Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 15:34 21/08/2026 UTC
  • Vulnerability H score 49 Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836) Microsoft Entra ID is dealing with CVE-2026-69836, a CVSS 10.0 deserialization RCE that was exploited in the wild and is already fully mitigated, changing the immediate risk posture for cloud identity admins.
  • Vulnerability H score 40 Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570) CERT Polska says attackers are exploiting Zimbra Collaboration Suite CVE-2026-73570 (unauthenticated SNMP command injection RCE), and Shadowserver has tracked over 12,100 exposed Zimbra servers, advancing the urgency to patch and hunt.
  • Campaign H score 73 Mabna Institute campaign expands across multiple victims New reporting on the Mabna Institute/IRGC-backed Mabna Institute campaign shows large-scale compromise of roughly 8,000 professor accounts (spanning 100,000+ worldwide) and data theft/extortion, strengthening attribution and impact assessments.
  • Vulnerability H score 73 Gogs path traversal to Git hooks RCE (CVE-2026-52813) Gogs fixed CVE-2026-52813, a maximum-severity path traversal leading to Git hooks RCE via ../ in organization names, moving the issue from theoretical exposure to a concrete upgrade directive (0.14.3).
  • Data Leak H score 70 SickKids employee and applicant data exposure SickKids disclosed exposure of employee and applicant personal data via a third-party software flaw, updating the incident’s scope and prompting immediate identity-theft/social-engineering risk mitigation despite no impact to clinical systems.
  • Public Sector Action H score 37 CISA KEV patch directive for TrueConf Server flaws CISA added TrueConf Server CVE-2026-72529 and CVE-2026-72530 to KEV and ordered FCEB agencies to remediate within two weeks, advancing compliance requirements around actively exploited RCE-capable flaws.
Last updated: 08:06 21/08/2026 UTC

Latest updates

Browse →

Microsoft Windows 11 gaming disruption after KB5121003

Service Disruption

Updated: 21.08.2026 17:54 · First: 21.08.2026 17:54 · 📰 1 src / 1 articles · H score: 0

The Windows 11 gaming disruption is causing crashes, launch failures, freezes, and restarts on affected PCs, and Microsoft is investigating the problem. The issue affects Windows 11 24H2 and 25H2 systems after KB5121003 and later updates. Early findings point to RGB lighting devices whose drivers or components may trigger the breakage when certain games start. Embark Studios has shared a temporary inpoutx64.sys workaround while Microsoft works on an official fix.

Arrayref maintainer account hit by network compromise

Incident

Updated: 20.08.2026 20:53 · First: 20.08.2026 20:53 · 📰 3 src / 3 articles · H score: 33

The arrayref maintainer account was compromised, and malicious crate releases on crates.io executed during compilation on developers’ systems, creating a supply-chain intrusion risk. The same account also poisoned append-only-vec and internment within a 23-minute window, widening exposure across widely used Rust packages. The fake dependency proc-macro1 used a `build.rs` script and platform-specific payloads to run on Linux, Windows, and macOS systems. The payload was built to collect host data and browser credentials, making the compromise a direct theft and persistence risk for developers.

CISA KEV patch directive for TrueConf Server flaws

Public Sector Action

Updated: 21.08.2026 15:25 · First: 21.08.2026 15:25 · 📰 1 src / 1 articles · H score: 37

CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV catalog and ordered FCEB agencies to secure TrueConf Server within two weeks, forcing rapid federal response to actively exploited vulnerabilities. The affected product is a self-hosted secure messaging and video-conferencing platform that runs inside an organization's LAN, so exposure can reach internal networks. The directive addresses flaws that can enable unauthenticated script execution and remote code execution.

Agent Tesla v4 infostealer with emoji obfuscation and BEC delivery

Malware Activity

Updated: 21.08.2026 15:00 · First: 21.08.2026 15:00 · 📰 1 src / 1 articles · H score: 29

The Agent Tesla v4 infostealer is now being delivered through a BEC lure that targets finance departments and can steal credentials from more than 40 applications. The sample adds Unicode emoji obfuscation, ConfuserEx, and DonutLoader injection to make detection harder. It also exfiltrates stolen data to attacker-controlled infrastructure within seconds, increasing the chance of rapid account compromise.

FTP-banner dead-drop resolver malware delivery campaign

Campaign

Updated: 21.08.2026 14:00 · First: 21.08.2026 14:00 · 📰 1 src / 1 articles · H score: 39

A campaign is using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, creating a new command-delivery path that can bypass standard web-service monitoring. The operation has been weaponized since early July 2026 and was still active with new infrastructure seen in August 2026. It starts with ZIP archives that trigger a .LNK infection chain, and researchers assess phishing as the likely initial access route. The payloads provide remote access, screen capture, file transfer, and credential-theft capabilities.

E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers

Malware Activity

Updated: 21.08.2026 14:00 · First: 21.08.2026 14:00 · 📰 1 src / 1 articles · H score: 29

New Windows RAT activity has been identified using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, increasing risk from remote command execution, screenshot capture, and credential theft. The activity has been operational since early July 2026 and remained active into August 2026, showing that the delivery method is still in use. The infection chain relies on .LNK-based execution and likely phishing to start the compromise. The two malware families use different C2 and execution paths, but both aim to establish durable remote access on victim systems.

SickKids employee and applicant data exposure

Data Leak

Updated: 21.08.2026 13:10 · First: 21.08.2026 13:10 · 📰 1 src / 1 articles · H score: 70

A SickKids cybersecurity incident exposed personal information for current and former employees, Boomerang and SickKids Foundation staff, and job applicants, creating identity-theft and social-engineering risk. The hospital says the exposure came from a third-party software flaw and that clinical systems and patient records were untouched. The public Careers website was temporarily taken offline and later restored. Individuals identified as affected will be notified directly, and SickKids is offering 24 months of credit monitoring and identity protection.

Defense contractors' CMMC confidence rises while proof of compliance lags

Trend

Updated: 21.08.2026 11:41 · First: 21.08.2026 11:41 · 📰 1 src / 1 articles · H score: 25

Across the defense industrial base, defense contractors are becoming more confident in CMMC/SPRS compliance even as their ability to prove it remains weak, widening a verification gap that affects procurement and legal exposure. A recent survey of 273 contractors found 96% confidence in self-attested scores but only 29% with the evidence needed to back them up. A second survey showed the same pattern over a longer horizon, with SPRS scores improving while confidence in their accuracy fell.

GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650

Security Patch Release

Updated: 18.08.2026 00:03 · First: 18.08.2026 00:03 · 📰 2 src / 3 articles · H score: 31

GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauthenticated attacker remotely modify or delete public projects and user data. The same release also patched CVE-2026-19650 in the GraphQL multiplex query handler. GitLab.com and GitLab Dedicated were already patched. Self-managed installations need to move to 19.2.4, 19.1.6, 19.0.8, or 18.11.11.

Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)

Vulnerability

Updated: 21.08.2026 09:06 · First: 21.08.2026 09:06 · 📰 2 src / 2 articles · H score: 49

Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity and access management service and stems from deserialization of untrusted data that can let an attacker execute code over a network. Microsoft says the issue has already been fully mitigated, so no customer action is required.

Tyler Robert Buchanan guilty plea in Scattered Spider crypto-theft case

Law Enforcement

Updated: 20.04.2026 16:33 · First: 20.04.2026 16:33 · 📰 2 src / 2 articles · H score: 26

Tyler Robert Buchanan pleaded guilty in the United States in a Scattered Spider cybercrime case, increasing his criminal exposure for wire fraud and aggravated identity theft. The plea resolves part of a scheme prosecutors say used SMS phishing and SIM swapping to steal cryptocurrency and hijack victims' accounts.

Scattered Spider 2022 SMS phishing campaign targeting technology companies

Campaign

Updated: 21.04.2026 17:53 · First: 21.04.2026 17:53 · 📰 1 src / 1 articles · H score: 29

Tyler Robert Buchanan’s guilty plea newly confirms Scattered Spider’s 2022 SMS phishing campaign, showing it reached at least a dozen major technology companies and enabled downstream cryptocurrency theft. The operation matters because it paired text-message social engineering with credential theft and later SIM-swapping abuse.

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign

Updated: 20.08.2026 22:59 · First: 20.08.2026 22:59 · 📰 1 src / 1 articles · H score: 16

A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and European defense targets. The operation is actively stealing tokens and steering victims through legitimate login flows to make takeover attempts harder to spot. Between August 6 and August 13, 2026, the group sent targeted phishing emails to people in or related to the European defense industry. The activity spans Ukraine, Western Europe, and the U.S. and is designed for repeated account access rather than a single one-off lure.

Proc-macro1 malicious crate payload

Malware Activity

Updated: 20.08.2026 20:53 · First: 20.08.2026 20:53 · 📰 1 src / 1 articles · H score: 29

A proc-macro1 typosquatted dependency executed a build-time payload during compilation, creating a credential-stealing risk for developers on Linux, Windows, and macOS. The payload reconstructed its infrastructure from base64-encoded fragments and chose host-matched code for each platform. It then targeted browser secrets from Chrome, Brave, and Edge while establishing persistence on the endpoint.

Gogs path traversal to Git hooks RCE (CVE-2026-52813)

Vulnerability

Updated: 20.08.2026 20:23 · First: 20.08.2026 20:23 · 📰 1 src / 1 articles · H score: 73

Gogs fixed CVE-2026-52813, a maximum-severity flaw that could lead to remote code execution through Git hooks. The bug accepted organization names containing ../ path traversal sequences, letting attackers write repository data to unintended filesystem locations and overwrite hooks configuration. The issue was addressed in version 0.14.3.

ErrTraffic and Cruciferra ClickFix BYOVD malware activity

Malware Activity

Updated: 20.08.2026 20:23 · First: 20.08.2026 20:23 · 📰 1 src / 1 articles · H score: 72

The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes. The activity routes victims from compromised WordPress sites through an obfuscated JavaScript loader before fetching the next stage from a Polygon smart contract. Recent uses of the framework have also pushed Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader. The chain broadens the malware's reach and makes the delivery path harder to inspect.

DoJ charges Mabna Institute members and State Department offers reward

Law Enforcement

Updated: 20.08.2026 20:23 · First: 20.08.2026 20:23 · 📰 1 src / 1 articles · H score: 70

The U.S. Department of Justice charged 17 Mabna Institute members in a cyberintrusion case, and the U.S. Department of State announced a $10 million reward tied to the investigation.

Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)

Vulnerability

Updated: 20.08.2026 12:46 · First: 20.08.2026 12:46 · 📰 3 src / 3 articles · H score: 40

CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is now actively exploited, giving attackers unauthenticated remote code execution against exposed servers. The flaw is a command injection issue in the SNMP monitoring component when SNMP notifications are enabled. Zimbra 10.1.20 was released on July 20 to patch the vulnerability, and exposed deployments remain a live target.

Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)

Vulnerability

Updated: 20.08.2026 09:04 · First: 20.08.2026 09:04 · 📰 2 src / 2 articles · H score: 24

CVE-2026-32475 in Elementor Pro lets an unauthenticated attacker bypass file-upload validation in the Forms module's File Upload field, write a PHP file into a public directory, and reach remote code execution on affected WordPress sites. The flaw affects plugin versions prior to and including 4.2.1 on sites that expose a published Elementor page with the vulnerable form field. Version 4.2.2 was released on 2026-08-19 to address the issue.

Elementor Pro 4.2.2 security update for CVE-2026-32475

Security Patch Release

Updated: 20.08.2026 09:04 · First: 20.08.2026 09:04 · 📰 2 src / 2 articles · H score: 27

Elementor Pro released version 4.2.2 to fix CVE-2026-32475, closing an unauthenticated file-upload RCE path in the WordPress plugin. The update targets the Forms module's File Upload field and removes a flaw that could let an attacker write a PHP file into a public directory. Sites still running 4.2.1 or earlier need the patch to eliminate the exposed code-execution path.

Encrypted prompt injection in xAI's Grok web chat exfiltrates session context

Technical Analysis

Updated: 20.08.2026 17:36 · First: 20.08.2026 17:36 · 📰 1 src / 1 articles · H score: 22

Researchers disclosed Cryptographic Context Injection, an encrypted prompt-injection technique that can make xAI's Grok web chat leak private session data through an outbound tool call. The chain can expose a user's name, approximate location, subscription tier, and ongoing conversation prompts to an attacker-controlled server. The payload hides behind PBKDF2 and AES-256-GCM, so the malicious instructions are recovered inside the model runtime rather than being seen as ordinary page text.

JFrog security patch release for CVE-2026-69106

Security Patch Release

Updated: 20.08.2026 17:30 · First: 20.08.2026 17:30 · 📰 1 src / 1 articles · H score: 30

JFrog has issued fixes for JFrog Artifactory after disclosure of CVE-2026-69106 and CVE-2026-65922, two flaws that could let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues affect JFrog Artifactory deployments handling repository metadata, including paths that can be poisoned or trusted improperly. Administrators should move to the patched release and reduce exposure of anonymous access where it is not required.

JFrog Artifactory metadata manipulation flaws (multiple vulnerabilities)

Vulnerability

Updated: 20.08.2026 17:30 · First: 20.08.2026 17:30 · 📰 1 src / 1 articles · H score: 25

JFrog Artifactory flaws let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues are tracked as CVE-2026-69106 and CVE-2026-65922, and JFrog has issued fixes. One flaw affects X-Orig-Client-Uri handling, while the other allows writes into trusted .jfrog/ metadata paths.

Isolated-vm security fixes for sandbox escape flaw

Security Patch Release

Updated: 20.08.2026 16:48 · First: 20.08.2026 16:48 · 📰 2 src / 2 articles · H score: 16

Security fixes for isolated-vm now close a sandbox escape flaw in affected releases, reducing the risk of host memory corruption and potential host RCE. The patch covers all versions before and including 7.0.0 and ships in 6.2.0 and 7.0.1. The issue is tracked as GHSA-864f-rcv7-6rh4.

Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw

Vulnerability

Updated: 20.08.2026 16:48 · First: 20.08.2026 16:48 · 📰 1 src / 1 articles · H score: 16

isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versions through 7.0.0. The bug can crash the host with SIGSEGV and, in the maximum demonstrated case, reach control-flow hijack with potential remote code execution. Patched releases 6.2.0 and 7.0.1 are available, and earlier versions should be updated.

NCSC interim sandboxing guidance for autonomous AI agents

Defensive Guidance

Updated: 20.08.2026 15:45 · First: 20.08.2026 15:45 · 📰 1 src / 1 articles · H score: 16

NCSC issued interim guidance for autonomous AI agents, recommending sandboxing, human oversight, and tightly controlled access to reduce the risk of unintended or malicious actions. The advice targets organizations building or operating agentic AI systems and calls for pre-deployment assessment of autonomy, prompts, tools, networks, and services. It also pushes default-deny network controls, distinct identities, short-lived credentials, and the ability to stop agent activity quickly when behavior changes.

Rising SPRS scores mask declining CMMC confidence across US defense contractors

Trend

Updated: 20.08.2026 15:40 · First: 20.08.2026 15:40 · 📰 2 src / 2 articles · H score: 22

US defense contractors and subcontractors are posting a five-year high in SPRS self-assessment scores while confidence in those scores is falling, widening a CMMC readiness gap across the DIB. The trust decline suggests self-reported compliance may be outpacing verified cybersecurity maturity. Only 65% of respondents said their score was accurate, down from 89% last year and 94% in 2024. Just 1% said they are completely prepared for CMMC certification.

Atlassian third-party dependency patches (multiple vulnerabilities)

Security Patch Release

Updated: 20.08.2026 15:24 · First: 20.08.2026 15:24 · 📰 1 src / 1 articles · H score: 26

Atlassian released fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira after finding 10 critical and 162 high-severity issues in shared third-party dependencies. The release addresses about 109 unique CVEs and reduces exposure to RCE, DoS, information theft, MitM, authentication bypass, and SSRF across multiple products.

Atlassian third-party dependency security bulletin

Security Patch Release

Updated: 20.08.2026 15:24 · First: 20.08.2026 15:24 · 📰 1 src / 1 articles · H score: 26

Atlassian released a Security Bulletin with fresh updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira to address 10 critical and 162 high-severity third-party dependency issues. The bundled fixes cover about 109 unique CVEs and reduce exposure to RCE, DoS, information theft, MitM, authentication bypass, and SSRF. The bulletin makes the patch cycle relevant across multiple Atlassian product lines because shared libraries spread the defects beyond a single application.

MLflow and FUXA active exploitation wave

Exploitation Wave

Updated: 18.08.2026 20:44 · First: 18.08.2026 20:44 · 📰 3 src / 3 articles · H score: 46

Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA are both being targeted in the wild. The activity spans internet-wide probing of public instances and abuse attempts against reachable systems. The wave surfaced on August 17-18, 2026 and remains active.