Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 08:04 11/08/2026 UTC
Last updated: 16:49 10/08/2026 UTC

Latest updates

Browse →

CERT Polska private APN hardening recommendations

Advisory/Mitigation

Updated: 11.08.2026 09:55 · First: 11.08.2026 09:55 · 📰 1 src / 1 articles · H score: 29

CERT Polska issued mitigation guidance for private APNs used to reach OT equipment after a real intrusion path into a Polish CHP plant. The recommendations focus on client isolation, traffic segmentation, and default-credential hygiene to stop lateral movement across cellular-managed access. The guidance is aimed at reducing the risk of pivoting from a compromised device into industrial control systems.

BdThemes hit by network compromise

Incident

Updated: 10.08.2026 17:30 · First: 10.08.2026 17:30 · 📰 3 src / 3 articles · H score: 17

A BdThemes WordPress plugin supply-chain compromise let attackers poison the Biggopti promotional API feed and trigger browser-executed code in wp-admin pages, leading to rogue administrator accounts and a webshell on impacted sites. Wordfence said attacks were seen starting August 7, and the earliest possible campaign start was June 23; the affected plugins were later temporarily closed pending review. A later analysis tied the browser path to a March 1 code change in Prime Slider that concatenated an unescaped JSON field into an HTML attribute. The compromise affected BdThemes products including Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit.

SecurityWeek AI Risk Summit 2026

Commercial Activity

Updated: 27.05.2026 16:00 · First: 27.05.2026 16:00 · 📰 1 src / 1 articles · H score: 0

SecurityWeek will host the 2026 Artificial Intelligence (AI) Risk Summit on August 11-12, 2026, creating a paid cybersecurity conference focused on AI adoption and security for CISOs, security leaders, AI researchers, developers, policymakers, and enterprise risk professionals.

Russian Electrum Poland energy-sector destructive campaign

Campaign

Updated: 11.08.2026 02:07 · First: 11.08.2026 02:07 · 📰 1 src / 1 articles · H score: 43

The Russian Electrum-linked December 29, 2025 operation expanded into a multi-site destructive campaign against Poland's energy sector, targeting 30 wind and solar installations and a large CHP plant. The activity destroyed key equipment and used OT disruption tactics across multiple facilities. The breadth of the target set and the repeated destructive methods show a coordinated campaign rather than a single-site incident.

StormEncryptor ransomware deployment by Storm-1175

Malware Activity

Updated: 10.08.2026 20:42 · First: 10.08.2026 20:42 · 📰 2 src / 2 articles · H score: 40

Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ransom notes. Microsoft says the China-linked threat actor likely gained access by exploiting CVE-2026-18577 in N-able N-central, then used AnyDesk or SimpleHelp, Advanced IP Scanner, and Mimikatz after compromise. The activity marks a shift from the group's earlier Medusa ransomware use and shows a rapid path from access to data exfiltration and ransomware deployment within a few days. N-able later released hotfix 2026.3 HF1/build 2026.3.1.7 for CVE-2026-18577 and urged immediate installation.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 3 src / 8 articles · H score: 49

CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation before the vendor’s emergency fix. N-able said the flaw stems from an incomplete patch path for CVE-2026-18556, and that 2026.3.1.7 is the first unaffected release after an alternate bypass left 2026.3 insufficient. CISA added the issue to KEV on August 5, 2026, and Microsoft later linked recent attacks to Storm-1175 likely exploiting CVE-2026-18577 before deploying StormEncryptor and using AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz.

Atlassian Rovo crafted-link prompt injection security flaw

Vulnerability

Updated: 10.08.2026 18:30 · First: 10.08.2026 18:30 · 📰 1 src / 1 articles · H score: 0

Atlassian Rovo had a crafted-link prompt injection flaw that could seed attacker instructions into an authenticated session and let the assistant’s browsing agent move company data to the public web. Varonis Threat Labs disclosed the issue as RovoBlast on August 7, and Atlassian fixed it after the report. The flaw affected Rovo across connected enterprise services, creating exposure for organizations that relied on the assistant’s browsing and research features.

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave

Updated: 03.08.2026 13:39 · First: 03.08.2026 13:39 · 📰 2 src / 2 articles · H score: 24

SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root escalation used against exposed appliances. SonicWall patched the flaws on July 14, and CISA added both to KEV the same day after exploitation was confirmed. INC Ransomware has been the most active group in the wider campaign, while Volexity said UTA0533 began exploiting the flaws as early as June 22 to deploy KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.

Prime Slider unescaped HTML attribute security flaw

Vulnerability

Updated: 10.08.2026 17:30 · First: 10.08.2026 17:30 · 📰 1 src / 1 articles · H score: 17

Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-admin page loads. The issue was introduced on March 1 and was still unpatched at publication.

Ghostjacking AI hijacking attack using trusted logs and alerts

Technical Analysis

Updated: 10.08.2026 15:59 · First: 10.08.2026 15:59 · 📰 1 src / 1 articles · H score: 30

Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk of DNS takeover, code execution, and credential theft across widely used integrations.

Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls

Technical Analysis

Updated: 10.08.2026 13:45 · First: 10.08.2026 13:45 · 📰 2 src / 2 articles · H score: 39

Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assistants through trusted logs and alerts. The attack was shown against Cloudflare, Datadog, and Sentry, where it could drive DNS changes, code execution, and cloud credential theft in demo scenarios. Tenet said the technique worked 9 times out of 10 against Claude Code on Cloudflare’s recommended setup, and that a related Claude Desktop flaw could exfiltrate data; Anthropic fixed that flaw without issuing a CVE.

Justin Swaddle sentencing in The Com sextortion case

Law Enforcement

Updated: 10.08.2026 15:56 · First: 10.08.2026 15:56 · 📰 1 src / 1 articles · H score: 13

Leeds Crown Court sentenced Justin Swaddle to two years in prison for blackmail and sextortion tied to The Com, extending criminal accountability in a case that reached nearly 120 victims worldwide. The UK National Crime Agency identified 117 female victims aged 13 to 17, and seized-device evidence showed coercion, threats, and abusive material. Swaddle had been arrested by West Yorkshire Police in October 2023 and later pleaded guilty on July 2.

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation

Updated: 10.08.2026 15:25 · First: 10.08.2026 15:25 · 📰 1 src / 1 articles · H score: 31

Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication abuse on Windows systems. Microsoft said it has applied mitigations and that defenders should install the applicable security updates. The guidance also calls for least-privilege access, phishing-resistant authentication, and stronger endpoint protections. The advisory ties the response to a vendor CVSS 6.5 issue and a broader hardening push across authentication methods.

Gunra ransomware mitigation advisory (CISA/FBI/partners)

Advisory/Mitigation

Updated: 10.08.2026 15:00 · First: 10.08.2026 15:00 · 📰 1 src / 1 articles · H score: 38

CISA, FBI, DC3, NSA, USSS, and KNPA issued #StopRansomware: Gunra Ransomware to give organizations detection guidance, IOCs, and mitigation recommendations for Gunra ransomware risk. The advisory targets critical infrastructure sectors worldwide, including healthcare, financial services, government services and facilities, and professional and nonprofit services. It links the threat to exploitation of CVE-2024-55591 and CVE-2025-24472 on internet-facing devices and warns of double extortion. Defenders are told to urgently mitigate vulnerabilities, prioritize patching known exploited vulnerabilities, and align controls to CPGs.

Gunra ransomware CVE exploitation and double-extortion activity

Malware Activity

Updated: 10.08.2026 15:00 · First: 10.08.2026 15:00 · 📰 1 src / 1 articles · H score: 38

The Gunra ransomware activity is actively exploiting CVE-2024-55591 and CVE-2025-24472 to reach internet-facing devices, putting victim systems and data at immediate risk. Once inside, the operators use double extortion to steal data and encrypt files. Victims are threatened with publication through a Tor-based portal if ransom is not paid within five to seven days. The activity spans critical infrastructure and multiple sectors worldwide.

Valve Steam hardware customer shipping data leak via CEVA Logistics

Data Leak

Updated: 10.08.2026 14:47 · First: 10.08.2026 14:47 · 📰 1 src / 1 articles · H score: 26

Valve disclosed a shipping-data leak affecting Steam hardware customers in Europe after attackers accessed CEVA Logistics systems. The exposed records include names, addresses, phone numbers, email addresses, and ordered product details, creating a real risk of phishing and delivery scams. The breach covered information gathered to ship hardware orders and was linked to access that occurred between July 29 and August 1, 2026.

CEVA Logistics hit by cyberattack

Incident

Updated: 10.08.2026 14:47 · First: 10.08.2026 14:47 · 📰 1 src / 1 articles · H score: 33

CEVA Logistics faced a cyberattack that disrupted operations at eight European warehouses, forcing the shipping provider to isolate affected systems and bring in outside investigators. The incident affected logistics operations for Europe-based customers and remained under active review after the attack window of July 29 to August 1, 2026. The disclosure increases the risk of operational disruption and supply-chain fallout for affected retailers and shipment recipients.

TrueConf Server actively exploited arbitrary code execution and sandbox escape flaws security flaw

Vulnerability

Updated: 08.08.2026 17:16 · First: 08.08.2026 17:16 · 📰 2 src / 2 articles · H score: 42

TrueConf Server vulnerabilities KLCERT-26-057 and KLCERT-26-058 were exploited in July 2026 by Head Mare against unpatched Russian companies using exposed TCP port 4307. The chain let attackers run code as NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a poisoned build. That activity delivered PhantomCore and PhantomGraph; the latter used SysExcSvc.dll and SysReadSvc.dll with Microsoft OneDrive as C2, and Kaspersky said the vendor patched affected releases on June 18, 2026.

OFAC sanctions Shelbit crypto network

Regulatory/Legal Action

Updated: 10.08.2026 12:00 · First: 10.08.2026 12:00 · 📰 1 src / 1 articles · H score: 37

OFAC sanctioned Shelbit, founder Siavash Kayvanpour, and affiliated entities in a move targeting an alleged $6bn illicit crypto network tied to IRGC wallets and sanctions evasion. The action also named Aban Tether and entities across the UAE, Poland, and Georgia. It tightens enforcement pressure on a cross-border blockchain conduit that authorities say was used for illicit finance.

Solidity Pro VS Code extension browser wallet and credential stealer

Malware Activity

Updated: 10.08.2026 10:38 · First: 10.08.2026 10:38 · 📰 1 src / 1 articles · H score: 30

The Solidity Pro VS Code extension is now flagged as a browser wallet and credential stealer, exposing VS Code users to crypto theft and account compromise. Early versions 1.0.0 through v2.4.x fetched and ran an encrypted payload from Cloudflare Workers, while v3.0.0 and later versions shifted to broader credential theft. The stealer can harvest browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. It then exfiltrates the loot through a Telegram bot and uses heavy obfuscation plus delayed activation to evade review and sandboxing.

Head Mare multi-sector campaigns targeting Russian organizations

Campaign

Updated: 08.08.2026 17:16 · First: 08.08.2026 17:16 · 📰 1 src / 1 articles · H score: 34

Multiple Head Mare campaigns are active against Russian organizations across several sectors, using phishing, public-facing web server exploitation, and contractor access to broaden intrusion opportunities. The operation increases the risk of repeat compromise across instrumentation, electronics, transportation, energy, IT, and software development organizations.

Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw

Vulnerability

Updated: 08.08.2026 11:54 · First: 08.08.2026 11:54 · 📰 1 src / 1 articles · H score: 1

The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-app data the signed-in user could access. Varonis Threat Labs independently confirmed the one-click link route, and Atlassian closed that path server-side on July 8, 2026. The flaw turned permitted access into an outbound data leak without requiring the victim to intentionally share the data.

Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft

Technical Analysis

Updated: 08.08.2026 11:03 · First: 08.08.2026 11:03 · 📰 1 src / 1 articles · H score: 30

PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The disclosure includes proof-of-concept chains for password capture, token theft, click hijacking, and AI-email prompt injection. Several paths were still working when published, while others had already been fixed or stopped working on retest.

Metabase unauthenticated SQL injection zero-day actively exploited SQL injection flaw

Vulnerability

Updated: 07.08.2026 23:14 · First: 07.08.2026 23:14 · 📰 2 src / 2 articles · H score: 49

A Metabase unauthenticated SQL injection zero-day put Metabase Cloud and self-hosted installations at risk of administrator takeover, credential theft, and data export. The flaw affected versions 1.58 and above and was confirmed actively exploited before disclosure on Aug. 7, 2026. Metabase said it blocked the attack endpoints and rolled out a fix for the vulnerability. Organizations running exposed self-hosted installs were told to upgrade immediately or temporarily block `/api/session/reset_password` while applying the patch.

N-able security patch release for CVE-2026-18577

Security Patch Release

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 3 articles · H score: 46

N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3.1.7 for all versions before 2026.3, after earlier investigation found remote administrative access on servers running 2026.1 and earlier. N-able says hosted deployments already received the update, while on-premises customers must install it manually. The company also provided IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

N-able N-central servers hit by network compromise

Incident

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 3 src / 5 articles · H score: 41

N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take Control and Cloudflared services. N-able said the activity affected a limited number of customers, began with signs of abuse on August 1, and led to CVE-2026-18577 and the emergency release of hotfix 2026.3.1.7 as the first unaffected version. CISA later added CVE-2026-18577 to KEV after reports of active exploitation, and published indicators include four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

Framework customer data leak from compromised Metabase instance

Data Leak

Updated: 07.08.2026 23:14 · First: 07.08.2026 23:14 · 📰 1 src / 1 articles · H score: 35

Framework confirmed a customer data leak after attackers compromised its Metabase instance, exposing personal and business records tied to customers. The stolen data included full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company names. The exposure raises risk of phishing, account targeting, and identity abuse for affected customers.

Unlimited Technology Systems hit by ransomware attack

Incident

Updated: 07.08.2026 22:30 · First: 07.08.2026 22:30 · 📰 1 src / 1 articles · H score: 60

Unlimited Technology Systems disclosed a data breach that exposed personal information for 3,803,750 people after an unauthorized actor accessed files in its commercial data center. The intrusion is tied to activity between October 5 and October 10, 2025, and the company later confirmed the exposure in July 2026. The breach involved sensitive patient data handled for healthcare providers, increasing identity-theft and privacy risk. The company said no ransomware or data-extortion group has publicly claimed responsibility.

WEL1DROPPER cross-platform RAT and infostealer delivery chain

Malware Activity

Updated: 07.08.2026 21:48 · First: 07.08.2026 21:48 · 📰 1 src / 1 articles · H score: 36

The WEL1DROPPER malware chain is delivering RAT and infostealer payloads through nearly 800 malicious npm packages, expanding cross-platform risk for Windows, macOS, and Linux systems. The packages use a README-driven require() path to trigger the loader, which fingerprints the host and retrieves a matching payload from Cloudflare Workers or fallback wel1[.]ru domains. On Windows, the final stage includes ETW/AMSI patching, sandbox checks, and persistence via a Registry Run key and scheduled task. On Linux, the chain can deploy Sliver, an open-source C2 framework, showing the loader is part of a broader malicious distribution operation.

Flooding Dropper malicious npm package campaign targeting Windows, Mac, and Linux

Campaign

Updated: 07.08.2026 21:48 · First: 07.08.2026 21:48 · 📰 1 src / 1 articles · H score: 44

A new npm supply-chain campaign has published nearly 800 malicious packages to push RAT and infostealer payloads onto Windows, Mac, and Linux systems. The packages use a README-driven require() path instead of the more common lifecycle-hook trigger, which helps the delivery blend into normal developer workflows. The operation is tracked as Flooding Dropper and appears to extend a prior Moika package-publishing pattern. The malware chain uses Cloudflare Workers, wel1[.]ru DNS TXT delivery, and platform-specific payloads to reach infected hosts.