From BleepingComputer · 40 stories
Google fined over €400m by Irish DPC for manipulating location data consent
Google received a fine exceeding €400 million from Ireland's Data Protection Commission (DPC) for manipulating users into agreeing to location data tracking. The DPC's six-year inquiry found Google lacked a valid legal basis for processing location data, which could reveal sensitive personal information.
WhatsApp Enhances Account Security with Stronger 2FA and Multiple Passkeys
WhatsApp has updated its account security features, allowing users to set alphanumeric passwords with special characters for two-step verification, replacing the previous six-digit PINs. The platform also introduced support for adding multiple passkeys to a single account, useful for users across iOS and Android devices, and added more context for calls from unknown numbers on Android.
TikTok settles DOJ children's privacy lawsuit for $400 million
TikTok and its parent company, ByteDance, have agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice (DOJ) in 2024. The lawsuit alleged violations of the Children's Online Privacy Protection Act (COPPA) by collecting personal information from underage users without parental consent. The settlement includes new age-related controls and parental oversight measures.
Cyberattack on CEVA Logistics Exposes European Steam Hardware Customer Data
A cyberattack on CEVA Logistics, Valve's European shipping partner, between July 29 and August 1, 2026, compromised personal data of Steam hardware customers in Europe. The breach exposed names, addresses, phone numbers, email addresses, and product details, leading Valve to warn customers about potential phishing attempts. This incident highlights supply chain vulnerabilities and impacts multiple retailers relying on CEVA Logistics.
Dependabot introduces default three-day cooldown for version updates
Dependabot now includes a default three-day cooldown before opening version update pull requests. This change aims to reduce the risk of merging compromised versions immediately after their release, enhancing supply chain security for developers.
Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams
Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.
DIVD Network Breach Linked to Zammad Zero-Days and AI-Driven Attack
The Dutch Institute for Vulnerability Disclosure (DIVD) reported that its network breach was caused by two zero-day vulnerabilities in the Zammad ticketing system, identified as CVE-2026-102489 and CVE-2026-102490. These flaws allowed session hijacking, remote code execution, and root privilege escalation, with an AI agent automating the attack and data exfiltration.
Over 543,000 Valid Credentials Exposed in Public GitHub Repositories
A study by Truffle Security found over 543,000 valid credentials exposed in public GitHub repositories, with some remaining accessible for years. This highlights that GitHub's Push Protection, while effective for new exposures in covered categories, does not revoke existing leaked credentials and misses certain types of secrets.
New "Pass-ta-key" Attacks Bypass Passkey Protections in Google Password Manager
Researchers from Palo Alto Networks' Unit 42 have identified three "Pass-ta-key" attack methods that allow malware on compromised Windows machines to bypass passkey protections in Chrome's Google Password Manager. These attacks exploit how Chrome stores device keys and re-enrolls devices, enabling silent authentication, installation of attacker-controlled keys, or extraction of synced passkey private keys, demonstrating vulnerabilities in passkey implementations when an endpoint is already compromised.
HalluSquatting Attack Exploits AI Hallucinations to Form Botnets
The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.
WordPress wp2shell Vulnerability Exploited; Urgent Patches Released
Two critical WordPress vulnerabilities, dubbed 'wp2shell' (CVE-2026-60137 and CVE-2026-63030), allow unauthenticated attackers to execute code. Affecting versions 6.9.0-6.9.4 and 7.0.0-7.0.1, fixes were released in versions 6.9.5 and 7.0.2. The vulnerabilities, actively exploited, prompted immediate patching, affecting over 500 million sites. WordPress initiated forced automatic updates, while Cloudflare deployed protective measures.
PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM
Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.
CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access
A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.
MetaMask Addresses Security Incident, Exits Affected Ethereum Validators
MetaMask is responding to an ongoing security incident affecting its infrastructure and has begun exiting affected validators in its non-custodial staking operations. This measure is precautionary, with no immediate threat identified to MetaMask wallets, but will incur foregone rewards and potential downtime penalties for the exited validators.
Threat Actor Sells Data Stolen from Fortune 500 Azure Tenants
A threat actor named 'TheHatman' is selling data allegedly exfiltrated from the Azure tenants of several Fortune 500 companies, including McDonald's and TCS. The stolen information, which includes employee directories and highly privileged account records, poses a significant risk for targeted attacks like spear-phishing and business email compromise.
OpenAI's Astra AI Model Solves 10 Long-Standing Math and Computer Science Problems
OpenAI introduced Astra, an unreleased AI model, after an internal version achieved ten significant advances in mathematics and theoretical computer science. These problems had seen no progress for at least a decade, and in some cases, much longer, indicating a potential shift in AI's capability for foundational scientific research.
RefluXFS Linux Kernel Flaw Allows Local Root Access on XFS Filesystems
A nine-year-old Linux kernel flaw, dubbed RefluXFS (CVE-2026-64600), allows unprivileged local users to overwrite root-owned files on XFS filesystems and gain persistent root access. This race condition vulnerability affects systems running Linux kernel v4.11 or later with XFS filesystems created with `reflink=1`, including default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux.
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
GitHub Actions and Pages Experience Degraded Availability, Migration to Azure Accelerated
GitHub experienced degraded availability for GitHub Actions and Pages on August 6, leading to failing or delayed workflow runs and impacting services like Copilot and GitHub Enterprise Importer. In response, GitHub is accelerating its architectural roadmap for Actions, including a full migration of the service to Azure to improve isolation, resiliency, and scalability.
Cyberattack Exposes Data of 8.7 Million Customers at Three UK Airports
Manchester Airports Group (MAG) reported a cyberattack affecting approximately 8.7 million customers across Manchester, London Stansted, and East Midlands airports. The breach compromised personal data such as email addresses, phone numbers, vehicle registrations, and postcodes, but no financial information was accessed.
Android 17 Integrates Encrypted Client Hello for Enhanced Web Privacy
Android 17 introduces platform-wide support for Encrypted Client Hello (ECH), a new internet standard that encrypts website destination information. This prevents internet service providers (ISPs) and Wi-Fi operators from seeing specific domain names, thereby limiting user profiling and targeted advertising. This makes Android the first major mobile operating system to implement ECH at a platform level.
New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets
A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.
Polish Energy Plant Cyberattack Used Novel Private APN Vector, Shutting Down Turbine
A previously undisclosed cyberattack in December 2025 targeted a small Polish combined heat and power (CHP) plant, causing a temporary shutdown of its steam turbine and water treatment system. The attack, which threatened heat supply to 50,000 residents, utilized a private Access Point Name (APN) as an attack vector, marking the first documented real-world use of this method to access industrial control systems.
Malicious `proc-macro1` crate leads to supply chain attack on `arrayref` and other Rust crates
The Rust Security Response Team identified and removed several malicious crates, including `proc-macro1`, which was used in a supply chain attack to compromise popular crates like `arrayref`, `internment`, and `append-only-vec`. This incident highlights the vulnerability of software supply chains to malicious package injections and necessitates developers to verify their dependencies.
WhatsApp Rolls Out Optional On-Device Scam Alert Feature in Limited Beta
WhatsApp has launched a limited beta of "Scam Alert," an optional feature that uses an on-device machine learning model to identify suspicious messages from unknown contacts. This feature processes message content locally on the user's device to maintain end-to-end encryption while alerting users to potential scams. Users can block, report, or ignore flagged messages, and can opt to share message data to improve the model's accuracy.
Zimbra Releases Critical Security Patches for Classic Web Client
Zimbra has released version 10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via crafted emails. Additionally, Zimbra version 10.1.20 addresses multiple vulnerabilities, including command injection and mail forwarding bypass. The updates are crucial to maintain security for users of the Zimbra Collaboration Suite.
Coca-Cola's Fairlife Hits U.S. Production Halt Due to Anubis Ransomware Attack
A ransomware attack by the Anubis group has forced Coca-Cola's Fairlife to suspend U.S. production. Hackers claim they extracted 1 TB of data, threatening to release it unless a ransom is paid. The incident raises concerns about cybersecurity in the food and beverage sector.
Microsoft Issues Record 570 Security Patches, Including Three Zero-Days
Microsoft's July 2026 Patch Tuesday included a record 570 security patches, with three zero-day vulnerabilities addressed. The increase is partly due to AI-assisted discovery, highlighting a trend in vulnerability identification and remediation.
Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD
Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.
19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks
Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.
Opera Rolls Out 'Paste Protect' to Counter ClickFix Cyber Attacks
Opera has introduced 'Paste Protect', a new feature to block malicious clipboard commands copied from websites, aimed at mitigating ClickFix-style attacks. These attacks leverage social engineering tactics to mislead users into pasting harmful code into terminals. The new feature marks the first native defense against this rising cyber threat in a major web browser.
Microsoft's 2026 Digital Defense Report: AI Gives Cyberattackers an Early Advantage
Microsoft's 2026 Digital Defense Report states that cyberattackers are currently leveraging AI faster than defenders, accelerating vulnerability discovery, malware development, and post-compromise activities. This creates a period where attackers have an advantage, as defenders struggle to keep pace with the speed of AI-powered threats.
Critical RCE Flaw in Forminator WordPress Plugin Affects 600,000+ Sites
A critical security vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, leading to remote code execution and site compromise. The flaw, rated 9.8 on CVSS, affects over 600,000 active installations and requires specific form configurations for exploitation, but has been patched in version 1.56.2.
New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data
Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.
Revolut confirms customer data breach via fraudulent government agency requests
Revolut disclosed that an unauthorized third party obtained sensitive customer data by submitting fraudulent requests from a legitimate government agency email domain. The exposed information includes identity details, contact information, and potentially verification selfies, account statements, and transaction histories for a limited number of customers. This incident highlights vulnerabilities in data access protocols, even when dealing with seemingly legitimate government communications.
Trezor Discloses ShipMonk Breach Exposed Data of 67,000 U.S. Customers
Hardware wallet manufacturer Trezor announced that 67,000 U.S. customers had their personal data exposed due to a breach at its shipping provider, ShipMonk. This incident is significant because it adds to previously disclosed exposures and highlights the risks associated with third-party data handling, even after assurances of data deletion.
PaperCut warns of active exploitation of zero-day vulnerability in NG and MF software
PaperCut issued an urgent security advisory regarding a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software, which is actively being exploited in attacks. The company released emergency patches and advised organizations to restrict access to web interfaces of Internet-exposed servers, as this vulnerability poses a significant risk to affected systems.
Craneware Reports Data Breach Affecting US Hospitals and Pharmacies
Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.
Russian National Charged in US for Malware Campaign Targeting 80,000 Freelancers
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, has been extradited to the US and charged with orchestrating a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware between 2016 and 2017. Aktulaev used 255 fake accounts on an unnamed freelance employment platform to distribute malicious Excel attachments, gaining remote control and stealing data from victims' systems. This case highlights international efforts to prosecute cybercriminals.
Two Berlin State Ministries Disconnected from Government Network Following Security Breach
Two Berlin state ministries, responsible for urban development and mobility, have been isolated from the city government's IT network due to a security breach. This incident has disrupted internal communications and some public services, highlighting vulnerabilities in government IT infrastructure.