Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 03:19 28/08/2026 UTC
  • Case Case score 89 Carhartt public leak after ShinyHunters extortion and Databricks linkage ShinyHunters escalated the Carhartt extortion claim into a public release exposing alleged data from 12.9M+ accounts and linking it to Carhartt’s Databricks platform, materially raising fraud and identity-theft risk.
  • Data Leak H score 67 Manchester Airports Group customer booking and Wi-Fi sign-up data leak Manchester Airports Group confirmed a data leak across three UK airports involving booking and in-airport Wi‑Fi sign-up records, advancing the incident from rumor to actionable phishing and smishing risk.
  • Data Leak H score 59 TeamPCP supply-chain credential and data leak The TeamPCP-linked supply-chain incident advanced by exposing 500k credentials and at least 300GB of data via poisoned open-source code, increasing the likelihood of widespread downstream compromise.
  • Incident H score 51 ATF hit by ransomware attack ATF confirmed a Qilin ransomware breach of a standalone system in a major incident response effort, advancing containment work even as it reports no impact to eForms or the enterprise network.
  • Incident H score 48 Hugging Face hit by network compromise Hugging Face disclosed a multi-day compromise after attackers leveraged a zero-day in HDF5 handling to steal credentials from production workers, advancing the threat from intrusion to deeper infrastructure access.
  • Vulnerability H score 34 Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452) CVE-2026-8452’s addition to CISA’s KEV Catalog highlights an active Citrix NetScaler ADC/Gateway exploitation wave that can yield root-level RCE, pushing urgent remediation priorities for exposed appliances.
Last updated: 02:19 28/08/2026 UTC

Latest updates

Browse →

Artifactory token-refresh via legacy credential endpoint security flaw

Vulnerability

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 2 src / 2 articles · H score: 44

Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeover risk for affected deployments. The flaw enabled privileged access through a weak refresh path rather than normal authentication. JFrog was alerted after the abuse was uncovered.

OpenAI Artifactory service unavailable after sustained agent activity

Service Disruption

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 1 src / 1 articles · H score: 29

OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outage signaled that the service had been pushed beyond its intended operating conditions. OpenAI later rebuilt Artifactory, revoked agent credentials, and tightened access controls to restore containment.

Hugging Face hit by network compromise

Incident

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 1 src / 1 articles · H score: 48

The Hugging Face breach expanded after attackers used a zero-day in HDF5 handling to extract credentials from production workers, increasing their access inside the environment. The compromise enabled deeper infrastructure access and turned an initial intrusion into a multi-day breach. The event raised the risk of broader internal exposure and follow-on access to sensitive systems.

PaperCut NG and MF actively exploited zero-day security flaw

Vulnerability

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 1 src / 1 articles · H score: 26

PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk. The vendor has issued emergency patches and urged administrators to restrict web access to trusted IP addresses.

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 1 src / 1 articles · H score: 41

PaperCut released emergency patches for public-facing PaperCut NG/MF servers after warning that the software is under active zero-day exploitation. The patch release gives exposed customers an urgent remediation path while the company continues to recommend access restriction and other mitigation for systems that cannot be patched immediately.

PaperCut customer confirmed compromise incidents

Incident

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 1 src / 1 articles · H score: 36

PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immediate risk. PaperCut urged operators of Internet-exposed PaperCut Application Servers to restrict access to trusted IP addresses and deploy emergency patches. The company also shared indicators of compromise, including altered or missing server.log files and suspicious activity from pc-app.exe. The attacks remain under investigation, and the actor and post-compromise actions have not been disclosed.

Manchester Airports Group (MAG) hit by network compromise

Incident

Updated: 27.08.2026 19:12 · First: 27.08.2026 19:12 · 📰 1 src / 1 articles · H score: 64

Manchester Airports Group (MAG) confirmed a customer data breach that exposed travelers' records across Manchester, Stansted, and East Midlands airports. The stolen data included Wi‑Fi sign-ups and booking-related details, but payment details were not accessed. MAG said it contained the intrusion and temporarily suspended its Manage My Booking service while it notified law enforcement and warned customers about suspicious messages.

Vercel security patch release for CVE-2026-75604

Security Patch Release

Updated: 27.08.2026 18:13 · First: 27.08.2026 18:13 · 📰 1 src / 1 articles · H score: 33

Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixes landed in Next.js 15.5.24 and 16.3.3, covering both a Windows path traversal issue and a flaw reachable through crafted AVIF image files. The Windows bug is tracked as CVE-2026-75604 and affects Next.js 13.4 through 15.5.23 plus 16.0 through 16.3.2. Vercel-hosted apps are reported protected, while affected Windows-hosted users were told to upgrade immediately.

ReliaQuest hit by network compromise

Incident

Updated: 27.08.2026 18:12 · First: 27.08.2026 18:12 · 📰 1 src / 1 articles · H score: 37

ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a lookalike domain and a fake SSO page to harvest credentials and trigger an MFA push approval. ReliaQuest said no applications or systems were accessed and no customer data was touched.

ToxNetV2 LLM-assisted botnet controller

Malware Activity

Updated: 27.08.2026 18:12 · First: 27.08.2026 18:12 · 📰 1 src / 1 articles · H score: 25

The ToxNetV2 botnet now uses an LLM-assisted controller that can turn host telemetry into operator-approved actions, expanding infected-system tasking to command execution, file writes, SSH, persistence, and compilation. The controller sends environment context to NVIDIA NIM with the z-ai/glm-5.2 model, parses the responses into structured tasks, and waits for operator approval before execution. The broader botnet also includes encrypted peer-to-peer C2, host management, scanner workers, self-propagation logic, and 17 network-attack launchers.

Amazon Kiro IDE prompt injection data exfiltration security flaw

Vulnerability

Updated: 27.08.2026 16:39 · First: 27.08.2026 16:39 · 📰 1 src / 1 articles · H score: 28

Amazon Kiro IDE 0.7.45 on Windows was found to have a prompt injection vulnerability that let attacker-controlled repository content influence Kiro Powers and push sensitive local information to an external endpoint. The flaw enabled data exfiltration after a victim opened a malicious workspace file and sent a message, even without explicitly asking Kiro to access or transmit the data. Amazon released a fix in Kiro IDE 0.8.140 after responsible disclosure.

TeamPCP supply-chain credential and data leak

Data Leak

Updated: 27.08.2026 16:31 · First: 27.08.2026 16:31 · 📰 1 src / 1 articles · H score: 59

A TeamPCP-linked supply-chain leak exposed half a million credentials and at least 300GB of data, putting over a thousand organizations worldwide at risk of downstream compromise. The exposure came from malicious code inserted into open-source repositories and then pulled into downstream applications used across government, academic, and private-sector environments. The stolen material included credentials, authentication secrets, and source code.

Manchester Airports Group customer booking and Wi-Fi sign-up data leak

Data Leak

Updated: 27.08.2026 16:00 · First: 27.08.2026 16:00 · 📰 1 src / 1 articles · H score: 67

Manchester Airports Group (MAG) confirmed a data leak involving customer booking and in-airport Wi-Fi sign-up records at three UK airports, creating phishing and smishing risk for affected travelers. The exposed records included email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said it had contained the risk, contacted customers and temporarily suspended its Manage My Booking service.

QTFY's freelance PRC hacker-network and cyber-contracting ecosystem

Threat Actor Meta

Updated: 27.08.2026 15:00 · First: 27.08.2026 15:00 · 📰 1 src / 1 articles · H score: 33

QTFY's participation in freelance PRC hacker networks and malicious cyber contracting marketplaces reveals a broader support ecosystem behind its operations. The networked model helps the group obtain new exploits and attack techniques faster, increasing risk to US government and critical infrastructure targets. It also points to a more scalable and resilient adversary market presence rather than a standalone hacking crew.

FBI urgent mitigation advisory for QTFY

Advisory/Mitigation

Updated: 27.08.2026 15:00 · First: 27.08.2026 15:00 · 📰 1 src / 1 articles · H score: 39

The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mission Force on 2026-08-26, responds to an active threat that uses custom malicious platforms to reach targeted networks. QTFY has used zero-day and N-day vulnerabilities, reconnaissance tooling, and traffic-obfuscation infrastructure to support the activity.

QTFY US government and critical infrastructure targeting campaign

Campaign

Updated: 27.08.2026 15:00 · First: 27.08.2026 15:00 · 📰 1 src / 1 articles · H score: 38

The FBI warned that QTFY is actively targeting US government and critical infrastructure systems with a custom-built intrusion ecosystem, increasing the risk of stealthy compromise across sensitive sectors. The group has operated since 2018 and has focused on the defense industrial base, communications, government, and higher education sectors. In 2024, it exfiltrated data from over 300 organizations after exploiting a Check Point Quantum Gateway vulnerability. Its toolkit includes QScan for reconnaissance and exploitation and QTRouter for traffic obfuscation through compromised IoT devices.

Security teams' daily AI use rises as alert overload and missed triage persist

Trend

Updated: 27.08.2026 14:30 · First: 27.08.2026 14:30 · 📰 1 src / 1 articles · H score: 26

Security teams are moving AI into daily security operations, making the technology a mainstream part of alert handling and investigation. The shift is happening as many teams still face 100 to 1,000 alerts per day, which stretches triage capacity and delays response. Missed or ignored alerts are still turning into breaches and downtime, tying adoption directly to operational risk. The trend shows both rising AI reliance and a continuing visibility gap when staffing and workload cannot keep pace.

Carhartt data leak after ShinyHunters dark web publication

Data Leak

Updated: 27.08.2026 14:10 · First: 27.08.2026 14:10 · 📰 1 src / 1 articles · H score: 87

The Carhartt data leak now exposes information from more than 12.9 million accounts, after ShinyHunters released stolen records on a dark web site. The exposed archive includes names, email addresses, phone numbers, and physical addresses, increasing fraud and identity-theft risk. Have I Been Pwned linked the breach to Carhartt's Databricks analytics platform, while Carhartt had not publicly confirmed the extortion claims at the time of publication.

Carhartt public leak after ShinyHunters extortion and Databricks linkage

Case

Updated: 27.08.2026 14:10 · First: 27.08.2026 14:10 · 📰 0 src / 1 articles

ShinyHunters has moved the Carhartt incident from an extortion claim to a public data-leak event by releasing an allegedly stolen archive on a dark web site after a $3.3 million ransom went unpaid. The archive was described as more than 50GB of customer, employee, and corporate data, and subsequent analysis tied the exposure to Carhartt's Databricks analytics platform. Have I Been Pwned said the leak affects more than 12.9 million Carhartt accounts and includes names, email addresses, phone numbers, and physical addresses, with over 15,000 employee @carhartt.com addresses also present. Carhartt had not publicly confirmed the extortion claim or disclosed remediation details in the available material.

Spark RAT phishing campaign targeting Cambodia

Campaign

Updated: 27.08.2026 14:00 · First: 27.08.2026 14:00 · 📰 1 src / 1 articles · H score: 29

A Spark RAT campaign is targeting individuals and organizations in Cambodia, using phishing archives, DLL sideloading, and a BYOVD step to disable defenses and install remote access tooling. The activity broadened lure themes across government notices, public health materials, real estate, and promotional content, increasing the chance of successful initial access. The intrusion chain also adds persistence and security-product tampering, raising the risk of sustained compromise.

Boston Scientific hit by cyberattack

Incident

Updated: 26.08.2026 18:19 · First: 26.08.2026 18:19 · 📰 2 src / 2 articles · H score: 26

Boston Scientific confirmed a cyberattack that caused a network outage and disrupted access to business systems used to process and ship customer orders. The event affects the company’s global operations and raises ongoing availability and continuity risk while restoration continues. The attack method, initial access route, and any data exposure remain undisclosed.

Dark Caracal GoCaracal Latin American phishing campaign

Campaign

Updated: 27.08.2026 12:33 · First: 27.08.2026 12:33 · 📰 1 src / 1 articles · H score: 33

Dark Caracal-linked operators deployed GoCaracal in a June 2026 intrusion, expanding a regional operation that combined phishing tradecraft, malware deployment, and Latin American targeting. The activity matters because the framework supported remote shell access, payload execution, and additional theft and control functions. Analysts also tied the operation to Bandook use and recurring delivery patterns across related infrastructure. The evidence points to a broader campaign thread rather than a one-off malware sample.

GoCaracal malware framework deployed during June 2026 Venezuela intrusion

Malware Activity

Updated: 27.08.2026 12:33 · First: 27.08.2026 12:33 · 📰 1 src / 1 articles · H score: 28

The GoCaracal malware framework surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, giving operators remote shell access and payload execution on the infected host. The extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying, expanding post-compromise control and collection options. Assessors linked the activity to Dark Caracal with medium confidence and shared a YARA rule plus IoCs for hunting.

Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)

Vulnerability

Updated: 27.08.2026 12:16 · First: 27.08.2026 12:16 · 📰 1 src / 1 articles · H score: 34

CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway VPN or AAA virtual servers. Successful exploitation can reach remote code execution as root on unpatched instances. CISA added the flaw to the KEV Catalog and moved to force rapid remediation across vulnerable federal systems.

ATF hit by ransomware attack

Incident

Updated: 27.08.2026 11:13 · First: 27.08.2026 11:13 · 📰 1 src / 1 articles · H score: 51

The ATF confirmed a system compromise after the Qilin ransomware gang added the agency to its leak portal, creating a major incident that required immediate containment. The affected environment was a standalone system separate from the enterprise network, and the agency said there was no indication that ATF eForms or other systems were affected. ATF cut connections, launched incident-response and forensic work, and said its operations were not impacted.

NVIDIA GPUThor mitigation advisory

Advisory/Mitigation

Updated: 26.08.2026 21:48 · First: 26.08.2026 21:48 · 📰 2 src / 2 articles · H score: 29

University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial-of-service, and enable host root escalation. NVIDIA later issued GPUThor hardening guidance on August 21 after being notified on April 29, 2026, recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting untrusted CUDA workloads. The affected models tested were RTX A4000, RTX A4500, RTX A5000, and RTX A6000. The researchers also reported double-bit errors and incorrect triple-bit error repairs, and said a locally owned RTX A6000 could be driven into a DoS state with ECC enabled.

NVIDIA Ampere-class GPUs GPUThor Rowhammer ECC bypass privilege-escalation flaw

Vulnerability

Updated: 26.08.2026 21:48 · First: 26.08.2026 21:48 · 📰 2 src / 2 articles · H score: 26

GPUThor is a Rowhammer vulnerability affecting NVIDIA workstation GPUs with GDDR6 memory that can defeat ECC and enable denial-of-service plus host root privilege escalation. University of Toronto researchers said they tested RTX A6000, RTX A5000, RTX A4500, and RTX A4000 cards, used non-uniform hammering to bypass Target Row Refresh (TRR), and reported April 29, 2026 notification to NVIDIA. NVIDIA later issued guidance recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting untrusted CUDA workloads. The researchers said there is no CVE and no patch for the attack.

UAT-10147 global Windows and Linux web server targeting campaign

Campaign

Updated: 27.08.2026 10:05 · First: 27.08.2026 10:05 · 📰 1 src / 1 articles · H score: 37

The UAT-10147 campaign is targeting Windows and Linux web servers globally, increasing exposure for education, media, technology, and gaming organizations. The activity points to a broad multi-sector operation rather than a single victim event.

CISA adds six flaws to KEV catalog

Public Sector Action

Updated: 27.08.2026 10:05 · First: 27.08.2026 10:05 · 📰 1 src / 1 articles · H score: 37

CISA added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, directing federal defenders to prioritize remediation of actively exploited weaknesses in products including Citrix NetScaler ADC and NetScaler Gateway. The agency set deadlines of August 29, 2026 for CVE-2019-1068 and CVE-2026-8452, and September 9, 2026 for the remaining flaws. The update raises remediation pressure across FCEB agencies and other organizations that track KEV-listed exposure.

Microsoft Windows 11 gaming disruption after KB5121003

Service Disruption

Updated: 21.08.2026 17:54 · First: 21.08.2026 17:54 · 📰 1 src / 3 articles · H score: 0

The Windows 11 gaming disruption is causing crashes, launch failures, freezes, and restarts on affected PCs, and Microsoft is investigating the problem. The issue affects Windows 11 24H2 and 25H2 systems after KB5121003 and later updates. Early findings point to RGB lighting devices whose drivers or components may trigger the breakage when certain games start. Embark Studios has shared a temporary inpoutx64.sys workaround while Microsoft works on an official fix.