Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:11 03/08/2026 UTC
Last updated: 23:04 02/08/2026 UTC
  • Security Patch Release H score 55 Arista VeloCloud Orchestrator security update for CVE-2026-16812 Arista patched CVE-2026-16812, an actively exploited maximum-severity 10 OS command injection in on-prem VeloCloud Orchestrator, and added it to CISA’s Known Exploited Vulnerabilities catalog—raising urgency for fleet-wide remediation.
  • Vulnerability H score 51 Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316) Cisco Secure FMC is exposed by CVE-2026-20316, a static credential flaw already exploited in zero-day attacks, prompting hot fixes with no full workaround and increasing the likelihood of credential-based compromise.
  • Threat Actor Meta H score 89 Tycoon2FA-Kali365-ARToken alliance reshapes ransomware ecosystem operations Tycoon2FA and Kali365’s device-code phishing PaaS commoditizes token theft across multiple criminal platforms, advancing ransomware-ecosystem operator access abuse at scale.
  • Malware Activity H score 83 Dysphoria botnet DDoS and traffic relay activity The Dysphoria botnet has grown to about 200,000 infected devices and is being used for sustained DDoS plus traffic-relay operations, expanding disruption potential and confirming ongoing evolution.
  • Data Leak H score 76 Internet-exposed BMC password-hash exposure Internet-exposed BMCs are leaking password-derived authentication material at scale (24,650 hosts on UDP/623 IPMI), materially increasing odds of offline cracking and unauthorized management-plane access.
  • Advisory/Mitigation H score 57 Ruflo exposed-instance remediation guidance After disclosure of CVE-2026-59726, Ruflo guidance tells operators of exposed instances to close ports 3001/27017 and rotate LLM API keys, accelerating mitigation against fully exploitable AI-agent compromise risk.

Latest updates

Browse →

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity

Updated: 03.08.2026 22:25 · First: 03.08.2026 22:25 · 📰 1 src / 1 articles · H score: 29

The fake Xeno Executor loader chain is dropping a Java-based RAT and information stealer onto devices used by Roblox players, creating a high-risk path to credential theft and remote control. Victims run xeno.exe believing it is legitimate, but it launches an obfuscated Java stage and fetches the final payload. The malware steals browser cookies and stored data from Chrome, Edge, Brave, Opera, and Vivaldi, and targets Discord, Roblox, Minecraft, Microsoft Store tokens, and Exodus Wallet data. Its keylogging, screenshotting, webcam access, and remote shell features turn the infection into a full post-compromise surveillance platform.

Roblox fake Xeno Executor installer campaign

Campaign

Updated: 03.08.2026 22:25 · First: 03.08.2026 22:25 · 📰 1 src / 1 articles · H score: 36

The fake Xeno Executor installer campaign is spreading malware to Roblox players, putting account data, payment details, and remote access at risk. Operators push the lure through gaming forums, Discord communities, and compromised or impersonated accounts. The activity has run since the start of the year, spiked in March, and then stabilized. Victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer.

Xanadu hit by network compromise

Incident

Updated: 03.08.2026 21:43 · First: 03.08.2026 21:43 · 📰 1 src / 1 articles · H score: 34

Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configurations at risk. The rogue package turned routine imports into credential theft and sent data to metrics.femboy[.]energy. Attackers appear to have probed the project’s self-hosted CI runners to recover publishing secrets before pushing the malicious version. The compromise raises follow-on access risk for a research and HPC environment that relies on the library.

Alibaba developer tools npm supply-chain espionage campaign

Campaign

Updated: 03.08.2026 21:43 · First: 03.08.2026 21:43 · 📰 1 src / 1 articles · H score: 44

A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compromise. Malicious packages impersonate private @ali-scoped dependencies and use a layered delivery chain to hide loader logic. The operation spans March and April 2026 and is aimed at Chinese-speaking developers in Alibaba-linked environments.

Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users

Malware Activity

Updated: 03.08.2026 21:43 · First: 03.08.2026 21:43 · 📰 1 src / 1 articles · H score: 37

Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-speaking environments at risk of backdoor access. The packages impersonate private @ali-scoped components and use decoy wrappers to activate hidden dependencies. The final payload supports command execution, file upload/download, host reconnaissance, payload staging, and lateral movement, raising the impact of the supply-chain compromise.

N-able security patch release for CVE-2026-18577

Security Patch Release

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 2 articles · H score: 41

N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3.1.7 for all versions before 2026.3, after earlier investigation found remote administrative access on servers running 2026.1 and earlier. N-able says hosted deployments already received the update, while on-premises customers must install it manually. The company also provided IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 2 articles · H score: 40

CVE-2026-18577 is an authentication bypass in N-able N-central affecting hosted and on-premises servers before 2026.3. N-able said it detected active exploitation on August 1 and released hotfix 2026.3.1.7 on August 2, urging customers to upgrade immediately. The vendor said the issue stems from an incomplete patch for CVE-2026-18576, and it published IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder. Huntress separately reported exploitation tied to one partner account, nine organisations, and one endpoint in each, with observed post-compromise activity limited to process enumeration.

N-able N-central servers hit by network compromise

Incident

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 2 articles · H score: 39

N-able N-central servers were hit by an authentication bypass compromise that let attackers gain remote administrative access and persist on managed endpoints through Take Control and Cloudflared services. CVE-2026-18577 affects hosted and on-premises N-central deployments, and N-able said hotfix 2026.3.1.7 is the first unaffected release. The vendor said it detected active exploitation on August 1 and urged immediate upgrading, while published IOCs include four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis

Updated: 03.08.2026 19:24 · First: 03.08.2026 19:24 · 📰 1 src / 1 articles · H score: 3

Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or mint passkey authentication material. The methods, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, abuse Chrome's device-key handling, re-enrollment flow, and synced-secret handling rather than breaking cryptography. The strongest path targets the 32-byte Security Domain Secret (SDS) that protects synced passkeys, creating reusable access risk after an initial compromise.

Visa acquires BioCatch for fraud intelligence expansion

Industry Action

Updated: 03.08.2026 18:32 · First: 03.08.2026 18:32 · 📰 1 src / 1 articles · H score: 55

Visa agreed to acquire BioCatch for $2.4 billion in cash, consolidating cyber and fraud-detection capabilities in the payments sector. The deal adds behavioral biometrics to Visa's security portfolio and broadens its reach in financial crime detection. Closing is expected by the end of Visa’s fiscal second quarter of 2027, pending approvals.

BTMOB Android RAT malware-as-a-service activity

Malware Activity

Updated: 03.08.2026 17:45 · First: 03.08.2026 17:45 · 📰 1 src / 1 articles · H score: 27

The BTMOB Android RAT kept being sold and updated as a malware-as-a-service package across 2025-2026, extending its reach and increasing the risk of information theft and remote control on Android phones. The operation also splintered into a broader underground market with resellers, source-code sellers, and independent administrators. Official releases continued while cheaper lookalike offers and Telegram sales campaigns pushed access, infrastructure, and code.

BTMOB's underground market fragments into resellers and source-code sellers

Threat Actor Meta

Updated: 03.08.2026 17:45 · First: 03.08.2026 17:45 · 📰 1 src / 1 articles · H score: 20

BTMOB's underground market has fragmented into resellers, source-code sellers, and independent administrators, weakening control over the Android RAT ecosystem. Across 2025-2026, the same brand was used for competing offers of access, private infrastructure, and source code, creating uncertainty over who was behind each sale. The shift expands the market for cheaper copies and lookalike versions while making support and authenticity harder to verify. It turns BTMOB from a single malware service into a contested criminal software marketplace.

Horizon3 Series E funding round

Industry Action

Updated: 03.08.2026 16:00 · First: 03.08.2026 16:00 · 📰 1 src / 1 articles · H score: 14

Horizon3 raised $250 million in a Series E round, lifting its valuation to $2 billion and extending its capacity to scale cybersecurity operations. The company said the capital will support go-to-market expansion through MSPs and telcos and continued R&D against AI-driven attacks. The round was co-led by NightDragon and NEA, with additional new and returning investors participating.

HollowFrame and Matryoshka fake Python DLL sideloading activity

Malware Activity

Updated: 03.08.2026 14:26 · First: 03.08.2026 14:26 · 📰 1 src / 1 articles · H score: 23

The HollowFrame loader and Matryoshka backdoors were delivered through a counterfeit Python runtime, turning a spear phishing chain into trusted-process abuse on two endpoints at a law firm. The operators added Defender exclusions for `python.exe`, then used DLL sideloading to hand execution to malicious Go and Rust payloads. One Matryoshka variant also used GitHub as a covert tasking and file-transfer channel.

GHOSTBLADE credential-stealing activity on Apple iOS

Malware Activity

Updated: 03.08.2026 13:49 · First: 03.08.2026 13:49 · 📰 1 src / 1 articles · H score: 34

The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account takeover and deeper compromise. The activity uses a DarkSword exploit chain and malicious web pages to reach iOS 18.4 through 18.7 targets. Successful execution turns the implant into a credential-stealing and file-exfiltration tool. The operation expands the blast radius beyond the initial exploit by collecting reusable login material from compromised devices.

INC Ransomware campaign expands across multiple victims

Campaign

Updated: 03.08.2026 13:39 · First: 03.08.2026 13:39 · 📰 1 src / 1 articles · H score: 43

The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countries. Newly listed victims and follow-on email and phone pressure tactics suggest the group is pairing exploitation with extortion. The activity has been tied to recent abuse of CVE-2026-15409 and CVE-2026-15410 against exposed appliances.

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave

Updated: 03.08.2026 13:39 · First: 03.08.2026 13:39 · 📰 1 src / 1 articles · H score: 57

Attackers are conducting an active zero-day exploitation wave against SonicWall SMA1000 appliances using CVE-2026-15409 and CVE-2026-15410, creating takeover risk for exposed remote-access systems. The flaws let unauthenticated attackers open a WebSocket tunnel to restricted services and escalate to root, which can turn edge appliances into launch points for internal network access. The activity has been underway since at least June 22 and has already produced multiple new victims across several regions and sectors.

KT Corporation hit by network compromise

Incident

Updated: 31.07.2026 01:28 · First: 31.07.2026 01:28 · 📰 2 src / 2 articles · H score: 40

KT Corporation was hit by a femtocell-based network compromise that exposed subscriber data and enabled unauthorized mobile micropayments. South Korea’s PIPC said the issue began with a lost femtocell whose certificate was reused to reach KT’s mobile network, intercept traffic, and steal authentication codes used for payments. The regulator said 16,647 users had mobile-number and device identifiers compromised, and 368 customers were defrauded of 240 million won ($175,000). The same investigation also found 38 internal servers infected with malware including BPFDoor after a separate compromise of the KT Roaming Rental Service website.

Police National Legal Database (PNLD) hit by network compromise

Incident

Updated: 03.08.2026 12:13 · First: 03.08.2026 12:13 · 📰 2 src / 2 articles · H score: 45

The Police National Legal Database (PNLD) confirmed a compromise that exposed police, government, and customer contact information, with some data later published on the dark web. The exposure included names, organisations, and work email addresses for police, criminal justice, government, and customer contacts. The breach increases phishing risk even though PNLD said there was no evidence that passwords or other security credentials were compromised.

Police National Legal Database dark-web contact data leak

Data Leak

Updated: 03.08.2026 12:13 · First: 03.08.2026 12:13 · 📰 1 src / 1 articles · H score: 34

The Police National Legal Database (PNLD) confirmed that contact information for police, government and customer users was published on the dark web, exposing names and work email addresses and increasing phishing risk. The exposed set included records tied to police officers, police staff, criminal justice professionals, government partners and customers. The leak was identified on July 26, 2026, and PNLD said there was no evidence that passwords or other security credentials were compromised.

Coldcard seed-generation PRNG actively exploited security flaw

Vulnerability

Updated: 01.08.2026 20:17 · First: 01.08.2026 20:17 · 📰 3 src / 3 articles · H score: 35

Coldcard hardware wallet firmware carried a seed-generation flaw that used a deterministic software PRNG instead of the STM32 hardware RNG, enabling offline reconstruction of candidate seeds for affected wallets. The flaw was linked to a July 30 Bitcoin sweep that drained 1,196 addresses and about 1,082.65 BTC. Coinkite shipped emergency firmware on July 31, but existing seeds created on vulnerable builds still need to be replaced.

Applied Biosystems human identification software file-tampering flaw (CVE-2026-17583)

Vulnerability

Updated: 03.08.2026 11:05 · First: 03.08.2026 11:05 · 📰 1 src / 1 articles · H score: 27

The Applied Biosystems file-tampering flaw in human identification software could let data files be altered before analysis, creating a near-undetectable integrity risk for DNA test outputs. Thermo Fisher Scientific has patched CVE-2026-17583 in five supported product lines, while older end-of-life lines remain unpatched. The issue is rated High with a CVSS v4.0 score of 8.2 and affects .fsa and .hid outputs. Thermo Fisher said it knew of no exploitation when it disclosed the flaw.

Hugging Face diffusers trust_remote_code bypass (multiple vulnerabilities)

Vulnerability

Updated: 28.07.2026 18:15 · First: 28.07.2026 18:15 · 📰 2 src / 2 articles · H score: 22

Hugging Face Diffusers flaws in the FaceHugger set let crafted model repositories bypass trust_remote_code and load arbitrary code during model loading. The disclosure covers CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513, with one path abusing the `None.py` pipeline-name edge case and another exploiting a TOCTOU race between hf_hub_download and snapshot_download. Diffusers 0.38.0 was released on May 1 to close the identified variants. The affected loading path includes DiffusionPipeline.from_pretrained with custom pipelines, so AI pipelines, CI/CD systems, and container images that pull from Hugging Face repositories can be exposed if they load untrusted content.

Rails Active Storage mitigation guidance for CVE-2026-66066

Advisory/Mitigation

Updated: 01.08.2026 17:20 · First: 01.08.2026 17:20 · 📰 1 src / 1 articles · H score: 40

Rails maintainers issued mitigation guidance for CVE-2026-66066, directing Active Storage operators to upgrade to libvips 8.13 or later and rotate secrets after the flaw enabled arbitrary file read and possible RCE. The guidance applies to apps that process untrusted image uploads with libvips, where a crafted image can expose application files and environment secrets. Administrators on supported systems can also block the vulnerable path with VIPS_BLOCK_UNTRUSTED or Vips.block_untrusted(true). Rails says there is no workaround for deployments using libvips before 8.13.

Rails Active Storage arbitrary file read and RCE flaw (CVE-2026-66066)

Vulnerability

Updated: 01.08.2026 17:20 · First: 01.08.2026 17:20 · 📰 1 src / 1 articles · H score: 37

CVE-2026-66066 leaves Rails Active Storage vulnerable to arbitrary file read and possible RCE when libvips handles untrusted image uploads. The flaw affects Active Storage before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, with public PoC exploits accelerating disclosure and response.

Rails maintainers security patch release for CVE-2026-66066

Security Patch Release

Updated: 01.08.2026 17:20 · First: 01.08.2026 17:20 · 📰 1 src / 1 articles · H score: 40

Rails published an advisory and version guidance for CVE-2026-66066, a critical Active Storage flaw affecting specific release lines and requiring upgrades. The patch scope covers Active Storage before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1. Systems using libvips should move to 8.13 or later and rotate exposed secrets because the issue can expose arbitrary files and lead to RCE.

Adform hit by network compromise

Incident

Updated: 01.08.2026 00:09 · First: 01.08.2026 00:09 · 📰 2 src / 2 articles · H score: 24

Adform’s trackpoint-async.js tracking script was compromised in a supply-chain attack, causing downstream sites to deliver crypto-stealing code to visitors and redirect wallet payments. The malicious script ran from s2.adform.net and targeted clipboard-copied wallet addresses. Adform said it detected suspicious activity on July 27 and removed the code, but the activity had already been active for about a week.

Adform trackpoint-async.js clipboard-hijacking malware activity

Malware Activity

Updated: 01.08.2026 00:09 · First: 01.08.2026 00:09 · 📰 2 src / 2 articles · H score: 31

The trojanized Adform tracking script began monitoring visitors’ clipboards and swapping copied Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled ones, creating an active crypto-payment theft risk on websites that embedded the code. The malicious payload was delivered through trackpoint-async.js from s2.adform.net and operated only while affected pages were open. Related malicious scripts also sent victim IP addresses, referring websites, and URL paths to 84.32.102[.]230:7744. Adform said it removed the code after detecting suspicious activity on July 27, 2026.

Adobe security patch release for CVE-2026-48395

Security Patch Release

Updated: 01.08.2026 10:12 · First: 01.08.2026 10:12 · 📰 1 src / 1 articles · H score: 39

Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execution. The release includes CVE-2026-48395, CVE-2026-48396, CVE-2026-48390, CVE-2026-48391, CVE-2026-48374, CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394. Users should apply the latest updates to reduce exposure to these code-execution paths.

CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign

Campaign

Updated: 01.08.2026 09:29 · First: 01.08.2026 09:29 · 📰 3 src / 3 articles · H score: 40

Microsoft Threat Intelligence says Storm-2945/Midnight Blizzard has run CaptiveCrunch since early May, hijacking hotel and conference Wi‑Fi captive portals to route guests through attacker infrastructure and push fake browser/OS updates. The landing pages used ClickFix techniques, and some also served an APK or redirected users into device code authentication flows on Microsoft sign-in pages starting July 16. Microsoft attributes the activity to a sub-cluster of Midnight Blizzard and says the operation has targeted corporate travelers’ accounts at shared venues. The campaign uses CornFlake and ChocoShell to steal browser credentials, cookies, Microsoft 365 SSO tokens, and Wi‑Fi credentials, with a web panel branded FruitStone.