Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 16:23 12/08/2026 UTC
Last updated: 15:09 12/08/2026 UTC

Latest updates

Browse →

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign

Updated: 12.08.2026 16:35 · First: 12.08.2026 16:35 · 📰 2 src / 2 articles · H score: 22

Lazarus expanded Operation Dream Job into a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and abused compromised Roundcube instances to hide communications, while Check Point tied the latest wave to Troy, RelayShell, and a FudModule variant that incorporated CVE-2026-68820. Microsoft patched CVE-2026-68820 in this month's Patch Tuesday and marked it actively exploited. Check Point also reported that the exploit supported Windows 11 builds 26100 and 26200 and that at least 17 servers were infected with RelayShell.

SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 19:47 · First: 11.08.2026 19:47 · 📰 3 src / 3 articles · H score: 45

CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an administrator, on affected on-premises systems. Researchers also chained it to CVE-2026-63520 to reach code execution without credentials. SharePoint Server Subscription Edition, 2019, and 2016 are affected, while SharePoint Online is not listed, and the July update is said to break the chain.

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity

Updated: 12.08.2026 17:30 · First: 12.08.2026 17:30 · 📰 1 src / 1 articles · H score: 19

The WindRelay malware chain turned a 13-minute phone call into live card fraud, relaying a victim’s card data to a fake terminal and helping an operator take out a loan in the victim’s name. The activity paired WindRelay with SpyNote RAT to gain remote access on Android devices and install the relay tool while the victim stayed on the line. Group-IB linked the malware to 23 samples uploaded between November 2025 and July 2026, with impersonation themes tied to institutions in Czechia, Slovakia and Slovenia.

AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload

Malware Activity

Updated: 12.08.2026 17:09 · First: 12.08.2026 17:09 · 📰 1 src / 1 articles · H score: 11

The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every update and uninstall, creating repeated browser-tab redirection for users. The poisoned code landed in versions 1.7.2.0 and 1.7.3.0 through Google's CRX content delivery network on July 31, 2026. The same release also suppresses DeepSeek redirection to ChatGPT, showing a deliberate change in extension behavior.

Malicious VPN and proxy extension campaign targeting Russian-speaking users

Campaign

Updated: 12.08.2026 17:09 · First: 12.08.2026 17:09 · 📰 1 src / 1 articles · H score: 21

A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations, source IPs, and TLS SNI values. The operation spans at least 40 Chrome Web Store developer accounts and impersonates 66 VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, and ExpressVPN. The scale of installation activity and the large number of still-active add-ons indicate the operation remains ongoing.

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release

Updated: 11.08.2026 21:08 · First: 11.08.2026 21:08 · 📰 3 src / 3 articles · H score: 39

Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active exploitation and can let a local attacker escalate to SYSTEM. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign against defense and aerospace companies in Europe and India. The latest analysis says the malware negotiated its command channel with a post-quantum key exchange before pulling down the exploit, then loaded FudModule v3.1 through MISTPEN with layered encryption. The same infrastructure also used RelayShell, impersonation sites for Enveil, and a backdoor called Troy.

City-Forum Salesforce and ServiceNow guest-user exploitation campaign

Campaign

Updated: 12.08.2026 16:00 · First: 12.08.2026 16:00 · 📰 1 src / 1 articles · H score: 34

The City-Forum campaign is actively targeting Salesforce and ServiceNow with a custom multi-platform toolset, enabling guest-user enumeration and content exfiltration across multiple sectors. The operation is focused on telecoms, banks and financial-services firms, enterprise-software vendors, and public-sector portals. A fixed infrastructure node has remained active since March 2025, suggesting sustained and stealthy activity.

OpenAI Anthropic and Google reasoning APIs cross-session replay security flaw

Vulnerability

Updated: 12.08.2026 14:47 · First: 12.08.2026 14:47 · 📰 1 src / 1 articles · H score: 36

A newly disclosed cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs exposed hidden reasoning and secrets from session logs, including API keys and passwords. The weakness let opaque reasoning blocks move across sessions, users, and compatible models, turning preserved reasoning state into a secret-extraction risk. Researchers said the demonstrated attacks stopped working after mitigations in August 2026.

Perimeter prevention is recovering while post-compromise defenses lag across enterprise environments

Trend

Updated: 12.08.2026 14:41 · First: 12.08.2026 14:41 · 📰 1 src / 1 articles · H score: 26

First-half 2026 simulations show perimeter prevention recovering, but post-compromise controls still fail against quiet attacker behavior across enterprise environments. Average prevention effectiveness rose from 62% to 69%, while logging reached 58% and the alert score stayed at 14%. Once an intruder is inside, reconnaissance is blocked only 10% of the time and credential theft from memory or the registry often slips through. The result is a defense trend that favors noisy attacks at the edge and leaves low-noise breach preparation underprotected.

Signal launches Automatic Key Verification for encrypted chat key verification

Security Tool/Service

Updated: 12.08.2026 14:21 · First: 12.08.2026 14:21 · 📰 1 src / 1 articles · H score: 11

Signal launched Automatic Key Verification, adding key transparency checks that help users confirm encrypted chats have not been intercepted and reduce man-in-the-middle and key-swapping risk across its messaging ecosystem.

Adobe security patch release for CVE-2026-71398

Security Patch Release

Updated: 11.08.2026 19:50 · First: 11.08.2026 19:50 · 📰 2 src / 2 articles · H score: 37

Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The flaws could allow arbitrary code execution, and administrators were advised to install the update promptly. A later report described the same patch as part of a broader Adobe update cycle that also covered ColdFusion and Commerce. For Campaign Classic, the fix is tied to ACC v7 7.4.4 build 9400 and applies to fully on-premise deployments and the on-premise components of hybrid deployments.

VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)

Vulnerability

Updated: 12.08.2026 12:01 · First: 12.08.2026 12:01 · 📰 1 src / 1 articles · H score: 47

CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitation has now been observed shortly after Broadcom's late-July patch release, raising urgency for exposed vCenter servers. QUIRSO linked the activity to an intrusion chain that used path traversal and then reverse_ssh for persistence and outbound access.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave

Updated: 12.08.2026 12:01 · First: 12.08.2026 12:01 · 📰 1 src / 1 articles · H score: 46

Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence. The wave has reached 361 unique victim IP addresses across 47 countries, with attackers using path traversal followed by a malicious cron job and reverse_ssh to hold access. Activity began on August 3, shortly after disclosure, indicating rapid post-patch abuse of vulnerable appliances.

SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release

Security Patch Release

Updated: 12.08.2026 10:31 · First: 12.08.2026 10:31 · 📰 1 src / 1 articles · H score: 37

SAP released patches for Commerce Cloud (Data Hub Adapter) to fix CVE-2026-58231, a CVSS 10.0 flaw that could let an unauthenticated attacker reach arbitrary code execution. The issue stems from insufficient authorization checks and input validation failures in vulnerable functions. Onapsis urged customers to move to a fixed Commerce Cloud release and re-deploy the updated version. A temporary IP Filter Set workaround can restrict access to the vulnerable endpoint until patching is complete.

Microsoft security patch release for CVE-2026-62832

Security Patch Release

Updated: 12.08.2026 09:41 · First: 12.08.2026 09:41 · 📰 2 src / 2 articles · H score: 5

Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release covers CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. CVE-2026-68820 is marked actively exploited and was added to CISA KEV, with federal agencies required to apply the fix by August 25, 2026.

CISA adds CVE-2026-68820 to KEV catalog

Public Sector Action

Updated: 12.08.2026 09:41 · First: 12.08.2026 09:41 · 📰 1 src / 1 articles · H score: 3

CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by August 25, 2026. The action formalizes the vulnerability as an official remediation priority and sets a concrete compliance deadline. It affects federal defenders responsible for Windows patching and vulnerability response.

Google Chrome expands Android notification anti-abuse controls with automatic permission revocation and rate limiting

Security Tool/Service

Updated: 12.08.2026 04:15 · First: 12.08.2026 04:15 · 📰 1 src / 1 articles · H score: 14

Google Chrome expanded its anti-abuse systems for Android notifications, reducing unwanted notification volume by more than 7 billion per day in Q1 2026. The controls now include automatic notification permission revocation for stale or suspicious sites and rate limiting for disruptive senders, cutting off deceptive notification traffic before it reaches users. The changes also target abuse tied to scams, malware, phishing attempts, and fraudulent payment requests.

Microsoft security patch release for CVE-2026-68820

Security Patch Release

Updated: 12.08.2026 00:28 · First: 12.08.2026 00:28 · 📰 3 src / 3 articles · H score: 23

Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes CVE-2026-68820, an actively exploited privilege-escalation zero-day in Windows Ancillary Function Driver for WinSock (AFD.sys) that can raise a locally authenticated user to SYSTEM. Microsoft also flagged CVE-2026-62832 as likely to be exploited and CVE-2026-72971 as a publicly disclosed lower-impact flaw.

Cisco Secure Firewall ASA and FTD active DoS exploitation denial-of-service flaw (CVE-2026-20349)

Vulnerability

Updated: 11.08.2026 22:45 · First: 11.08.2026 22:45 · 📰 2 src / 2 articles · H score: 31

CVE-2026-20349 is being actively exploited against Cisco Secure Firewall ASA and FTD software, enabling crafted HTTP requests to trigger a remote denial of service on devices with certain remote access services enabled. Cisco has released hot fixes for affected releases and says there is no workaround other than upgrading to a fixed version.

Zoom annotation tool flaws (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 22:08 · First: 11.08.2026 22:08 · 📰 1 src / 1 articles · H score: 24

Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Windows, Zoom Rooms, and Zoom Meeting SDK builds. The issues are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, covering a buffer over-write, a buffer over-read, and a use-after-free condition. Fixes shipped in June and July 2026 before the public disclosure, and the company says no exploitation has been reported. The affected flows rely on annotation messages in shared-screen meetings, where the receiver trusts the sender enough to rebuild the object in full.

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign

Updated: 11.08.2026 21:36 · First: 11.08.2026 21:36 · 📰 2 src / 2 articles · H score: 32

CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine since at least May 2026. The operation moves targets from job sites to Telegram and Zoom interviews, then pushes a poisoned WireGuard-based client and SourceForge lures tied to SopraVPN and Sopra Steria lookalikes. The malicious client can decrypt and run embedded PowerShell on Windows and fetch another executable through the VPN on Linux, creating a path to malware installation and unauthorized access.

Poisoned WireGuard-derived VPN client used to run commands on victim hosts

Malware Activity

Updated: 11.08.2026 21:36 · First: 11.08.2026 21:36 · 📰 1 src / 1 articles · H score: 20

A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct malware delivery. The modified client is distributed as SopraVPN through fake SourceForge projects and a bogus website. Its configuration handling adds a non-standard SymmetricKey option that decrypts embedded PowerShell before execution. The Windows build can create a scheduled task, while the Linux build uses cURL to fetch a secondary executable.

Delta Air Lines Flight 591 in-flight Wi-Fi disruption

Service Disruption

Updated: 11.08.2026 21:34 · First: 11.08.2026 21:34 · 📰 1 src / 1 articles · H score: 3

Delta Air Lines Flight 591 lost onboard Wi-Fi for nearly 30 minutes after an unauthorized wireless network appeared during the flight from Las Vegas to Atlanta, interrupting passenger connectivity. Delta said the issue did not affect safety or aircraft operating systems. The carrier is investigating the event with federal law enforcement and aviation regulators.

Windows 10 KB5120249 cumulative update (August 2026 Patch Tuesday)

Security Patch Release

Updated: 11.08.2026 21:26 · First: 11.08.2026 21:26 · 📰 1 src / 1 articles · H score: 26

Microsoft released Windows 10 KB5120249 for versions 22H2 and 21H2, making it a mandatory Patch Tuesday update for supported systems. The release fixes security vulnerabilities and bugs and also addresses a File History backup failure on SMB network shares. It additionally expands rollout of new Secure Boot certificates and moves systems to OS Builds 19045.7663 and 19044.7663 after installation.

Windows Ancillary Function Driver for WinSock zero-day privilege escalation (CVE-2026-68820)

Vulnerability

Updated: 11.08.2026 21:08 · First: 11.08.2026 21:08 · 📰 1 src / 1 articles · H score: 29

CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys) was patched after active exploitation in zero-day attacks, leaving affected Windows systems exposed to SYSTEM privilege escalation. Microsoft said a locally authenticated attacker could run a specially crafted application to trigger a race condition and elevate privileges. The flaw was used in intrusions to deploy FudModule, making it a high-risk local escalation issue for Windows administrators.

Adobe security patch release for CVE-2026-48362

Security Patch Release

Updated: 11.08.2026 19:50 · First: 11.08.2026 19:50 · 📰 2 src / 2 articles · H score: 37

Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application DoS. The release names CVE-2026-48362, CVE-2026-48273, and CVE-2026-71384 among the critical issues. Adobe says it is not aware of exploits in the wild and tells users to apply the patches immediately.

Wesco CRM data leak claimed by ExfilSquad

Data Leak

Updated: 11.08.2026 18:59 · First: 11.08.2026 18:59 · 📰 1 src / 1 articles · H score: 50

ExfilSquad claimed it stole and leaked Wesco CRM data, putting customer and employee records and related account information at risk of public exposure. Wesco said it is investigating the cloud CRM environment involved and reported no business disruption. The claim centers on 2.6 million records and a leak-site publication that could expose sensitive business and identity data.

NullReceiver trojanized npm packages C2 via Ethereum recipient address

Malware Activity

Updated: 05.08.2026 16:41 · First: 05.08.2026 16:41 · 📰 2 src / 2 articles · H score: 3

NullReceiver is a malware activity that hides C2 infrastructure inside Ethereum recipient addresses, letting trojanized npm packages decode a server location from a blockchain transfer instead of using a smart contract or calldata. In the broader activity, bianira-ui and fluid-type-ui were published on July 28, 2026 and later removed from npm after limited downloads, while researchers tied the technique to the DPRK-linked Contagious Interview campaign associated with the Lazarus group. New reporting adds six npm packages identified by Sonatype Research Labs on August 10, all carrying the same payload and tracked as sonatype-2026-005899 and sonatype-2026-005901. Sonatype said the loader queried an attacker-controlled Ethereum wallet to recover C2 addresses, and the six packages split between three hijacked publishing accounts and three purpose-built packages.

Cursor command-line coding agent pre-trust command execution security flaw

Vulnerability

Updated: 11.08.2026 17:30 · First: 11.08.2026 17:30 · 📰 1 src / 1 articles · H score: 26

A Cursor vulnerability in the command-line coding agent lets a cloned repository run arbitrary commands before trust verification, creating sandbox-bypassing code-execution risk for developers. Cursor shipped a fix on July 23 after a July 20 report, but the submission was later closed as informative and no advisory was published. The flaw was found in the isolated worktree feature, and affected users should move to build 2026.07.23-e383d2b or later.

Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)

Vulnerability

Updated: 11.08.2026 15:05 · First: 11.08.2026 15:05 · 📰 1 src / 1 articles · H score: 10

CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code execution. Researchers found the capability enabled on 9 of 26 devices and demonstrated takeover on a commercial Autel EV charger. The affected surface includes Quectel EC25/EG25/RM52xN modules and some phones that accepted RUN AT. No attacks have been reported, and vendors are relying on mitigation and hardened defaults rather than a single universal patch.