Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 16:19 13/08/2026 UTC
Last updated: 14:22 13/08/2026 UTC

Latest updates

Browse →

ShipMonk hit by network compromise

Incident

Updated: 13.08.2026 18:13 · First: 13.08.2026 18:13 · 📰 1 src / 1 articles · H score: 43

ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider breach affected order data for nearly 14,000 customers and raised the risk of follow-on phishing and impersonation attempts. Trezor said its own systems were not compromised, but the third-party incident exposed sensitive customer contact and shipping details.

Trezor customers customer data exposed after ShipMonk breach

Data Leak

Updated: 13.08.2026 18:13 · First: 13.08.2026 18:13 · 📰 1 src / 1 articles · H score: 44

A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impersonation. The exposed information included names, shipping addresses, email addresses, phone numbers, and some city data. Trezor systems were not compromised, but affected customers now face heightened fraud exposure.

Google Cloud ships quantum-safe key exchange and publishes post-quantum migration roadmap

Security Tool/Service

Updated: 13.08.2026 18:00 · First: 13.08.2026 18:00 · 📰 1 src / 1 articles · H score: 11

Google Cloud has begun rolling out quantum-safe key exchange and a staged post-quantum migration roadmap, expanding cryptographic protections for cloud services ahead of the 2027-2028 transition window. The update covers Google Cloud API endpoints, application and proxy load balancers, and Cloud KMS, making the platform’s security capabilities ready for post-quantum handshakes and key management. The rollout matters because it reduces exposure to store-now-decrypt-later risk while giving customers a path to validate hybrid deployments without breaking existing applications. Additional services, including Cloud VPN, Interconnect, Private CA, Cloud IAM, and a quantum-safe Cloud HSM, are scheduled to follow.

Adobe Commerce and Magento incorrect authorization flaw (CVE-2026-71362, exploitation attempts detected)

Vulnerability

Updated: 12.08.2026 23:54 · First: 12.08.2026 23:54 · 📰 2 src / 2 articles · H score: 40

CVE-2026-71362 exploitation attempts against Adobe Commerce and Magento are now being blocked, creating customer-account hijack and private-data exposure risk for affected storefronts. The flaw is an incorrect authorization issue that can let an attacker switch one customer session to another account without authentication. Sansec Shield WAF is already stopping observed abuse attempts while administrators are being urged to patch.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave

Updated: 12.08.2026 12:01 · First: 12.08.2026 12:01 · 📰 2 src / 2 articles · H score: 46

Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence. The wave has reached 361 unique victim IP addresses across 47 countries, with attackers using path traversal followed by a malicious cron job and reverse_ssh to hold access. Activity began on August 3, shortly after disclosure, indicating rapid post-patch abuse of vulnerable appliances.

White House NSPM creates NCC cyber-operations program

Public Sector Action

Updated: 13.08.2026 16:30 · First: 13.08.2026 16:30 · 📰 1 src / 1 articles · H score: 31

The White House memo now directs the National Coordination Center (NCC) to create a vetting program for private security companies to conduct limited cyber operations against foreign cybercrime organizations. The framework puts the activity under U.S. government control with compliance review for constitutional, legal, and international-agreement requirements. It is intended to disrupt ransomware, phishing, financial fraud, sextortion, and impersonation scams.

National Security Presidential Memorandum (NSPM) authorized federal law enforcement agencies to collaborate with private firms on offensive cyber strikes for signed August 12

Public Sector Action

Updated: 13.08.2026 15:35 · First: 13.08.2026 15:35 · 📰 1 src / 1 articles · H score: 31

The White House authorized federal law enforcement agencies to work with private firms on offensive cyber strikes against foreign threat actors targeting the US, creating a new government-overseen framework for limited cyber operations. The National Security Presidential Memorandum (NSPM), signed on August 12, formalizes the program and places oversight with the Homeland Security Task Force’s National Coordination Center (NCC). The move expands public-private coordination against transnational cybercrime groups and aims to disrupt attacks affecting US businesses and individuals.

WhatsApp rolls out optional Scam Alert on-device scam warning feature

Security Tool/Service

Updated: 13.08.2026 14:50 · First: 13.08.2026 14:50 · 📰 1 src / 1 articles · H score: 11

WhatsApp has begun rolling out Scam Alert, a new optional security feature that warns users about potential scam messages, raising protection for over 3 billion users. The control runs on-device machine learning and keeps message content on the phone, which reduces privacy exposure while adding scam detection.

ICO reprimand of ACRO for GDPR breach

Regulatory/Legal Action

Updated: 13.08.2026 11:30 · First: 13.08.2026 11:30 · 📰 1 src / 1 articles · H score: 31

The ICO issued a reprimand to ACRO over GDPR infringement tied to a 2023 data breach that affected over 10,000 people. The breach involved unauthorized access to ACRO’s website and content management system (CMS) between August 2022 and March 2023. The exposure included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal-offence information. The reprimand centers on poor patch management and insufficient security monitoring.

Criminal Records Office (ACRO) hit by data theft breach

Incident

Updated: 13.08.2026 11:30 · First: 13.08.2026 11:30 · 📰 1 src / 1 articles · H score: 37

The Criminal Records Office (ACRO) suffered an unauthorized-access breach that exposed sensitive records for 10,920 victims and put criminal-record data at risk. The intrusion ran from August 2022 to March 2023 and affected ACRO’s website and content management system (CMS). Exposed information included National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence data. The breach created lasting privacy and identity-theft risk even though full exfiltration could not be confirmed.

WindRelay and SpyNote RAT Android NFC relay fraud activity

Malware Activity

Updated: 13.08.2026 01:22 · First: 13.08.2026 01:22 · 📰 1 src / 1 articles · H score: 33

The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses a bank-impersonation call, a sideloaded fake app, and Accessibility Service abuse to gain device control before the attacker installs WindRelay and relays NFC card data. Samples seen between November 2025 and July 2026 indicate a sustained malware set, and targeting appears focused on Czechia, Slovakia, and Slovenia.

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign

Updated: 12.08.2026 16:35 · First: 12.08.2026 16:35 · 📰 3 src / 3 articles · H score: 22

Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and LinkedIn recruiter impersonation, then delivered Troy and a FudModule variant that incorporated CVE-2026-68820 and abuse of compromised Roundcube infrastructure. Microsoft patched CVE-2026-68820 in the August 2026 Patch Tuesday and marked it actively exploited. Check Point also reported RelayShell use on at least 17 servers and described additional delivery paths through MISTPEN, DLL sideloading, and a trojanized PDF viewer.

SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 19:47 · First: 11.08.2026 19:47 · 📰 3 src / 3 articles · H score: 45

CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an administrator, on affected on-premises systems. Researchers also chained it to CVE-2026-63520 to reach code execution without credentials. SharePoint Server Subscription Edition, 2019, and 2016 are affected, while SharePoint Online is not listed, and the July update is said to break the chain.

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity

Updated: 12.08.2026 17:30 · First: 12.08.2026 17:30 · 📰 1 src / 1 articles · H score: 19

The WindRelay malware chain turned a 13-minute phone call into live card fraud, relaying a victim’s card data to a fake terminal and helping an operator take out a loan in the victim’s name. The activity paired WindRelay with SpyNote RAT to gain remote access on Android devices and install the relay tool while the victim stayed on the line. Group-IB linked the malware to 23 samples uploaded between November 2025 and July 2026, with impersonation themes tied to institutions in Czechia, Slovakia and Slovenia.

AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload

Malware Activity

Updated: 12.08.2026 17:09 · First: 12.08.2026 17:09 · 📰 1 src / 1 articles · H score: 11

The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every update and uninstall, creating repeated browser-tab redirection for users. The poisoned code landed in versions 1.7.2.0 and 1.7.3.0 through Google's CRX content delivery network on July 31, 2026. The same release also suppresses DeepSeek redirection to ChatGPT, showing a deliberate change in extension behavior.

Malicious VPN and proxy extension campaign targeting Russian-speaking users

Campaign

Updated: 12.08.2026 17:09 · First: 12.08.2026 17:09 · 📰 2 src / 2 articles · H score: 41

A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations, source IPs, and TLS SNI values. The operation spans at least 40 Chrome Web Store developer accounts and impersonates 66 VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, and ExpressVPN. The scale of installation activity and the large number of still-active add-ons indicate the operation remains ongoing.

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release

Updated: 11.08.2026 21:08 · First: 11.08.2026 21:08 · 📰 3 src / 3 articles · H score: 39

Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active exploitation and can let a local attacker escalate to SYSTEM. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign against defense and aerospace companies in Europe and India. The latest analysis says the malware negotiated its command channel with a post-quantum key exchange before pulling down the exploit, then loaded FudModule v3.1 through MISTPEN with layered encryption. The same infrastructure also used RelayShell, impersonation sites for Enveil, and a backdoor called Troy.

City-Forum Salesforce and ServiceNow guest-user exploitation campaign

Campaign

Updated: 12.08.2026 16:00 · First: 12.08.2026 16:00 · 📰 2 src / 2 articles · H score: 34

The City-Forum campaign is actively targeting Salesforce and ServiceNow with a custom multi-platform toolset, enabling guest-user enumeration and content exfiltration across multiple sectors. The operation is focused on telecoms, banks and financial-services firms, enterprise-software vendors, and public-sector portals. A fixed infrastructure node has remained active since March 2025, suggesting sustained and stealthy activity.

OpenAI Anthropic and Google reasoning APIs cross-session replay security flaw

Vulnerability

Updated: 12.08.2026 14:47 · First: 12.08.2026 14:47 · 📰 1 src / 1 articles · H score: 36

A newly disclosed cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs exposed hidden reasoning and secrets from session logs, including API keys and passwords. The weakness let opaque reasoning blocks move across sessions, users, and compatible models, turning preserved reasoning state into a secret-extraction risk. Researchers said the demonstrated attacks stopped working after mitigations in August 2026.

Perimeter prevention is recovering while post-compromise defenses lag across enterprise environments

Trend

Updated: 12.08.2026 14:41 · First: 12.08.2026 14:41 · 📰 1 src / 1 articles · H score: 26

First-half 2026 simulations show perimeter prevention recovering, but post-compromise controls still fail against quiet attacker behavior across enterprise environments. Average prevention effectiveness rose from 62% to 69%, while logging reached 58% and the alert score stayed at 14%. Once an intruder is inside, reconnaissance is blocked only 10% of the time and credential theft from memory or the registry often slips through. The result is a defense trend that favors noisy attacks at the edge and leaves low-noise breach preparation underprotected.

Signal launches Automatic Key Verification for encrypted chat key verification

Security Tool/Service

Updated: 12.08.2026 14:21 · First: 12.08.2026 14:21 · 📰 1 src / 1 articles · H score: 11

Signal launched Automatic Key Verification, adding key transparency checks that help users confirm encrypted chats have not been intercepted and reduce man-in-the-middle and key-swapping risk across its messaging ecosystem.

Adobe security patch release for CVE-2026-71398

Security Patch Release

Updated: 11.08.2026 19:50 · First: 11.08.2026 19:50 · 📰 2 src / 2 articles · H score: 37

Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The flaws could allow arbitrary code execution, and administrators were advised to install the update promptly. A later report described the same patch as part of a broader Adobe update cycle that also covered ColdFusion and Commerce. For Campaign Classic, the fix is tied to ACC v7 7.4.4 build 9400 and applies to fully on-premise deployments and the on-premise components of hybrid deployments.

VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)

Vulnerability

Updated: 12.08.2026 12:01 · First: 12.08.2026 12:01 · 📰 2 src / 2 articles · H score: 47

CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitation has now been observed shortly after Broadcom's late-July patch release, raising urgency for exposed vCenter servers. QUIRSO linked the activity to an intrusion chain that used path traversal and then reverse_ssh for persistence and outbound access.

SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release

Security Patch Release

Updated: 12.08.2026 10:31 · First: 12.08.2026 10:31 · 📰 1 src / 1 articles · H score: 37

SAP released patches for Commerce Cloud (Data Hub Adapter) to fix CVE-2026-58231, a CVSS 10.0 flaw that could let an unauthenticated attacker reach arbitrary code execution. The issue stems from insufficient authorization checks and input validation failures in vulnerable functions. Onapsis urged customers to move to a fixed Commerce Cloud release and re-deploy the updated version. A temporary IP Filter Set workaround can restrict access to the vulnerable endpoint until patching is complete.

Microsoft security patch release for CVE-2026-62832

Security Patch Release

Updated: 12.08.2026 09:41 · First: 12.08.2026 09:41 · 📰 2 src / 2 articles · H score: 5

Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release covers CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. CVE-2026-68820 is marked actively exploited and was added to CISA KEV, with federal agencies required to apply the fix by August 25, 2026.

CISA adds CVE-2026-68820 to KEV catalog

Public Sector Action

Updated: 12.08.2026 09:41 · First: 12.08.2026 09:41 · 📰 1 src / 1 articles · H score: 3

CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by August 25, 2026. The action formalizes the vulnerability as an official remediation priority and sets a concrete compliance deadline. It affects federal defenders responsible for Windows patching and vulnerability response.

Google Chrome expands Android notification anti-abuse controls with automatic permission revocation and rate limiting

Security Tool/Service

Updated: 12.08.2026 04:15 · First: 12.08.2026 04:15 · 📰 1 src / 1 articles · H score: 14

Google Chrome expanded its anti-abuse systems for Android notifications, reducing unwanted notification volume by more than 7 billion per day in Q1 2026. The controls now include automatic notification permission revocation for stale or suspicious sites and rate limiting for disruptive senders, cutting off deceptive notification traffic before it reaches users. The changes also target abuse tied to scams, malware, phishing attempts, and fraudulent payment requests.

Microsoft security patch release for CVE-2026-68820

Security Patch Release

Updated: 12.08.2026 00:28 · First: 12.08.2026 00:28 · 📰 3 src / 3 articles · H score: 23

Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes CVE-2026-68820, an actively exploited privilege-escalation zero-day in Windows Ancillary Function Driver for WinSock (AFD.sys) that can raise a locally authenticated user to SYSTEM. Microsoft also flagged CVE-2026-62832 as likely to be exploited and CVE-2026-72971 as a publicly disclosed lower-impact flaw.

Cisco Secure Firewall ASA and FTD active DoS exploitation denial-of-service flaw (CVE-2026-20349)

Vulnerability

Updated: 11.08.2026 22:45 · First: 11.08.2026 22:45 · 📰 2 src / 2 articles · H score: 31

CVE-2026-20349 is being actively exploited against Cisco Secure Firewall ASA and FTD software, enabling crafted HTTP requests to trigger a remote denial of service on devices with certain remote access services enabled. Cisco has released hot fixes for affected releases and says there is no workaround other than upgrading to a fixed version.

Zoom annotation tool flaws (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 22:08 · First: 11.08.2026 22:08 · 📰 1 src / 1 articles · H score: 24

Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Windows, Zoom Rooms, and Zoom Meeting SDK builds. The issues are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, covering a buffer over-write, a buffer over-read, and a use-after-free condition. Fixes shipped in June and July 2026 before the public disclosure, and the company says no exploitation has been reported. The affected flows rely on annotation messages in shared-screen meetings, where the receiver trusts the sender enough to rebuild the object in full.