workplace accounts.

Digdir government digital services DDoS disruption

Service Disruption

Updated: 25.08.2026 18:52 · First: 25.08.2026 18:52 · 📰 1 src / 1 articles · H score: 1

Norway’s Digdir government digital infrastructure is experiencing an ongoing DDoS-driven service disruption that has left some public services unavailable or partially accessible since Monday at 03.38 CEST. The outage affects core digital functions such as ID-porten and eSignering, creating login errors, slow responses, and access failures for public-sector users.

Nutex Health hit by data theft breach

Incident

Updated: 25.08.2026 17:44 · First: 25.08.2026 17:44 · 📰 1 src / 1 articles · H score: 31

The Nutex Health breach disclosure now centers on unauthorized access and exfiltration from company servers, creating risk that private and confidential information was exposed. The healthcare provider said it has launched an ongoing investigation, activated its cybersecurity response plan, and begun containment. As of August 24, it had not identified a material impact on operations or financial reporting systems.

ZeroTokens real-time phishing campaign

Campaign

Updated: 25.08.2026 17:30 · First: 25.08.2026 17:30 · 📰 1 src / 1 articles · H score: 36

The ZeroTokens phishing campaign is steering victim sessions in real time, raising the chance that credentials and financial information are captured across more than 700 organizations. Operators can monitor what victims enter and change the next prompt while keeping the session active through failed verification attempts. The operation uses a believable W-8BEN tax-documentation lure and infrastructure that passes SPF, DKIM, and DMARC checks.

NVIDIA NemoClaw Ollama browser-to-localhost control security flaw

Vulnerability

Updated: 25.08.2026 17:07 · First: 25.08.2026 17:07 · 📰 1 src / 1 articles · H score: 15

A malicious webpage can exploit NVIDIA NemoClaw's Ollama backend when it is bound to 0.0.0.0:11434, enabling unauthenticated local control of the model API. The attacker can use DNS rebinding to reach the local service and overwrite the model's chat template. That can plant hidden instructions that persist across later conversations.

RecruitTrap fake recruiter corporate credential phishing campaign

Campaign

Updated: 25.08.2026 16:00 · First: 25.08.2026 16:00 · 📰 1 src / 1 articles · H score: 7

RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-screen counterfeit login pages and pre-qualification checks to filter out personal email addresses, which increases the chance that stolen logins map to enterprise accounts. Compromised access could expose OAuth tokens, internal communications, and cloud applications.

WhatsApp rolls out multiple passkeys, stronger two-step verification, and scam-call context

Security Tool/Service

Updated: 25.08.2026 16:00 · First: 25.08.2026 16:00 · 📰 2 src / 2 articles · H score: 11

WhatsApp is rolling out new account security controls that expand passkey support, strengthen two-step verification, and add more call-screen scam context for suspicious non-contact callers. The update reduces account-takeover and scam risk for users across Android and iOS. It also extends a broader security push that already included Strict Account Settings, fraudulent device-linking warnings, and Scam Alert protections.

Marimo notebook software MCP command code injection security flaw (CVE-2026-75149)

Vulnerability

Updated: 25.08.2026 15:43 · First: 25.08.2026 15:43 · 📰 1 src / 1 articles · H score: 30

A code injection flaw in Marimo notebook software lets a specially crafted notebook run an attacker-supplied MCP command as a local subprocess when opened in edit mode, exposing versions prior to 0.23.15. The vulnerability is tracked as CVE-2026-75149 and carries CVSS v4 8.7 and CVSS v3.1 8.8 scores. Marimo fixed the issue in 0.23.15, and users on affected releases should upgrade.

Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)

Vulnerability

Updated: 20.08.2026 12:46 · First: 20.08.2026 12:46 · 📰 3 src / 5 articles · H score: 46

CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is being actively exploited for unauthenticated remote code execution through a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. Synacor released ZCS 10.1.20 on July 20 to patch the flaw, while CERT Polska and CISA flagged the vulnerability for urgent response. Shadowserver later reported 274 compromised instances seen on 2026-08-22, alongside at least 8200 unpatched instances in its scans.

CISA A Tale of Two SOCs mitigation advisory

Advisory/Mitigation

Updated: 25.08.2026 15:00 · First: 25.08.2026 15:00 · 📰 1 src / 1 articles · H score: 26

CISA published A Tale of Two SOCs, an advisory that turns red team findings into mitigation guidance for critical infrastructure organizations defending IT, cloud, and OT environments. The advisory highlights how detection and response outcomes differed sharply between two assessed organizations. It directs defenders to strengthen baselines, monitoring, and coordination to improve resistance to real-world threat activity.

CISA red-team advisory for critical infrastructure

Public Sector Action

Updated: 25.08.2026 15:00 · First: 25.08.2026 15:00 · 📰 1 src / 1 articles · H score: 28

On 2026-08-25, CISA published A Tale of Two SOCs, a public advisory drawn from red team assessments for two critical infrastructure organizations. The guidance helps organizations improve detection, response, and protections across IT, cloud, and OT environments. It shows how monitoring, baselines, and faster containment can determine whether initial access is detected or escalated.

Mirage2FA Microsoft 365 phishing-as-a-service campaign

Campaign

Updated: 25.08.2026 14:56 · First: 25.08.2026 14:56 · 📰 1 src / 1 articles · H score: 53

The Mirage2FA phishing-as-a-service campaign is actively targeting Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, putting authenticated sessions and connected services at risk. Activity spans 2024 to 2026 and has affected thousands of companies. ANY.RUN linked the operation to 4,532 unique organization email domains and more than 9,000 potential compromise events. The broad session-theft model increases the risk of impersonation, fraud, and follow-on access through SSO-connected services.

24 Npm packages and unpkg fake CAPTCHA phishing campaign

Campaign

Updated: 25.08.2026 14:52 · First: 25.08.2026 14:52 · 📰 2 src / 2 articles · H score: 36

OX Security disclosed a 24 npm packages campaign abusing npm and unpkg mirrors to host fake Cloudflare CAPTCHA pages. The mirrored HTML rendered from trusted mirror domains and used ClickFix-style redirect flows to send visitors onward, with the lure first using login[.]microsofte[.]live and later api.keyval[.]org. The redirect logic was reported to send users to the ChatGPT website at the time of research, while the same setup could be repurposed for other phishing destinations. The activity turns package mirrors into a trusted-hosted delivery layer for phishing pages and other attacker-chosen content.

Operation Jackal IV international cybercrime arrests

Law Enforcement

Updated: 25.08.2026 13:53 · First: 25.08.2026 13:53 · 📰 1 src / 1 articles · H score: 15

Law enforcement agencies from 22 countries arrested 58 individuals and identified 263 suspects in Operation Jackal IV, disrupting West African cybercrime networks tied to the Black Axe syndicate. The joint action targeted cyber-enabled financial fraud, including romance scams, investment scams, and business email compromise. In South Africa, authorities also blocked 257 bank accounts and seized $2.67 million from a criminal syndicate. The operation extended across November 2025 to June 2026, showing the scale of the multinational enforcement effort.

CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962

Public Sector Action

Updated: 25.08.2026 09:12 · First: 25.08.2026 09:12 · 📰 1 src / 1 articles · H score: 49

CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. The action requires Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in operators in the federal civilian branch to apply fixes by August 27, 2026. The directive reduces the window for further abuse of a CVSS 10.0 access-control bug that can expose or alter critical data.

Calix GS7 XGS (GS5239XG) missing-authentication UPnP WAN bypass (CVE-2026-75501)

Vulnerability

Updated: 25.08.2026 00:14 · First: 25.08.2026 00:14 · 📰 1 src / 1 articles · H score: 15

CVE-2026-75501 exposes Calix GS7 XGS (GS5239XG) residential routers to unauthenticated WAN UPnP port-forwarding, creating a path to bypass NAT and firewall protections. The flaw affects devices running EXOS/6.6.47 firmware and can let remote attackers open a path from the public internet to internal devices. No vendor fix is available, so users are being told to disable UPnP or ask their ISP to do so.

MiniOrange SAML 2.0 Single Sign On plugin for WordPress authentication bypass flaws (multiple vulnerabilities)

Vulnerability

Updated: 24.08.2026 22:26 · First: 24.08.2026 22:26 · 📰 2 src / 2 articles · H score: 46

miniOrange SAML 2.0 Single Sign On plugin for WordPress has two authentication bypass vulnerabilities that are being actively exploited and can be chained to let attackers log in as administrators on affected sites. The flaws are tracked as CVE-2026-61979 and CVE-2026-15981, and a public PoC exploit increases the risk of wider abuse.

ShinyHunters company[.]claims impersonation campaign

Campaign

Updated: 24.08.2026 18:17 · First: 24.08.2026 18:17 · 📰 2 src / 2 articles · H score: 30

ShinyHunters is running a widespread impersonation campaign that uses company[.]claims domains to spoof help desks and IT teams, creating a repeatable credential-theft risk for targeted organizations. The operation pairs vishing with fake SSO pages and lookalike domains to capture login details. The pattern shows a broad, reusable social-engineering playbook rather than a single isolated lure.

Fake Codex download campaign using Google Sites and ClickFix

Campaign

Updated: 24.08.2026 18:00 · First: 24.08.2026 18:00 · 📰 1 src / 1 articles · H score: 35

The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The fake portal impersonates an OpenAI Codex download page and steers victims into opening Terminal and pasting a command. That command decodes a URL, fetches a shell-script loader, and ends with a Mach-O payload. The delivery chain also overlaps with Atomic macOS Stealer (AMOS) techniques.

Modu-ui Changup startup audition platform data leak via exposed API key

Data Leak

Updated: 24.08.2026 17:00 · First: 24.08.2026 17:00 · 📰 1 src / 1 articles · H score: 28

A Modu-ui Changup data leak exposed email addresses, evaluation comments, and startup idea summaries for about 5,000 successful applicants. The exposure mattered because an encryption key was found in the API, allowing encrypted records to be disclosed. The leak involved a government-backed startup audition platform in South Korea.

Ministry of SMEs and Startups (MSS) announced that personal information and startup idea summaries had been leaked and launched a detailed investigation with partner agencies for

Public Sector Action

Updated: 24.08.2026 17:00 · First: 24.08.2026 17:00 · 📰 1 src / 1 articles · H score: 26

South Korea’s Ministry of SMEs and Startups announced a personal-information leak and opened a joint investigation, escalating the official response to a breach affecting applicants on a government-backed startup platform. The inquiry involves the National Intelligence Service, the Cyber Security Center, and the National Police Agency. The response centers on Modu-ui Changup (모두의창업), which supports a nationwide startup audition program and holds applicants’ names, email addresses, and startup ideas.

Keycloak password-reset account takeover flaw (CVE-2026-18963)

Vulnerability

Updated: 24.08.2026 14:56 · First: 24.08.2026 14:56 · 📰 1 src / 1 articles · H score: 31

Patches are available for CVE-2026-18963 in Keycloak, closing a critical password-reset flaw that could let an unauthenticated remote attacker seize any user account, including administrative accounts. The weakness is an improper state validation bug in the reset-credentials flow, where a crafted request can jump straight to password update without the normal email action token. Fixed builds are Keycloak 26.7.2 and Red Hat build of Keycloak 26.4.15 / 26.6.6, with a temporary workaround to disable Forgot password.

COOLCLIENT updated backdoor deploying Msagent.sys

Malware Activity

Updated: 24.08.2026 14:51 · First: 24.08.2026 14:51 · 📰 1 src / 1 articles · H score: 23

The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is tied to Mustang Panda and was observed in operations spanning Myanmar, Mongolia, Pakistan, and Russia. The malware's expanded kernel-mode layer makes inspection and remediation harder while preserving its backdoor functionality.

Operation QUICSILVER Myanmar espionage campaign

Campaign

Updated: 24.08.2026 14:51 · First: 24.08.2026 14:51 · 📰 1 src / 1 articles · H score: 32

The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that deliver the QUICAgent backdoor. The activity was first observed in April 2026 and later resurfaced with related artifacts in June and July 2026. The multi-stage chain combines a malicious LNK, ftp.exe abuse, and staged payload reconstruction, increasing the chance of stealthy compromise.

Microsoft Windows 11 gaming disruption after KB5121003

Service Disruption

Updated: 21.08.2026 17:54 · First: 21.08.2026 17:54 · 📰 1 src / 2 articles · H score: 0

The Windows 11 gaming disruption is causing crashes, launch failures, freezes, and restarts on affected PCs, and Microsoft is investigating the problem. The issue affects Windows 11 24H2 and 25H2 systems after KB5121003 and later updates. Early findings point to RGB lighting devices whose drivers or components may trigger the breakage when certain games start. Embark Studios has shared a temporary inpoutx64.sys workaround while Microsoft works on an official fix.

British power plant hit by network compromise

Incident

Updated: 24.08.2026 12:22 · First: 24.08.2026 12:22 · 📰 1 src / 1 articles · H score: 11

A British power plant suffered a cyberattack that shut it down for four days in July 2026, disrupting energy operations. The event was later disclosed on August 22, 2026, with limited detail from official channels including the NCSC. The incident shows that even a relatively small UK energy facility can face multi-day operational disruption from a hostile intrusion.

Iran-affiliated cyber campaign targeting the US, Israel, GCC, and Europe

Campaign

Updated: 24.08.2026 12:22 · First: 24.08.2026 12:22 · 📰 1 src / 1 articles · H score: 42

Iran-affiliated cyber groups are running a multi-region campaign that has targeted the US, Israel, the GCC, and Europe since the outbreak of the war with the US / Israel. The activity spans water, critical infrastructure, military, government, energy, and healthcare sectors, and it has now reached Britain. The breadth of the target set points to a sustained adversary operation rather than a single isolated intrusion.