Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 08:34 20/08/2026 UTC
Last updated: 09:04 20/08/2026 UTC

Latest updates

Browse →

Manic Android malware activity with offline relay exfiltration

Malware Activity

Updated: 20.08.2026 13:02 · First: 20.08.2026 13:02 · 📰 1 src / 1 articles · H score: 27

The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving even when a victim device cannot reach C2. The malware combines spyware, banking fraud, and remote control features, widening the risk of credential theft and device takeover. It also targets at least 169 apps across banking, government/eID, payment, crypto wallet, messaging, and 2FA categories.

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity

Updated: 20.08.2026 13:00 · First: 20.08.2026 13:00 · 📰 1 src / 1 articles · H score: 28

The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries. It also abuses Android Accessibility Service and wireless debugging to obtain shell access and run high-privilege ADB commands. The malware can steal device lock credentials through a screen-overlay attack, helping attackers maintain persistent access to compromised devices. Compared with the first version’s 16 banking apps, the new variant is a much broader credential-theft threat.

Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)

Vulnerability

Updated: 20.08.2026 12:46 · First: 20.08.2026 12:46 · 📰 1 src / 1 articles · H score: 33

CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is now actively exploited, giving attackers unauthenticated remote code execution against exposed servers. The flaw is a command injection issue in the SNMP monitoring component when SNMP notifications are enabled. Zimbra 10.1.20 was released on July 20 to patch the vulnerability, and exposed deployments remain a live target.

Black Hat / Def Con attendee phishing campaign with Google Doc and DocSend lures

Campaign

Updated: 20.08.2026 12:30 · First: 20.08.2026 12:30 · 📰 1 src / 1 articles · H score: 29

A persistent phishing campaign used fake post-conference outreach and trusted file-sharing lures to target cybersecurity conference attendees, creating a path to credential theft and malware execution after Black Hat / Def Con. The actor first posed as CoinDesk's VP and head of marketing on X and then sent a Google Doc with a malicious Google Apps Script sidebar. When that did not work, the actor followed up with a Dropbox DocSend-style lure that delivered a counterfeit installer with platform-specific payloads, including AMOS on macOS. The sequence shows a repeated operation designed to keep targets engaged and trick them into running code.

Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)

Vulnerability

Updated: 20.08.2026 09:04 · First: 20.08.2026 09:04 · 📰 1 src / 1 articles · H score: 33

CVE-2026-32475 in Elementor Pro lets an unauthenticated attacker bypass file-upload validation in the Forms module's File Upload field, write a PHP file into a public directory, and reach remote code execution on affected WordPress sites. The flaw affects plugin versions prior to and including 4.2.1 on sites that expose a published Elementor page with the vulnerable form field. Version 4.2.2 was released on 2026-08-19 to address the issue.

Elementor Pro 4.2.2 security update for CVE-2026-32475

Security Patch Release

Updated: 20.08.2026 09:04 · First: 20.08.2026 09:04 · 📰 1 src / 1 articles · H score: 39

Elementor Pro released version 4.2.2 to fix CVE-2026-32475, closing an unauthenticated file-upload RCE path in the WordPress plugin. The update targets the Forms module's File Upload field and removes a flaw that could let an attacker write a PHP file into a public directory. Sites still running 4.2.1 or earlier need the patch to eliminate the exposed code-execution path.

Ransom Busters rogue ransomware middleman skims payments across RaaS operations

Threat Actor Meta

Updated: 19.08.2026 23:59 · First: 19.08.2026 23:59 · 📰 1 src / 1 articles · H score: 19

Researchers identified Ransom Busters as a suspected ransomware middleman that contacts victims before attacks are public, offering decryption and data-deletion help while potentially diverting ransom payments across multiple RaaS operations. The pattern raises payment integrity and trust risks for both victims and ransomware crews by inserting a rogue affiliate into the extortion chain. Evidence ties the activity to outreach around DragonForce, Settra, and Anubis, with claimed deletion prices of $20,000-$60,000.

Ransom Busters as a rogue ransomware affiliate posing as a recovery middleman

Threat Actor Meta

Updated: 19.08.2026 23:59 · First: 19.08.2026 23:59 · 📰 1 src / 1 articles · H score: 19

Ransom Busters has emerged as a suspected rogue ransomware affiliate posing as a recovery service, creating a criminal middleman layer that can siphon ransom payments and complicate RaaS negotiations. The activity raises the risk that victims may be misled before an attack becomes public and that paying one party will not prevent data leakage by others with access. Researchers linked the behavior to overlapping tradecraft across multiple ransomware-as-a-service operations and said the actor appears to exploit its access for profit outside normal affiliate sharing.

Sakura Rental Server hit by network compromise

Incident

Updated: 19.08.2026 23:53 · First: 19.08.2026 23:53 · 📰 1 src / 1 articles · H score: 59

Sakura Rental Server confirmed a separate intrusion involving unauthorized logins to 583 accounts and malware installed on its systems, adding a distinct compromise thread to the broader Sakura Internet security event. The attack reached customer-facing systems and client data. The affected credentials were invalidated and the malware was removed after discovery.

Sakura Internet customer data exposed after Sakura Internet breach

Data Leak

Updated: 19.08.2026 23:53 · First: 19.08.2026 23:53 · 📰 1 src / 1 articles · H score: 61

Sakura Internet disclosed that hackers accessed its sales management system, exposing customer contract and membership information tied to up to 1,360,563 member accounts. The company is individually notifying affected customers and has informed regulators about the exposure. The exact number of impacted accounts is still being determined, so the scope remains under investigation.

Cloudflare Workers remote Spectre leakage security flaw

Vulnerability

Updated: 19.08.2026 22:02 · First: 19.08.2026 22:02 · 📰 1 src / 1 articles · H score: 32

Researchers disclosed a remote Spectre weakness in Cloudflare Workers that leaked a JWT from a co-located Worker in production, exposing a cross-tenant memory-read risk. The demonstrated leakage reached 12 bits per second, far above the earlier 2021 result, and Cloudflare said the issue was mitigated in production. The attack did not require a V8 sandbox escape or native code execution, but it showed that shared-process isolation could still permit sensitive data leakage.

Operation CameraSwarm exploitation of Dahua authentication-bypass flaws

Case

Updated: 19.08.2026 21:09 · First: 19.08.2026 14:34 · 📰 0 src / 3 articles

Attackers used CVE-2021-33044 and CVE-2021-33045 in Operation CameraSwarm to compromise more than 14,530 Dahua devices between June 17 and July 22, 2026, combining the authentication-bypass flaws with credential attacks and a P2P relay path. Hunt.io said the operation left 1,923 cameras configured with a persistent account and reached 283 cameras through the P2P route, with confirmed compromises concentrated in Ukraine and Russia. CISA still lists both Dahua flaws in the Known Exploited Vulnerabilities catalog and directs operators to apply vendor mitigations or discontinue use if mitigations are unavailable. Dahua says fixed firmware is available, so the current picture is confirmed exploitation followed by ongoing patch-and-remove pressure for exposed camera fleets.

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign

Updated: 19.08.2026 20:50 · First: 19.08.2026 20:50 · 📰 1 src / 1 articles · H score: 24

The ongoing AI-assisted campaign against Siemens S7 Series PLCs is exposing U.S. critical infrastructure to disruption, data theft, equipment damage, and downtime. U.S. agencies say the activity is active and relies on AI-generated Python exploitation scripts plus internet scanning to find exposed devices. The operators are using Censys and ZoomEye to locate targets and then abusing weak authentication, outdated software, and high-severity flaws. The campaign spans sectors such as Energy, Water and Wastewater Systems, and Critical Manufacturing.

DoJ charges Mabna Institute-linked Iranian hackers

Law Enforcement

Updated: 19.08.2026 18:56 · First: 19.08.2026 18:56 · 📰 1 src / 1 articles · H score: 68

The U.S. Justice Department charged 17 Iranians tied to Mabna Institute, escalating a cross-border cybercrime case centered on long-running theft of data from American organizations. The action also included rewards of up to $10 million for information leading to five of the defendants, increasing pressure on fugitives linked to the operation.

Mabna Institute campaign expands across multiple victims

Campaign

Updated: 19.08.2026 18:56 · First: 19.08.2026 18:56 · 📰 1 src / 1 articles · H score: 73

A state-sponsored campaign tied to Mabna Institute and the IRGC compromised roughly 8,000 professor accounts and enabled theft of research and proprietary data across universities, businesses, and government institutions. The operation began around 2013 and reached more than 100,000 professors worldwide. It created large-scale exposure of academic and intellectual-property material, with reported losses valued at about $3.4 billion. The same operation also included extortion activity against at least one high-profile victim.

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign

Updated: 19.08.2026 18:00 · First: 19.08.2026 18:00 · 📰 1 src / 1 articles · H score: 32

An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware distribution path and helping attackers evade endpoint defenses. The activity was observed in late July 2026 and involved repeated delivery attempts against site visitors. The operation combines social engineering, blockchain-based C2 rotation, and defense evasion into one delivery chain.

ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion

Threat Actor Meta

Updated: 19.08.2026 18:00 · First: 19.08.2026 18:00 · 📰 1 src / 1 articles · H score: 32

ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. The shift lets operators rent delivery, social engineering, and defense evasion instead of building those functions in-house, increasing the speed and scale of malicious operations.

Cruciferra loader EDR-killing delivery chain

Malware Activity

Updated: 19.08.2026 18:00 · First: 19.08.2026 18:00 · 📰 1 src / 1 articles · H score: 18

The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware delivery while reducing detection.

Grandoreiro Latin America DLL sideloading campaign

Campaign

Updated: 19.08.2026 17:00 · First: 19.08.2026 17:00 · 📰 1 src / 1 articles · H score: 32

A renewed Grandoreiro campaign is targeting Latin American users, with Mexico accounting for 40% of observed detections and increasing banking-trojan risk across the region. Attackers used DLL sideloading through the legitimate Duplicate Files Finder application to load a malicious mingwm10.dll. Telemetry from May 2026 and the last 30 days of June showed the activity remained concentrated in Latin America, with smaller clusters in Europe and North America.

Grandoreiro banking trojan DLL sideloading activity in Latin America

Malware Activity

Updated: 19.08.2026 17:00 · First: 19.08.2026 17:00 · 📰 1 src / 1 articles · H score: 20

The Grandoreiro banking trojan has resurfaced in Latin America, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to run it through legitimate software. The activity raises infection risk by abusing trusted executables to load a malicious library instead of a clearly hostile file. Acronis TRU observed the activity in May 2026, and June telemetry still showed Mexico as the largest detection source. The loader also used anti-analysis checks, encrypted strings, and delayed C2 contact until environmental checks passed.

SilkParasite RAT toolkit activity

Malware Activity

Updated: 19.08.2026 16:12 · First: 19.08.2026 16:12 · 📰 1 src / 1 articles · H score: 22

SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection exposure. The stack combines DLL sideloading, plugin-based modularity, and multiple covert C2 channels to keep operations flexible across victims. One implant uses Google Drive for tasking, while another relies on HTTP Cookie / ETag headers, underscoring a low-footprint design built for stealthy government-targeting espionage.

SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign

Campaign

Updated: 19.08.2026 16:12 · First: 19.08.2026 16:12 · 📰 1 src / 1 articles · H score: 26

The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy espionage access. The operation uses multiple RAT families and regionally tailored lures to adapt payloads to victim environments and reduce detection. Researchers assess the cluster as a China-nexus operation first discovered in late 2025.

Prevalent AI raises $22 million growth funding from Integrity Growth Partners

Industry Action

Updated: 19.08.2026 15:00 · First: 19.08.2026 15:00 · 📰 1 src / 1 articles · H score: 11

Prevalent AI raised $22 million from Integrity Growth Partners to fund US expansion and scale a cybersecurity-focused data fabric platform that helps organizations manage fragmented enterprise data.

CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)

Advisory/Mitigation

Updated: 19.08.2026 14:34 · First: 19.08.2026 14:34 · 📰 1 src / 1 articles · H score: 81

CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor mitigations or discontinue use if mitigations are unavailable. The guidance covers affected Dahua cameras and related products as of August 19, 2026, leaving exposed systems on notice for urgent remediation.

Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)

Vulnerability

Updated: 19.08.2026 14:34 · First: 19.08.2026 14:34 · 📰 2 src / 2 articles · H score: 78

CVE-2021-33044 and CVE-2021-33045 are authentication-bypass flaws in Dahua cameras and related products that let attackers bypass device identity checks during login. Hunt.io linked the flaws to Operation CameraSwarm, which compromised more than 14,530 Dahua IP cameras between June 17 and July 22, 2026 using TCP/37777 brute-forcing, cloud-relay access, and exploitation of the CVEs to install a persistent p2pwn backdoor account on 1,923 cameras. The researchers also said 283 cameras were reached through P2P and recovered 407 MB of operator data. Dahua lists fixed firmware, and CISA KEV still tracks both issues as exploited vulnerabilities.

Operation CameraSwarm campaign targeting Dahua devices

Campaign

Updated: 19.08.2026 14:34 · First: 19.08.2026 14:34 · 📰 2 src / 2 articles · H score: 70

Hunt.io disclosed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras mostly in Ukraine and Russia. The operation used TCP/37777 brute-forcing, CVE-2021-33044, CVE-2021-33045, and a cloud-relay path that relied on serial numbers and SDK credentials to reach 283 cameras behind NAT. Hunt.io also reported 1,923 cameras were configured with a persistent p2pwn account, recovered 407 MB of operator data, and said some toolkit references to CVE-2024-39943 and CVE-2025-31702 were misleading and not part of the observed attacks. Owners of affected Dahua devices were advised to check for p2pwn, disable P2P when not needed, and apply Dahua SA-2021-0130 firmware updates or later versions.

StopAndProtect multi-stage malware toolkit

Malware Activity

Updated: 19.08.2026 14:25 · First: 19.08.2026 14:25 · 📰 1 src / 1 articles · H score: 40

The StopAndProtect malware toolkit now combines encryption, document theft, screen locking, spreaders, and operator chat, increasing the impact of infections and making compromise harder to contain.

StopAndProtect hacked-WordPress cybercrime campaign

Campaign

Updated: 19.08.2026 14:25 · First: 19.08.2026 14:25 · 📰 1 src / 1 articles · H score: 49

The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal infrastructure. The operation uses ClickFix social engineering, PowerShell, and .NET downloaders/loaders to stage ransomware, credential theft, worming, and screen-locking components. By July 24, 2026, researchers associated the campaign with more than 6,000 unique IP addresses and over 700 uploaded archives from victim machines.

Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11

Security Tool/Service

Updated: 19.08.2026 14:14 · First: 19.08.2026 14:14 · 📰 1 src / 1 articles · H score: 11

Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security update. The issue caused 0xc0000005 access violation errors and interrupted quick and full scans. Microsoft delivered the remedy through Microsoft Defender Antivirus signature update version 1.457.236.0 or later and advised customers to apply the latest update or keep automatic updates enabled.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave

Updated: 12.08.2026 12:01 · First: 12.08.2026 12:01 · 📰 3 src / 5 articles · H score: 48

Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code execution on vulnerable appliances. QUIRSO said the activity began five calendar days after public disclosure, with 361 unique victim IP addresses across 47 countries and the largest clusters in Germany, the U.S., Turkey, Iran, and France. The intrusion chain included cron-abused payloads, a linuxFile WebSocket backdoor, and reverse_ssh for persistence and outbound access. The campaign also touched CVE-2026-59309 on at least one system, and the observed outcome on one infected host included Babuk-derived ransomware that encrypted files with the .babyk extension.