Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 18:49 06/08/2026 UTC
  • Law Enforcement H score 81 Connor Riley Moucka guilty plea in Snowflake data-theft case Connor Riley Moucka pleaded guilty in the Snowflake data-theft and extortion case, advancing the accountability for credential-and-no-MFA intrusions impacting at least 165 organizations.
  • Vulnerability H score 49 Apache Tomcat Oracle SQL injection flaw under active exploitation Huntress reported the Tomcat Oracle SQL injection operators embedded the khunt toolkit inside Oracle as schema objects, indicating a stealthy post-exploitation method under active exploitation.
  • Security Patch Release H score 48 N-able security patch release for CVE-2026-18576 N-able issued guidance that CVE-2026-18576 in N-central is actively exploited, pushing customers to install the emergency hotfix to stop admin-account hijacking.
  • Data Leak H score 58 N8n API tokens exposed in public GitHub commits Researchers found n8n API tokens committed to public GitHub remained valid on 321 instances, showing how exposed secrets can directly enable workflow and credential compromise without exploiting a vulnerability.
  • Security Patch Release H score 65 Gitea security patch release for CVE-2026-59774 Gitea’s 1.27.1 release closes CVE-2026-59774 and CVE-2026-60004, tightening defenses for self-hosted deployments where critical file-read exposure and RCE risk remain.
  • Campaign H score 42 QuickFox Windows supply-chain targeting campaign The QuickFox supply-chain effort uses a trojanized Windows installer to deliver a selective backdoor path via lookalike domains and DLL side-loading, updating risk for trusted VPN software users.
Last updated: 19:49 06/08/2026 UTC

Latest updates

Browse →

Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach

Incident

Updated: 06.08.2026 21:22 · First: 06.08.2026 21:22 · 📰 1 src / 1 articles · H score: 26

Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 accounts. The intrusion was detected after unusual activity appeared on July 28, and BIT later found that several login credentials had been compromised on July 31. BIT blocked external SharePoint access, patched the suspected vulnerabilities, and reset affected passwords. The agency said it has found no evidence of data theft beyond the compromised credentials.

AMD Zen 1 through Zen 4 Safe RET Interrupt security flaw

Vulnerability

Updated: 06.08.2026 19:17 · First: 06.08.2026 19:17 · 📰 2 src / 2 articles · H score: 37

Safe RET Interrupt Vulnerability affects Zen 1 through Zen 4 processors, where a local attacker can time an interrupt injection to weaken Safe RET and expose kernel memory. Researchers from MIT CSAIL described the attack on February 5 after showing a Linux timing window between branch-predictor sanitization and kernel use. On August 6, AMD issued AMD-SB-7061 and said the issue appears tied to the Linux implementation of Safe RET, with potential information disclosure on affected systems.

INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux

Technical Analysis

Updated: 06.08.2026 19:17 · First: 06.08.2026 19:17 · 📰 2 src / 2 articles · H score: 24

MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to schedule a hardware interrupt during kernel execution. The technique can re-poison branch predictors after neutralization and leak kernel memory on AMD and Intel systems; on an AMD Zen 2 host running Linux version 6.14.0-37-generic, it extracted /etc/shadow contents with 91.97% accuracy at 5.47 bytes/s and succeeded in 5 of 10 attempts, averaging 18 minutes per attempt. On August 6, AMD-SB-7061 named Zen 1 through Zen 4 as affected by the Safe RET Interrupt Vulnerability, and AMD warned that a precise interrupt could weaken Safe RET and lead to information disclosure. The researchers also tied the exploit path to interrupt-handler poisoning and compared the behavior with prior Inception-related RSB pollution techniques.

KVM/x86 shadow MMU stale-root check ordering flaw (CVE-2026-64561)

Vulnerability

Updated: 06.08.2026 20:58 · First: 06.08.2026 20:58 · 📰 1 src / 1 articles · H score: 19

CVE-2026-64561 discloses a Linux kernel weakness in KVM/x86 shadow MMU that can let a privileged L1 guest VM escape KVM isolation and execute code on the host. The flaw affects systems where nested virtualization is exposed to untrusted guests. A public proof-of-concept shows a path to host root execution, but the issue is not described as exploited in the wild. The upstream fix is merged, and unpatched hosts need a fixed stable kernel or vendor backport.

Cisco security patch release for CVE-2026-20303

Security Patch Release

Updated: 06.08.2026 20:13 · First: 06.08.2026 20:13 · 📰 1 src / 1 articles · H score: 43

Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. The patch bundle closes high-severity flaws that could expose deployed network management systems to validation, access-control, link-resolution, and sensitive-data risks. Cisco said the issues were found during internal security testing and are not known to be actively exploited.

Khunt Oracle database post-exploitation toolkit analysis

Technical Analysis

Updated: 06.08.2026 18:30 · First: 06.08.2026 18:30 · 📰 1 src / 1 articles · H score: 22

Researchers found khunt compiled and stored as Oracle schema objects, turning the database into a stealthy platform for command execution and credential dumping on the underlying Windows server. The entry path used SQL injection in a public-facing Java application on Apache Tomcat, then leveraged Oracle's embedded Java runtime to compile attacker-supplied code inside the database. The placement inside database objects reduced visibility for conventional endpoint tooling that focuses on files, binaries, and processes.

Rising physical wrench attacks on crypto holders in H1 2026

Trend

Updated: 06.08.2026 15:00 · First: 06.08.2026 15:00 · 📰 1 src / 1 articles · H score: 33

Physical wrench attacks on crypto holders are rising, pushing losses to $30m in the first half of 2026. The broader tally reaches $107m when attempted extractions are included, showing attackers are using in-person coercion to force transfers. Home invasions now make up 37% of incidents, up from 26% in 2023, while kidnappings remain a major share of losses. The pattern raises direct personal safety risk for high-value holders and their families, especially in France.

Apple iCloud Private Relay proxy bypass real IP leak security flaw

Vulnerability

Updated: 06.08.2026 14:33 · First: 06.08.2026 14:33 · 📰 1 src / 1 articles · H score: 26

Researchers disclosed a WebKit proxy-bypass vulnerability in Apple iCloud Private Relay that can expose a user's real IP address. The flaw affects Safari, other WebKit-based browsers, and devices on iOS, iPadOS, and macOS, weakening the privacy protection the relay is meant to provide. The bypass is triggered by DNS prefetching, WebAuthn Related Origin Requests, and WebTransport, which can send traffic directly from the device instead of through the configured proxy. A VPN can mitigate the leak, and Apple is investigating the issue.

Hunt AI deep links for memory-poisoning prompts

Defensive Guidance

Updated: 06.08.2026 14:30 · First: 06.08.2026 14:30 · 📰 1 src / 1 articles · H score: 17

Microsoft Security issued hunting guidance for AI Recommendation Poisoning, telling defenders to inspect ChatGPT, Claude, Grok, and Gemini deep links that can silently write "trusted source" instructions into persistent LLM memory. The guidance targets corporate AI users and reduces exposure to unauthorized memory poisoning. It focuses on URLs with query strings that contain prompt-injection terms such as "remember" or "trusted source". Security teams are told to treat these links like credential-harvesting lures.

AI Recommendation Poisoning via hidden Ask AI deep-link prompt injection

Technical Analysis

Updated: 06.08.2026 14:30 · First: 06.08.2026 14:30 · 📰 1 src / 1 articles · H score: 16

AI Recommendation Poisoning is turning ordinary Ask AI buttons into hidden prompt-injection channels that can silently rewrite ChatGPT, Claude, Gemini, and Grok memory. The technique matters because a single click can plant a persistent instruction that biases future answers toward a vendor or domain without malware, stolen credentials, or a zero-day. Production deployments were observed, and the behavior was catalogued in February 2026 as a repeatable memory-poisoning pattern across commercial sites.

Apache Tomcat Oracle SQL injection flaw under active exploitation

Vulnerability

Updated: 05.08.2026 22:55 · First: 05.08.2026 22:55 · 📰 2 src / 2 articles · H score: 49

SQL injection in a public-facing Java application running Apache Tomcat let attackers reach an Oracle database and load the khunt toolkit as database-stored Java objects rather than as files on disk. Huntress tied the activity to July 27, 2026, after credential-theft detections fired and requests were traced to 178.162.151[.]229. The attackers used KhuntCmd to run cmd.exe /c whoami and confirmed SYSTEM-level access on the underlying Windows server. They also used the toolkit to browse files, read hashes, and stage the SAM, SECURITY, and SYSTEM registry hives, while Huntress did not confirm exfiltration.

Zbtlink router firmware unauthenticated root-shell backdoor ENDLESSDOORS security flaw

Vulnerability

Updated: 06.08.2026 11:05 · First: 06.08.2026 11:05 · 📰 1 src / 1 articles · H score: 16

A factory-shipped backdoor in Zbtlink router firmware exposes at least 20 router models to unauthenticated root shell access. The implant, named ENDLESSDOORS, is present in firmware images spanning more than 2 years and can let a remote operator take over affected routers. Zbtlink has pulled impacted downloads and is developing patched firmware, while defenders are told to look for the implant's files and block its C2 traffic.

TeamCity security patch release for CVE-2026-63077

Security Patch Release

Updated: 28.07.2026 11:11 · First: 28.07.2026 11:11 · 📰 2 src / 3 articles · H score: 53

JetBrains released TeamCity On-Premises fixes for CVE-2026-63077, a critical unauthenticated remote code execution issue, through 2025.11.7, 2026.1.3, and a security patch plugin for 2017.1+.

TeamCity On-Premises unauthenticated RCE (CVE-2026-63077)

Vulnerability

Updated: 28.07.2026 11:11 · First: 28.07.2026 11:11 · 📰 2 src / 3 articles · H score: 46

JetBrains has patched CVE-2026-63077, a critical unauthenticated RCE flaw affecting all TeamCity On-Premises versions. The issue can let an attacker with HTTP(S) access bypass authentication and run arbitrary operating system commands as the TeamCity server process. Fixes are available in 2025.11.7 and 2026.1.3, and a patch plugin covers 2017.1+ when immediate upgrades are not possible.

Maksim Silnikau sentenced to 16 years for Ransom Cartel ransomware attacks

Law Enforcement

Updated: 06.08.2026 02:00 · First: 06.08.2026 02:00 · 📰 2 src / 2 articles · H score: 40

Maksim Silnikau was sentenced to 16 years in prison in Alexandria, Virginia for creating and running Ransom Cartel, a ransomware-as-a-service operation he built in 2021. The Justice Department says the group attacked at least 18 companies between 2021 and 2023, while Silnikau used stolen credentials, affiliate tooling, and cryptocurrency mixers to manage intrusions and ransom payments. The case also includes reported losses of more than $6.7 million, attempted extortion of at least $5.2 million, and ransom payments of $125,000 and $300,000 tied to separate firms. The prosecution remains partially open because a New Jersey case tied to Silnikau is unresolved.

At least 165 organizations data exposed after Snowflake breach

Data Leak

Updated: 06.08.2026 00:53 · First: 06.08.2026 00:53 · 📰 1 src / 1 articles · H score: 80

Snowflake tenant environments were breached and terabytes of data were stolen from at least 165 organizations, exposing sensitive records at scale. The stolen material was later used in extortion and offered for sale, raising the risk of further disclosure and downstream abuse. The affected population exceeded 100 million individuals.

Connor Riley Moucka guilty plea in Snowflake data-theft case

Law Enforcement

Updated: 06.08.2026 00:53 · First: 06.08.2026 00:53 · 📰 4 src / 4 articles · H score: 81

Connor Riley Moucka pleaded guilty in US court on August 5, 2026 in the Snowflake data-theft and extortion case. Prosecutors said the scheme used stolen login credentials and no MFA to access at least 165 organizations between February and October 2024. The case involved the theft of billions of sensitive records, more than $9.5 million in victim-company losses, and a scheduled October 27 sentencing.

Samsung Members/Samsung Account/Bixby app-handoff chain (multiple vulnerabilities)

Vulnerability

Updated: 05.08.2026 22:40 · First: 05.08.2026 22:40 · 📰 1 src / 1 articles · H score: 28

A Samsung Members and Samsung Account app-handoff vulnerability chain involving CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 enabled remote system-level compromise on Galaxy devices. The chain used Bixby entry-point abuse and a malicious link delivered through ads or messaging apps to push a target through multiple app handoffs, with potential remote code execution after system privileges were obtained. Samsung had patched Members in November 2025 and Account in December 2025, reducing exposure for updated devices.

A coordinated network of ChatGPT accounts likely originating from Southeast Asia campaign activity escalates

Campaign

Updated: 05.08.2026 21:33 · First: 05.08.2026 21:33 · 📰 1 src / 1 articles · H score: 29

OpenAI disrupted a Poipet-linked scam campaign that used ChatGPT to scale fraud across investment, romance, gambling, and law-enforcement impersonation schemes. The disruption matters because the network used AI to generate fake personas, translate lure messages, and produce promotional material for what appeared to be a hundreds-of-targets operation.

Organized criminal scam groups' AI-assisted multi-scam operating model

Threat Actor Meta

Updated: 05.08.2026 21:33 · First: 05.08.2026 21:33 · 📰 1 src / 1 articles · H score: 27

Organized criminal scam groups are increasingly using ChatGPT to run multiple fraud lines at once, widening their reach across investment, romance, gambling, and law-enforcement impersonation scams.

COLDCARD wallet random number generation security flaw

Vulnerability

Updated: 05.08.2026 20:49 · First: 05.08.2026 20:49 · 📰 1 src / 1 articles · H score: 42

A random number generation flaw in multiple COLDCARD models and firmware versions has been tied to theft of about 1,367 Bitcoin from 4,585 addresses, putting affected cold-storage wallet users at risk. The flaw is being used in the wild, and attackers are leveraging the theft to fuel a follow-on phishing campaign.

ConnectWise ScreenConnect remote access installation chain

Malware Activity

Updated: 05.08.2026 20:49 · First: 05.08.2026 20:49 · 📰 1 src / 1 articles · H score: 29

A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The payload is paired with a decoy docusign.exe and staged to look like a legitimate diagnostic workflow. Once installed, the remote-management tool connects to activeretirementrelocation[.]com, creating a foothold for data theft, cryptocurrency theft, or additional malware.

COLDCARD ScreenConnect phishing campaign

Campaign

Updated: 05.08.2026 20:49 · First: 05.08.2026 20:49 · 📰 1 src / 1 articles · H score: 39

A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device takeover and cryptocurrency theft. The operation impersonates COLDCARD with spoofed emails and a lookalike website, then pressures users through live chat to approve the installation. It is tied to a broader trust exploit around the recently disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft.

CISA orders federal mitigation for Langflow, N-central, and Tomcat

Public Sector Action

Updated: 05.08.2026 18:51 · First: 05.08.2026 18:51 · 📰 1 src / 1 articles · H score: 36

CISA ordered federal agencies to apply available mitigations for IBM Langflow, N-central, and Apache Tomcat, forcing urgent remediation of actively exploited vulnerabilities across government systems. The directive follows confirmed exploitation of CVE-2026-9198, CVE-2026-18576, and CVE-2026-34486 and added the flaws to CISA’s KEV catalog. Agencies were told to complete mitigation by the end of Friday, July 7th.

N-able security patch release for CVE-2026-18576

Security Patch Release

Updated: 05.08.2026 18:51 · First: 05.08.2026 18:51 · 📰 1 src / 1 articles · H score: 48

N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urged customers to install the fix on all versions before 2026.3 after the issue was reported as actively exploited. The out-of-band update addresses a weakness that had already been patched once but remained usable by threat actors.

Poison Claude-Ecomagent.in alliance reshapes ransomware ecosystem operations

Threat Actor Meta

Updated: 05.08.2026 18:36 · First: 05.08.2026 18:36 · 📰 1 src / 1 articles · H score: 22

Poison Claude and similar gray-market services are expanding an underground market for discounted frontier AI access, raising prompt visibility, privacy, and abuse risk for customers. Operators route requests through pooled accounts and charge a fraction of official token prices, often using AWS Bedrock bonus credits to subsidize access. The services also mask infrastructure behind Cloudflare and accept cryptocurrency. Researchers observed the ecosystem across underground cybercrime forums and messaging platforms.

Paperclip security patch release for CVE-2026-41679

Security Patch Release

Updated: 05.08.2026 17:30 · First: 05.08.2026 17:30 · 📰 2 src / 2 articles · H score: 45

Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The release split remediation across authenticated deployments and local mode, with fixes covering CVE-2026-41679 and the DNS rebinding flaw. The patch set reduced risk for both server and developer-machine execution paths.

Google Blogger lockout after malware false positive

Service Disruption

Updated: 05.08.2026 17:59 · First: 05.08.2026 17:59 · 📰 1 src / 1 articles · H score: 1

Google Blogger locked hundreds of blogs, blocking owners from dashboard access and risking site deletion after an automated false positive flagged them for malware-policy violations. The disruption began on August 4 and affected legitimate publishers whose blogs did not host malware or malicious scripts. Some sites were deleted from the platform, while others were restored only after appeal. The event left blog management and access controls unstable for affected publishers.

Paperclip RCE and auth-bypass flaws multiple vulnerabilities security flaw (CVE-2026-41679)

Vulnerability

Updated: 05.08.2026 17:30 · First: 05.08.2026 17:30 · 📰 2 src / 2 articles · H score: 41

Paperclip's three vulnerabilities affected authenticated deployments and local development mode, enabling command execution on network servers and a developer's machine through malicious agent imports and DNS rebinding. The most severe issue, CVE-2026-41679 at CVSS 10.0, could be triggered without a pre-existing account or victim interaction in certain network-accessible deployments. The package also included GHSA-xfqj-r5qw-8g4j at CVSS 8.3 for missing API access checks and GHSA-x8hx-rhr2-9rf7 at CVSS 9.6 for a browser-driven localhost attack. Paperclip fixed the main import flaw in v2026.416.0, and Rapid7 released a Metasploit module while CISA/NVD classified the first issue as proof-of-concept exploitation, with no in-the-wild exploitation reported as of August 5, 2026.

HashiCorp security patch release for CVE-2026-16498

Security Patch Release

Updated: 05.08.2026 17:27 · First: 05.08.2026 17:27 · 📰 1 src / 1 articles · H score: 37

HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect shared deployments. The bugs apply to multi-user HTTP mode rather than stdio mode, and operators are told to update to 1.1.0 or later. No active exploitation or public proof-of-concept was reported, and none of the CVEs was in CISA's KEV catalog as of August 5, 2026.