Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:27 04/08/2026 UTC
Last updated: 22:19 03/08/2026 UTC

Latest updates

Browse →

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity

Updated: 04.08.2026 22:03 · First: 04.08.2026 22:03 · 📰 1 src / 1 articles · H score: 30

XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data exfiltration. The malware is injected into benign project files and can execute when developers build the project, turning infected projects into a propagation path. The latest version adds a Chrome hijacker and Telegram trojanizer while expanding its evasion techniques. Its module set includes credential theft, keystroke logging, browser hijacking, and data exfiltration.

Open VSX evil twin extension data-harvesting campaign

Campaign

Updated: 04.08.2026 21:50 · First: 04.08.2026 21:50 · 📰 1 src / 1 articles · H score: 38

The Open VSX marketplace hosted 77 counterfeit extensions in an evil twin campaign that impersonated legitimate developer tools and sent environment data to an attacker-controlled server. The operation mattered because the packages harvested host, workspace, Git, and CI metadata from developer systems at scale, with 19 extensions collecting deeper reconnaissance. Researchers tied the packages together through shared infrastructure and behavior, and the counterfeit listings were later removed from the marketplace.

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta

Updated: 04.08.2026 20:27 · First: 04.08.2026 20:27 · 📰 1 src / 1 articles · H score: 39

Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targeting cloud accounts. The service now combines AiTM credential theft, OAuth consent abuse, and multiple target platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace. That shift lowers the barrier to entry for affiliates and increases the scale and persistence of account compromise.

WhatsApp linked-devices voting scam campaign

Campaign

Updated: 04.08.2026 17:30 · First: 04.08.2026 17:30 · 📰 1 src / 1 articles · H score: 34

A WhatsApp scam campaign is using hijacked accounts and a fake contest-vote lure to get victims to authorize an attacker-controlled linked device, giving the operator full messaging access. Messages arrive from compromised contacts and route targets to pages that mimic WhatsApp or the wa.me flow. Once the link is added, attackers can read messages, send messages as the account holder, and push the same scam to the victim's contacts. The abuse avoids password prompts, so it can remain hidden unless users review linked devices.

Varonis Atlas adds Agent Intent-Based Access Control for AI agent runtime guardrails

Security Tool/Service

Updated: 04.08.2026 17:00 · First: 04.08.2026 17:00 · 📰 1 src / 1 articles · H score: 11

Varonis Atlas added Agent Intent-Based Access Control (IBAC), giving enterprises runtime guardrails for AI agents that access sensitive data and tools. The capability compares an agent’s instruction, reasoning, tool calls, and data access in real time and can alert, block, modify, log, route for approval, or quarantine sessions. The launch targets the growing risk of agents drifting beyond their intended scope or touching data they should not reach.

Shai-Hulud credential-stealing npm worm spreading through poisoned package releases

Malware Activity

Updated: 04.08.2026 16:30 · First: 04.08.2026 16:30 · 📰 1 src / 1 articles · H score: 37

A credential-stealing npm worm spread through poisoned package releases on August 4, 2026, exposing developer and CI credentials and broadening supply-chain risk. The activity began with [email protected] and quickly extended beyond the original namespace into hundreds of packages.

AI coding-assistant guardrail bypass analyzed through recovered threat-actor prompt logs

Technical Analysis

Updated: 04.08.2026 16:30 · First: 04.08.2026 16:30 · 📰 1 src / 1 articles · H score: 23

Researchers found that threat actors are bypassing commercial AI safety controls by splitting malicious work across multiple sessions and files, reducing the chance any single request looks harmful. Cisco Talos recovered the behavior from prompt logs on threat-actor endpoints using Claude Code, Codex, Cursor and Gemini, and found guardrails offered little protection across platforms. The same operators also used false claims of owning infrastructure and CTF/bug bounty framing to keep the assistant engaged in abuse. The pattern weakens AI-assisted defense boundaries by showing how easily intent can be fragmented, normalized, and persisted across sessions.

Obsidian Security adds native governance controls for Claude Code and Cowork

Security Tool/Service

Updated: 04.08.2026 15:00 · First: 04.08.2026 15:00 · 📰 1 src / 1 articles · H score: 19

Obsidian Security expanded its agent governance platform with native controls for Claude Code and Cowork, tightening enterprise oversight of AI-agent access to production data and sensitive files. The update adds enforcement to restrict permissions and block unauthorized MCP/tool usage before risky actions can execute. It extends runtime governance across third-party business systems where agent-to-backend links can create privilege-escalation and policy-violation exposure.

Obsidian Security raises $85 million Series D

Commercial Activity

Updated: 04.08.2026 15:00 · First: 04.08.2026 15:00 · 📰 1 src / 1 articles · H score: 19

Obsidian Security raised $85 million in a Series D at a $1.1 billion valuation, adding capital to expand its agentic AI security business. The round lifts total funding to more than $200 million and supports broader governance for AI agents in enterprise apps. The company said the funds will help it add controls around Claude Code and Cowork to reduce unauthorized access and policy violations.

Cloud and SaaS targeting shifts toward identity, email auth, and non-human accounts in H1 2026

Trend

Updated: 04.08.2026 14:30 · First: 04.08.2026 14:30 · 📰 1 src / 1 articles · H score: 28

Cloud and SaaS environments became top targets in H1 2026, with attackers shifting from malware and vulnerability exploitation toward identity compromise and trust-layer abuse. The trend expands risk across email authentication, cloud entitlements, supply chains, AI gateways, remote administration tooling, and non-human identities.

Google ADK Python repository workflow prompt-injection security flaw

Vulnerability

Updated: 04.08.2026 14:16 · First: 04.08.2026 14:16 · 📰 1 src / 1 articles · H score: 34

Google's ADK Python repository workflows had a prompt-injection flaw that let a public GitHub issue steer a trusted triage bot into a privileged code-fixing path. Researchers showed the chain could reach the CI runner, execute arbitrary code, and expose the bot PAT and cloud credentials. Google removed issue-analyze.yml, issue-fix.yml, and pr-analyze.yml after the proof of concept; the record does not show in-the-wild exploitation.

17 African countries enact or amend cybercrime legislation

Public Sector Action

Updated: 04.08.2026 13:00 · First: 04.08.2026 13:00 · 📰 1 src / 1 articles · H score: 31

Seventeen African countries enacted or amended cybercrime legislation, expanding the region’s formal policy response to cybercrime and supporting cross-border coordination. Regional capacity-building continued alongside the legal changes, strengthening implementation across the continent. The move adds a broader public-sector foundation for cybercrime prevention, investigation, and cooperation.

AI-driven cybercrime surge across Africa drives losses, sextortion, and scam-center prevalence

Trend

Updated: 04.08.2026 13:00 · First: 04.08.2026 13:00 · 📰 1 src / 1 articles · H score: 32

AI-driven cybercrime has become a dominant digital-crime pattern across Africa, accounting for 55% of reported cases and driving higher losses, sextortion, and scam activity.

Police National Legal Database (PNLD) hit by network compromise

Incident

Updated: 03.08.2026 12:13 · First: 03.08.2026 12:13 · 📰 3 src / 3 articles · H score: 45

The Police National Legal Database (PNLD) suffered a data security incident that exposed names, organizations, and work email addresses for police officers, police staff, criminal justice professionals, government partners, and customers, with the data later published on the dark web. PNLD said the issue was identified on July 26 and that there was no evidence passwords or other security credentials were compromised. The incident also affected Ask the Police, where some names and email addresses from prior question submissions were exposed. The extortion group ExfilSquad claimed responsibility and said it held 1.9GB of data and 135,000 records.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 3 articles · H score: 41

CVE-2026-18577 is an authentication bypass in N-able N-central affecting hosted and on-premises servers before 2026.3. N-able said it detected active exploitation on August 1 and released hotfix 2026.3.1.7 on August 2, urging customers to upgrade immediately. The vendor said the issue stems from an incomplete patch for CVE-2026-18576, and it published IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder. Huntress separately reported exploitation tied to one partner account, nine organisations, and one endpoint in each, with observed post-compromise activity limited to process enumeration.

N-able N-central servers hit by network compromise

Incident

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 3 articles · H score: 40

N-able N-central servers were hit by an authentication bypass compromise that let attackers gain remote administrative access and persist on managed endpoints through Take Control and Cloudflared services. CVE-2026-18577 affects hosted and on-premises N-central deployments, and N-able said hotfix 2026.3.1.7 is the first unaffected release. The vendor said it detected active exploitation on August 1 and urged immediate upgrading, while published IOCs include four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign

Campaign

Updated: 04.08.2026 03:17 · First: 04.08.2026 03:17 · 📰 1 src / 1 articles · H score: 37

Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware. The attackers manipulate DNS/HTTP traffic on captive portal equipment to redirect hotel and conference-center users to phishing pages and device-code phishing flows. Microsoft says the campaign has been active since early May, with related phishing activity running since February and observed since July. The operation also uses CornFlake and ChocoShell for persistence, credential theft, surveillance, and exfiltration.

Pass-ta-key attacks against Google Password Manager on Windows TPM devices

Technical Analysis

Updated: 04.08.2026 02:58 · First: 04.08.2026 02:58 · 📰 1 src / 1 articles · H score: 23

Pass-ta-key identifies three attacks that let malware on already-compromised Windows devices abuse Google Password Manager synced passkeys. The techniques can impersonate a trusted device, bypass user verification, and in the most severe case recover the security domain secret used to protect synced credentials. The findings show that passkeys still depend on device integrity and on services correctly validating verification signals. They also shift defensive attention to Chrome device trust, recovery flows, and browser-memory exposure on TPM-backed endpoints.

DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages

Campaign

Updated: 03.08.2026 23:01 · First: 03.08.2026 23:01 · 📰 1 src / 1 articles · H score: 39

The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into running malicious commands, expanding malware-delivery risk across SaaS users. The lure pages rely on embedded iframes and browser-cache abuse to move victims into the payload chain. The operation is part of a broader DOUBLECUP service model that lets customers build and launch these attack pages.

DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity

Malware Activity

Updated: 03.08.2026 23:01 · First: 03.08.2026 23:01 · 📰 2 src / 2 articles · H score: 22

DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoader and a previously undocumented DeviceManager RAT. SOCRadar says the service provides licenses, a client agent, session and signal endpoints, encryption keys, and campaign-building tooling, while operators host lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce. The payload chain adds persistence, system collection, and C2 channels, including EtherHiding, HTTP, and DNS tunneling.

DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS

Threat Actor Meta

Updated: 03.08.2026 23:01 · First: 03.08.2026 23:01 · 📰 2 src / 2 articles · H score: 28

DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplies licenses, a Go-based Windows builder/client, and backend functions that generate campaign code, manage steganographic PNG delivery, and support operators who embed the required code in their ClickFix landing pages. Campaigns tied to the service have impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages and delivered CountLoader for Windows and macOS plus a DeviceManager RAT for Windows. The service lowers the barrier for browser-based malware delivery by combining cache-based staging, operator tooling, and EtherHiding-backed C2 handling.

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity

Updated: 03.08.2026 22:25 · First: 03.08.2026 22:25 · 📰 2 src / 2 articles · H score: 30

Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims running xeno.exe and then an obfuscated Java payload disguised as decompiler.exe. The malware chain checks for a Java Runtime Environment, loads the final payload, and delivers a Java-based RAT and information stealer that can steal browser cookies, account tokens, crypto-wallet data, and provide remote access through PowerShell and an interactive shell. Bitdefender said the activity has been ongoing since the start of 2026, with a surge in the second half of March. The payload also targets Chrome, Edge, Brave, Opera, Vivaldi, Discord, Minecraft, and Exodus Wallet data, and includes keylogging, screenshot capture, webcam access, desktop streaming, and file manipulation.

Roblox fake Xeno Executor installer campaign

Campaign

Updated: 03.08.2026 22:25 · First: 03.08.2026 22:25 · 📰 2 src / 2 articles · H score: 36

The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running xeno.exe, which starts a loader chain ending in a Java-based RAT and information stealer. The payload can harvest browser cookies, Discord, Roblox, and Minecraft account data, along with cryptocurrency-wallet data, payment information, and other sensitive files. Researchers said the activity has been ongoing since the start of 2026, with a surge in the second half of March. The same reporting also notes it can record keystrokes, capture screenshots and webcam footage, stream the desktop, and allow remote shell access, extending the compromise beyond initial theft.

Xanadu hit by network compromise

Incident

Updated: 03.08.2026 21:43 · First: 03.08.2026 21:43 · 📰 1 src / 1 articles · H score: 34

Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configurations at risk. The rogue package turned routine imports into credential theft and sent data to metrics.femboy[.]energy. Attackers appear to have probed the project’s self-hosted CI runners to recover publishing secrets before pushing the malicious version. The compromise raises follow-on access risk for a research and HPC environment that relies on the library.

Alibaba developer tools npm supply-chain espionage campaign

Campaign

Updated: 03.08.2026 21:43 · First: 03.08.2026 21:43 · 📰 1 src / 1 articles · H score: 44

A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compromise. Malicious packages impersonate private @ali-scoped dependencies and use a layered delivery chain to hide loader logic. The operation spans March and April 2026 and is aimed at Chinese-speaking developers in Alibaba-linked environments.

Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users

Malware Activity

Updated: 03.08.2026 21:43 · First: 03.08.2026 21:43 · 📰 1 src / 1 articles · H score: 37

Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-speaking environments at risk of backdoor access. The packages impersonate private @ali-scoped components and use decoy wrappers to activate hidden dependencies. The final payload supports command execution, file upload/download, host reconnaissance, payload staging, and lateral movement, raising the impact of the supply-chain compromise.

N-able security patch release for CVE-2026-18577

Security Patch Release

Updated: 03.08.2026 09:41 · First: 03.08.2026 09:41 · 📰 2 src / 2 articles · H score: 41

N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3.1.7 for all versions before 2026.3, after earlier investigation found remote administrative access on servers running 2026.1 and earlier. N-able says hosted deployments already received the update, while on-premises customers must install it manually. The company also provided IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis

Updated: 03.08.2026 19:24 · First: 03.08.2026 19:24 · 📰 1 src / 1 articles · H score: 3

Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or mint passkey authentication material. The methods, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, abuse Chrome's device-key handling, re-enrollment flow, and synced-secret handling rather than breaking cryptography. The strongest path targets the 32-byte Security Domain Secret (SDS) that protects synced passkeys, creating reusable access risk after an initial compromise.

Visa acquires BioCatch for fraud intelligence expansion

Industry Action

Updated: 03.08.2026 18:32 · First: 03.08.2026 18:32 · 📰 1 src / 1 articles · H score: 55

Visa agreed to acquire BioCatch for $2.4 billion in cash, consolidating cyber and fraud-detection capabilities in the payments sector. The deal adds behavioral biometrics to Visa's security portfolio and broadens its reach in financial crime detection. Closing is expected by the end of Visa’s fiscal second quarter of 2027, pending approvals.

BTMOB Android RAT malware-as-a-service activity

Malware Activity

Updated: 03.08.2026 17:45 · First: 03.08.2026 17:45 · 📰 1 src / 1 articles · H score: 27

The BTMOB Android RAT kept being sold and updated as a malware-as-a-service package across 2025-2026, extending its reach and increasing the risk of information theft and remote control on Android phones. The operation also splintered into a broader underground market with resellers, source-code sellers, and independent administrators. Official releases continued while cheaper lookalike offers and Telegram sales campaigns pushed access, infrastructure, and code.