Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:40 24/08/2026 UTC
Last updated: 05:49 24/08/2026 UTC

Latest updates

Browse →

MiniOrange SAML 2.0 Single Sign On plugin for WordPress authentication bypass flaws (multiple vulnerabilities)

Vulnerability

Updated: 24.08.2026 22:26 · First: 24.08.2026 22:26 · 📰 1 src / 1 articles · H score: 33

miniOrange SAML 2.0 Single Sign On plugin for WordPress has two authentication bypass vulnerabilities that are being actively exploited and can be chained to let attackers log in as administrators on affected sites. The flaws are tracked as CVE-2026-61979 and CVE-2026-15981, and a public PoC exploit increases the risk of wider abuse.

ShinyHunters company[.]claims impersonation campaign

Campaign

Updated: 24.08.2026 18:17 · First: 24.08.2026 18:17 · 📰 1 src / 1 articles · H score: 29

ShinyHunters is running a widespread impersonation campaign that uses company[.]claims domains to spoof help desks and IT teams, creating a repeatable credential-theft risk for targeted organizations. The operation pairs vishing with fake SSO pages and lookalike domains to capture login details. The pattern shows a broad, reusable social-engineering playbook rather than a single isolated lure.

Fake Codex download campaign using Google Sites and ClickFix

Campaign

Updated: 24.08.2026 18:00 · First: 24.08.2026 18:00 · 📰 1 src / 1 articles · H score: 35

The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The fake portal impersonates an OpenAI Codex download page and steers victims into opening Terminal and pasting a command. That command decodes a URL, fetches a shell-script loader, and ends with a Mach-O payload. The delivery chain also overlaps with Atomic macOS Stealer (AMOS) techniques.

Modu-ui Changup startup audition platform data leak via exposed API key

Data Leak

Updated: 24.08.2026 17:00 · First: 24.08.2026 17:00 · 📰 1 src / 1 articles · H score: 28

A Modu-ui Changup data leak exposed email addresses, evaluation comments, and startup idea summaries for about 5,000 successful applicants. The exposure mattered because an encryption key was found in the API, allowing encrypted records to be disclosed. The leak involved a government-backed startup audition platform in South Korea.

Ministry of SMEs and Startups (MSS) announced that personal information and startup idea summaries had been leaked and launched a detailed investigation with partner agencies for

Public Sector Action

Updated: 24.08.2026 17:00 · First: 24.08.2026 17:00 · 📰 1 src / 1 articles · H score: 26

South Korea’s Ministry of SMEs and Startups announced a personal-information leak and opened a joint investigation, escalating the official response to a breach affecting applicants on a government-backed startup platform. The inquiry involves the National Intelligence Service, the Cyber Security Center, and the National Police Agency. The response centers on Modu-ui Changup (모두의창업), which supports a nationwide startup audition program and holds applicants’ names, email addresses, and startup ideas.

Keycloak password-reset account takeover flaw (CVE-2026-18963)

Vulnerability

Updated: 24.08.2026 14:56 · First: 24.08.2026 14:56 · 📰 1 src / 1 articles · H score: 31

Patches are available for CVE-2026-18963 in Keycloak, closing a critical password-reset flaw that could let an unauthenticated remote attacker seize any user account, including administrative accounts. The weakness is an improper state validation bug in the reset-credentials flow, where a crafted request can jump straight to password update without the normal email action token. Fixed builds are Keycloak 26.7.2 and Red Hat build of Keycloak 26.4.15 / 26.6.6, with a temporary workaround to disable Forgot password.

COOLCLIENT updated backdoor deploying Msagent.sys

Malware Activity

Updated: 24.08.2026 14:51 · First: 24.08.2026 14:51 · 📰 1 src / 1 articles · H score: 23

The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is tied to Mustang Panda and was observed in operations spanning Myanmar, Mongolia, Pakistan, and Russia. The malware's expanded kernel-mode layer makes inspection and remediation harder while preserving its backdoor functionality.

Operation QUICSILVER Myanmar espionage campaign

Campaign

Updated: 24.08.2026 14:51 · First: 24.08.2026 14:51 · 📰 1 src / 1 articles · H score: 32

The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that deliver the QUICAgent backdoor. The activity was first observed in April 2026 and later resurfaced with related artifacts in June and July 2026. The multi-stage chain combines a malicious LNK, ftp.exe abuse, and staged payload reconstruction, increasing the chance of stealthy compromise.

Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)

Vulnerability

Updated: 20.08.2026 12:46 · First: 20.08.2026 12:46 · 📰 3 src / 4 articles · H score: 40

CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is now actively exploited, giving attackers unauthenticated remote code execution against exposed servers. The flaw is a command injection issue in the SNMP monitoring component when SNMP notifications are enabled. Zimbra 10.1.20 was released on July 20 to patch the vulnerability, and exposed deployments remain a live target.

Microsoft Windows 11 gaming disruption after KB5121003

Service Disruption

Updated: 21.08.2026 17:54 · First: 21.08.2026 17:54 · 📰 1 src / 2 articles · H score: 0

The Windows 11 gaming disruption is causing crashes, launch failures, freezes, and restarts on affected PCs, and Microsoft is investigating the problem. The issue affects Windows 11 24H2 and 25H2 systems after KB5121003 and later updates. Early findings point to RGB lighting devices whose drivers or components may trigger the breakage when certain games start. Embark Studios has shared a temporary inpoutx64.sys workaround while Microsoft works on an official fix.

British power plant hit by network compromise

Incident

Updated: 24.08.2026 12:22 · First: 24.08.2026 12:22 · 📰 1 src / 1 articles · H score: 11

A British power plant suffered a cyberattack that shut it down for four days in July 2026, disrupting energy operations. The event was later disclosed on August 22, 2026, with limited detail from official channels including the NCSC. The incident shows that even a relatively small UK energy facility can face multi-day operational disruption from a hostile intrusion.

Iran-affiliated cyber campaign targeting the US, Israel, GCC, and Europe

Campaign

Updated: 24.08.2026 12:22 · First: 24.08.2026 12:22 · 📰 1 src / 1 articles · H score: 42

Iran-affiliated cyber groups are running a multi-region campaign that has targeted the US, Israel, the GCC, and Europe since the outbreak of the war with the US / Israel. The activity spans water, critical infrastructure, military, government, energy, and healthcare sectors, and it has now reached Britain. The breadth of the target set points to a sustained adversary operation rather than a single isolated intrusion.

Unnamed UK power plant hit by network compromise

Incident

Updated: 24.08.2026 12:01 · First: 24.08.2026 12:01 · 📰 1 src / 1 articles · H score: 10

An unnamed UK power plant was disabled by Iranian hackers for four days, disrupting operations at a critical infrastructure site. The outage had little impact on the wider power supply because the facility was relatively small, but it still confirmed a successful cyber compromise. The report linked the attack to a broader operation affecting US water plants, adding concern around UK CNI resilience.

UAT-10147 global web-server intrusion campaign

Campaign

Updated: 24.08.2026 11:08 · First: 24.08.2026 11:08 · 📰 1 src / 1 articles · H score: 49

The UAT-10147 campaign is actively targeting Windows and Linux web servers worldwide, using publicly disclosed vulnerabilities to gain initial access and maintain persistence across multiple sectors. The activity raises risk for organizations in education, media, technology, and gaming, with observed focus across Brazil, Bolivia, China, Canada, and Vietnam. Operators are pairing AI-assisted tooling with exploit frameworks and post-exploitation implants to scale intrusion and data-theft operations.

SPECTRE cross-platform backdoor with Linux rootkit

Malware Activity

Updated: 24.08.2026 11:08 · First: 24.08.2026 11:08 · 📰 1 src / 1 articles · H score: 35

The SPECTRE malware activity adds a cross-platform backdoor and kernel-level EDR bypass, giving operators persistent control over infected Windows and Linux hosts. Talos says the implant also supports HTTPS C2, credential theft, and anti-analysis protections, while the Linux variant loads a Specter rootkit. The first observed use dates to April 2026, showing a recently emerged toolset built for stealth and durable access.

DOJ TikTok child-privacy settlement

Regulatory/Legal Action

Updated: 22.08.2026 17:32 · First: 22.08.2026 17:32 · 📰 2 src / 2 articles · H score: 32

TikTok agreed to a $400 million settlement with the U.S. Department of Justice over a child-privacy lawsuit, resolving major U.S. legal exposure under COPPA. The deal includes $300 million immediately and $100 million after an order vacates a prior consent decree tied to Musical.ly. The resolution closes allegations that TikTok let children under 13 create accounts and mishandled data in Kids Mode.

MarlboroMan ecosystem shift changes threat-actor operations

Threat Actor Meta

Updated: 21.08.2026 21:53 · First: 21.08.2026 21:53 · 📰 1 src / 1 articles · H score: 32

MarlboroMan publicly marketed RedC2 4.0 as a cross-platform C2 framework, widening access to evasion-focused intrusion tooling across Windows, macOS, and Linux. The offering packages surveillance, credential theft, payload loading, and mass-operation functions into a purchasable underground product. Its Red Agent layer adds LLM-driven command execution, reducing operator effort and increasing task speed. The result is a more commercialized and scalable offensive-tool ecosystem.

Trojanized npm packages deliver RedC2 4.0 Linux implant

Malware Activity

Updated: 21.08.2026 21:53 · First: 21.08.2026 21:53 · 📰 1 src / 1 articles · H score: 31

Trojanized npm packages are now delivering the RedC2 4.0 Linux implant through a supply-chain execution path, turning a routine package import into remote malware deployment. The payload runs as soon as the module loads, so a single transitive dependency can trigger compromise without any install hook or user action. The package set also supports credential theft, persistence, discovery, and command-and-control tasking. The activity expands the reach of an AI-assisted C2 framework across Windows, Linux, and macOS.

SynkLoader Microsoft Teams help-desk phishing campaign

Campaign

Updated: 21.08.2026 21:01 · First: 21.08.2026 21:01 · 📰 1 src / 1 articles · H score: 35

The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open corporate environments from infected devices. The malware was first compiled and distributed around July 28, 2026, and it combines fake login prompts with access modules for reverse proxying, remote shell, and VNC control. The operation is aimed at corporate users and is designed to collect passwords, expand internal access, and support follow-on intrusion activity. The module mix and Active Directory profiling suggest a campaign built for deeper post-compromise operations, not just a single credential grab.

SynkLoader malware distribution via Microsoft Teams phishing

Malware Activity

Updated: 21.08.2026 21:01 · First: 21.08.2026 21:01 · 📰 1 src / 1 articles · H score: 26

The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access and internal-network reach on infected devices.

AWS access keys publicly exposed and still valid

Data Leak

Updated: 21.08.2026 18:55 · First: 21.08.2026 18:55 · 📰 2 src / 2 articles · H score: 33

More than 9,300 AWS access keys exposed in public sources between August 2022 and August 2026 remained active and valid, creating a live risk of cloud account takeover. The exposed set included company-linked keys, AWS root keys, and AdministratorAccess credentials. Working keys could let attackers access data, change infrastructure, create persistent admin access, or deploy cryptominers.

Microsoft Defender BTR.sys reverse engineering shows a signed boot-time driver can be used for kernel-level file and registry operations

Technical Analysis

Updated: 21.08.2026 18:52 · First: 21.08.2026 18:52 · 📰 1 src / 1 articles · H score: 27

BTR.sys has been shown to function as a kernel-level file and registry operation primitive on Windows 7 through Windows 11 25H2, creating a new hardening and detection problem for Microsoft Defender deployments. The proof-of-concept BTR_CLI pulls the embedded driver from MpEngine.dll and submits a valid encrypted transaction to trigger boot-time operations. The technique does not require a software flaw or an external driver, but it does require administrator access and SeLoadDriverPrivilege. Researchers reported no evidence of real-world abuse and published Sysmon and Windows event patterns for defenders.

DoFun Android head unit malware spread through built-in updaters

Malware Activity

Updated: 21.08.2026 18:41 · First: 21.08.2026 18:41 · 📰 2 src / 2 articles · H score: 31

Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The campaign, attributed to MoYu and linked by Kaspersky to the broader BADBOX ecosystem, installs a hidden payload that reports device data, downloads additional modules, and is used for proxy botnet operations and ad fraud/click fraud. Kaspersky said the malware does not interfere with driving or critical vehicle control systems, and it notified DoFun, which said it resolved the problem.

MoYu Group campaign expands across multiple victims

Campaign

Updated: 21.08.2026 18:41 · First: 21.08.2026 18:41 · 📰 2 src / 2 articles · H score: 43

Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, with the activity attributed to MoYu and linked to the broader BADBOX ecosystem. The malware chain uses a C2 server and a second-stage loader to install payloads, then turns compromised devices into proxy botnet nodes and supports ad fraud/click fraud. Kaspersky says the malware does not affect driving or critical vehicle controls, and the campaign is described as the first documented infection chain built specifically for the targeted car head unit.

Arrayref maintainer account hit by network compromise

Incident

Updated: 20.08.2026 20:53 · First: 20.08.2026 20:53 · 📰 3 src / 3 articles · H score: 33

The arrayref maintainer account was compromised, and malicious crate releases on crates.io executed during compilation on developers’ systems, creating a supply-chain intrusion risk. The same account also poisoned append-only-vec and internment within a 23-minute window, widening exposure across widely used Rust packages. The fake dependency proc-macro1 used a `build.rs` script and platform-specific payloads to run on Linux, Windows, and macOS systems. The payload was built to collect host data and browser credentials, making the compromise a direct theft and persistence risk for developers.

CISA KEV patch directive for TrueConf Server flaws

Public Sector Action

Updated: 21.08.2026 15:25 · First: 21.08.2026 15:25 · 📰 1 src / 1 articles · H score: 37

CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV catalog and ordered FCEB agencies to secure TrueConf Server within two weeks, forcing rapid federal response to actively exploited vulnerabilities. The affected product is a self-hosted secure messaging and video-conferencing platform that runs inside an organization's LAN, so exposure can reach internal networks. The directive addresses flaws that can enable unauthenticated script execution and remote code execution.

Agent Tesla v4 infostealer with emoji obfuscation and BEC delivery

Malware Activity

Updated: 21.08.2026 15:00 · First: 21.08.2026 15:00 · 📰 1 src / 1 articles · H score: 29

The Agent Tesla v4 infostealer is now being delivered through a BEC lure that targets finance departments and can steal credentials from more than 40 applications. The sample adds Unicode emoji obfuscation, ConfuserEx, and DonutLoader injection to make detection harder. It also exfiltrates stolen data to attacker-controlled infrastructure within seconds, increasing the chance of rapid account compromise.

FTP-banner dead-drop resolver malware delivery campaign

Campaign

Updated: 21.08.2026 14:00 · First: 21.08.2026 14:00 · 📰 1 src / 1 articles · H score: 39

A campaign is using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, creating a new command-delivery path that can bypass standard web-service monitoring. The operation has been weaponized since early July 2026 and was still active with new infrastructure seen in August 2026. It starts with ZIP archives that trigger a .LNK infection chain, and researchers assess phishing as the likely initial access route. The payloads provide remote access, screen capture, file transfer, and credential-theft capabilities.

E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers

Malware Activity

Updated: 21.08.2026 14:00 · First: 21.08.2026 14:00 · 📰 1 src / 1 articles · H score: 29

New Windows RAT activity has been identified using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, increasing risk from remote command execution, screenshot capture, and credential theft. The activity has been operational since early July 2026 and remained active into August 2026, showing that the delivery method is still in use. The infection chain relies on .LNK-based execution and likely phishing to start the compromise. The two malware families use different C2 and execution paths, but both aim to establish durable remote access on victim systems.

SickKids employee and applicant data exposure

Data Leak

Updated: 21.08.2026 13:10 · First: 21.08.2026 13:10 · 📰 1 src / 1 articles · H score: 70

A SickKids cybersecurity incident exposed personal information for current and former employees, Boomerang and SickKids Foundation staff, and job applicants, creating identity-theft and social-engineering risk. The hospital says the exposure came from a third-party software flaw and that clinical systems and patient records were untouched. The public Careers website was temporarily taken offline and later restored. Individuals identified as affected will be notified directly, and SickKids is offering 24 months of credit monitoring and identity protection.