Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:34 09/08/2026 UTC
Last updated: 18:19 08/08/2026 UTC

Latest updates

Browse →

Head Mare multi-sector campaigns targeting Russian organizations

Campaign

Updated: 08.08.2026 17:16 · First: 08.08.2026 17:16 · 📰 1 src / 1 articles · H score: 34

Multiple Head Mare campaigns are active against Russian organizations across several sectors, using phishing, public-facing web server exploitation, and contractor access to broaden intrusion opportunities. The operation increases the risk of repeat compromise across instrumentation, electronics, transportation, energy, IT, and software development organizations.

TrueConf Server actively exploited arbitrary code execution and sandbox escape flaws security flaw

Vulnerability

Updated: 08.08.2026 17:16 · First: 08.08.2026 17:16 · 📰 1 src / 1 articles · H score: 41

TrueConf Server flaws KLCERT-26-057 and KLCERT-26-058 were used in active attacks to escape the sandbox and reach the underlying OS, exposing older servers to SYSTEM-level code execution. The weaknesses affect 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. The vendor fixed the issues on June 18.

Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw

Vulnerability

Updated: 08.08.2026 11:54 · First: 08.08.2026 11:54 · 📰 1 src / 1 articles · H score: 1

The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-app data the signed-in user could access. Varonis Threat Labs independently confirmed the one-click link route, and Atlassian closed that path server-side on July 8, 2026. The flaw turned permitted access into an outbound data leak without requiring the victim to intentionally share the data.

Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft

Technical Analysis

Updated: 08.08.2026 11:03 · First: 08.08.2026 11:03 · 📰 1 src / 1 articles · H score: 30

PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The disclosure includes proof-of-concept chains for password capture, token theft, click hijacking, and AI-email prompt injection. Several paths were still working when published, while others had already been fixed or stopped working on retest.

Metabase unauthenticated SQL injection zero-day actively exploited SQL injection flaw

Vulnerability

Updated: 07.08.2026 23:14 · First: 07.08.2026 23:14 · 📰 2 src / 2 articles · H score: 49

A Metabase unauthenticated SQL injection zero-day put Metabase Cloud and self-hosted installations at risk of administrator takeover, credential theft, and data export. The flaw affected versions 1.58 and above and was confirmed actively exploited before disclosure on Aug. 7, 2026. Metabase said it blocked the attack endpoints and rolled out a fix for the vulnerability. Organizations running exposed self-hosted installs were told to upgrade immediately or temporarily block `/api/session/reset_password` while applying the patch.

N-able security patch release for CVE-2026-18577

Security Patch Release

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 3 articles · H score: 46

N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3.1.7 for all versions before 2026.3, after earlier investigation found remote administrative access on servers running 2026.1 and earlier. N-able says hosted deployments already received the update, while on-premises customers must install it manually. The company also provided IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 3 src / 6 articles · H score: 49

CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an incomplete fix for CVE-2026-18556, and the company shipped 2026.3.1.7 as the first unaffected release after finding a bypass of the earlier patch. The vendor said it detected active exploitation on August 1 and published IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder. CISA added CVE-2026-18577 to KEV on August 5, 2026 and told FCEB agencies to apply fixes by August 6 and review Take Control activity.

N-able N-central servers hit by network compromise

Incident

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 3 src / 5 articles · H score: 41

N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take Control and Cloudflared services. N-able said the activity affected a limited number of customers, began with signs of abuse on August 1, and led to CVE-2026-18577 and the emergency release of hotfix 2026.3.1.7 as the first unaffected version. CISA later added CVE-2026-18577 to KEV after reports of active exploitation, and published indicators include four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

Framework customer data leak from compromised Metabase instance

Data Leak

Updated: 07.08.2026 23:14 · First: 07.08.2026 23:14 · 📰 1 src / 1 articles · H score: 35

Framework confirmed a customer data leak after attackers compromised its Metabase instance, exposing personal and business records tied to customers. The stolen data included full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company names. The exposure raises risk of phishing, account targeting, and identity abuse for affected customers.

Unlimited Technology Systems hit by ransomware attack

Incident

Updated: 07.08.2026 22:30 · First: 07.08.2026 22:30 · 📰 1 src / 1 articles · H score: 60

Unlimited Technology Systems disclosed a data breach that exposed personal information for 3,803,750 people after an unauthorized actor accessed files in its commercial data center. The intrusion is tied to activity between October 5 and October 10, 2025, and the company later confirmed the exposure in July 2026. The breach involved sensitive patient data handled for healthcare providers, increasing identity-theft and privacy risk. The company said no ransomware or data-extortion group has publicly claimed responsibility.

WEL1DROPPER cross-platform RAT and infostealer delivery chain

Malware Activity

Updated: 07.08.2026 21:48 · First: 07.08.2026 21:48 · 📰 1 src / 1 articles · H score: 36

The WEL1DROPPER malware chain is delivering RAT and infostealer payloads through nearly 800 malicious npm packages, expanding cross-platform risk for Windows, macOS, and Linux systems. The packages use a README-driven require() path to trigger the loader, which fingerprints the host and retrieves a matching payload from Cloudflare Workers or fallback wel1[.]ru domains. On Windows, the final stage includes ETW/AMSI patching, sandbox checks, and persistence via a Registry Run key and scheduled task. On Linux, the chain can deploy Sliver, an open-source C2 framework, showing the loader is part of a broader malicious distribution operation.

Flooding Dropper malicious npm package campaign targeting Windows, Mac, and Linux

Campaign

Updated: 07.08.2026 21:48 · First: 07.08.2026 21:48 · 📰 1 src / 1 articles · H score: 44

A new npm supply-chain campaign has published nearly 800 malicious packages to push RAT and infostealer payloads onto Windows, Mac, and Linux systems. The packages use a README-driven require() path instead of the more common lifecycle-hook trigger, which helps the delivery blend into normal developer workflows. The operation is tracked as Flooding Dropper and appears to extend a prior Moika package-publishing pattern. The malware chain uses Cloudflare Workers, wel1[.]ru DNS TXT delivery, and platform-specific payloads to reach infected hosts.

Go-based macOS stealer with DRAIN wallet-draining routine

Malware Activity

Updated: 07.08.2026 21:29 · First: 07.08.2026 21:29 · 📰 1 src / 1 articles · H score: 29

A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also siphoning cryptocurrency from infected wallets. The malware's DRAIN routine increases financial risk for macOS users by redirecting wallet contents to attacker-controlled accounts.

Levi Strauss & Co. hit by network compromise

Incident

Updated: 07.08.2026 18:48 · First: 07.08.2026 18:48 · 📰 1 src / 1 articles · H score: 15

Levi Strauss & Co. disclosed a social-engineering breach that let attackers access and exfiltrate corporate data from three employees’ company-issued computers. The company said its rapid response contained and terminated the unauthorized access and that no consumer data was impacted. Levi’s also said it has seen no operational disruption from the incident.

Rust-based clipboard hijacker swapping cryptocurrency addresses via Binance Smart Chain

Malware Activity

Updated: 07.08.2026 17:00 · First: 07.08.2026 17:00 · 📰 1 src / 1 articles · H score: 18

A Rust-based clipboard hijacker was observed swapping copied cryptocurrency wallet addresses with attacker-controlled destinations, putting payment workflows across 21 blockchain types at risk. The malware used Binance Smart Chain for command-and-control resolution through EtherHiding. A victim could still see a normal-looking transaction even though the destination had already been changed locally before signing.

H1 2026 banking-malware campaign via compromised corporate mailboxes

Campaign

Updated: 07.08.2026 17:00 · First: 07.08.2026 17:00 · 📰 1 src / 1 articles · H score: 33

A banking-malware campaign used compromised corporate mailboxes to reach users in Czechia, Slovakia, Poland and Lithuania, pushing the attack into victims' banking sessions. The messages looked like routine shipment, invoice and scanned-document emails, which helped the lure blend into normal business traffic. The attachment launched JavaScript, then PowerShell, then shellcode, before the malware altered proxy settings and installed a browser add-on. The chain showed how a trusted account can deliver the first stage of an operation while later steps reshape the browser session used for banking.

WordPress login screen pre-auth reflected XSS (CVE-2026-64638)

Vulnerability

Updated: 07.08.2026 15:56 · First: 07.08.2026 15:56 · 📰 1 src / 1 articles · H score: 24

WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional conditions into PHP code execution, but the advisory reports no in-the-wild exploitation. WordPress fixed it in 7.0.3 and backported the patch through the 4.7 branch.

WordPress security patch release for CVE-2026-64638

Security Patch Release

Updated: 07.08.2026 15:56 · First: 07.08.2026 15:56 · 📰 1 src / 1 articles · H score: 34

WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately and said sites with automatic background updates should receive the patch automatically. The patch closes a pre-auth reflected XSS issue in the login screen that can be chained into deeper compromise under additional conditions.

Linux SCTP use-after-free flaw (CVE-2026-64564)

Vulnerability

Updated: 07.08.2026 14:10 · First: 07.08.2026 14:10 · 📰 1 src / 1 articles · H score: 26

CVE-2026-64564 in Linux's SCTP networking code can let local users reach root on SCTP-reachable hosts, and lab testing also showed a container escape path. The flaw was publicly disclosed on August 6, while fixes had already shipped in stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148 on August 3. No public exploit code had surfaced at the time of publication, but systems running older kernels remain exposed until they update or remove SCTP access. The bug has existed since 2008, making it a long-lived privilege-escalation risk in environments that still allow SCTP traffic.

Linux stable kernel maintainers security patch release for CVE-2026-64564

Security Patch Release

Updated: 07.08.2026 14:10 · First: 07.08.2026 14:10 · 📰 1 src / 1 articles · H score: 28

Linux stable kernels shipped fixes for CVE-2026-64564, closing an SCTP use-after-free that could give local users root on hosts with SCTP reachable. The patched builds are 7.1.6, 6.18.42, 6.12.101 and 6.6.148, all released August 3. Systems still running older kernels with SCTP enabled should update promptly.

Around 1 500 UK charities customer data exposed after Beacon breach

Data Leak

Updated: 07.08.2026 13:45 · First: 07.08.2026 13:45 · 📰 1 src / 1 articles · H score: 53

Beacon disclosed a data leak that put information from around 1,500 UK charities at risk, including groups in healthcare and victim support. The exposed material is believed to include names, email addresses, telephone numbers and donation records, with attachments also likely downloaded. The provider said the incident was contained, but the exposure creates ongoing notification and follow-on fraud risk for affected charities and their supporters.

Beacon hit by network compromise

Incident

Updated: 07.08.2026 13:45 · First: 07.08.2026 13:45 · 📰 1 src / 1 articles · H score: 52

Beacon confirmed a systems access incident after an attacker used a compromised access key to reach its environment, creating risk for customer data held in the platform. The provider said the incident was contained with external cybersecurity experts and that it had not observed ongoing unauthorized access.

Microsoft 365 AitM phishing campaign using residential proxies

Campaign

Updated: 07.08.2026 13:38 · First: 07.08.2026 13:38 · 📰 1 src / 1 articles · H score: 34

An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted hundreds of organizations in the U.S., Canada, and Europe, making the credential theft and session hijacking effort broad enough to affect many enterprises at once.

Apache Traffic Server desynchronization zero-day (CVE-2026-63078)

Vulnerability

Updated: 07.08.2026 13:09 · First: 07.08.2026 13:09 · 📰 1 src / 1 articles · H score: 35

A desynchronization zero-day in Apache Traffic Server was exposed and later patched, leaving a concrete server request-handling flaw tied to CVE-2026-63078. The weakness can disrupt how front-end and back-end responses are matched, creating risk for request confusion and downstream exposure. Public record checks at publication time did not yet show the CVE in CVE.org or NVD, so the fixed-release mapping remained uncertain.

HTTP Terminator discovery of new HTTP desynchronization techniques and response queue poisoning

Technical Analysis

Updated: 07.08.2026 13:09 · First: 07.08.2026 13:09 · 📰 1 src / 1 articles · H score: 44

HTTP Terminator generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors, expanding the attack surface for parser-confusion flaws. The research also validated response queue poisoning (RQP) and introduced a dangling-byte method that makes it more reliable. A separate path exposed a patched Apache Traffic Server zero-day tracked as CVE-2026-63078, showing direct product impact. The work further identified Shared-Parser Confusion, where response-processing logic can be misapplied to requests.

Linux Netfilter conntrack direction-validation flaw (CVE-2026-63913)

Vulnerability

Updated: 07.08.2026 12:32 · First: 07.08.2026 12:32 · 📰 1 src / 1 articles · H score: 23

CVE-2026-63913 in Linux Netfilter conntrack lets a crafted SYN plus invalid reset packet prematurely close a NAT entry, creating session-state manipulation risk for affected systems. The flaw was fixed in stable Linux releases including 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12, and 7.1. The issue was disclosed through the broader NatJack research and carries a CVSS score of 8.2.

NatJack Windows and Linux NAT state-hijack flaws (multiple vulnerabilities)

Vulnerability

Updated: 07.08.2026 11:52 · First: 07.08.2026 11:52 · 📰 1 src / 2 articles · H score: 23

NatJack exposes Windows NAT used by Hyper-V and Linux Netfilter conntrack to session hijacking, DNS spoofing, and NAT-table exhaustion. Researchers assigned CVE-2026-56181 and CVE-2026-63913 to the affected implementations, turning the attack class into a concrete vulnerability target. The issue affects systems that share NAT infrastructure across Windows and Linux environments, especially where untrusted workloads can manipulate connection state. Available updates reduce risk, but the broader attack class still needs isolation and traffic-protection controls.

NatJack NAT-state attack research and proof-of-concept exploitation

Technical Analysis

Updated: 07.08.2026 12:32 · First: 07.08.2026 12:32 · 📰 1 src / 1 articles · H score: 21

NatJack exposes a new NAT connection-state attack class that can hijack TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables, increasing risk across systems that share the same translation boundary. The findings show affected behavior in Windows and Linux, with concrete implementation flaws tracked as CVE-2026-56181 and CVE-2026-63913. The research matters because it turns an assumed trust boundary inside NAT infrastructure into a practical path for traffic manipulation and denial of service.

The Gentlemen and Qilin continue a ransomware dominance battle in July 2026

Threat Actor Meta

Updated: 07.08.2026 11:20 · First: 07.08.2026 11:20 · 📰 1 src / 1 articles · H score: 27

The Gentlemen and Qilin continued a ransomware dominance battle in July 2026, together accounting for 33% of claimed attacks and concentrating a large share of the market in two crews. The Gentlemen claimed 135 attacks while Qilin claimed 125, keeping them ahead of other groups by a wide margin. A prior March-May 2026 comparison had already placed The Gentlemen ahead of Qilin, showing that leadership at the top of the ransomware ecosystem is still shifting.

TeamPCP ShadowRay 2.0 and TA-NATALSTATUS campaigns

Campaign

Updated: 07.08.2026 09:50 · First: 07.08.2026 09:50 · 📰 1 src / 1 articles · H score: 36

The TeamPCP campaign lineage now ties together ShadowRay 2.0/IronErn and TA-NATALSTATUS, showing a multi-year operation that abused AI infrastructure and Redis servers for botnet and miner deployment. The activity spans 2020-2026 and evolved from internet-facing compromise into broader cloud-native and software supply chain targeting. That continuity points to a persistent operator ecosystem that repeatedly reused overlapping domains, staging paths, backend infrastructure, and tradecraft across campaigns.