From SecurityWeek · 40 stories
Nightmare Eclipse Releases 'HardBreacher' Exploit for Kaspersky Endpoint Security
Security researcher Nightmare Eclipse released a proof-of-concept exploit, dubbed "HardBreacher," targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. Kaspersky stated that the underlying issue has been resolved via an automatic update, or users can trigger a database update manually. This exploit highlights ongoing concerns about endpoint security product vulnerabilities and the impact of public zero-day disclosures.
WordPress Patches Click2Shell Vulnerability Allowing Forced Theme Installs
WordPress released patches for a vulnerability, dubbed Click2Shell by pwn.ai, that allows a logged-in administrator to install a theme from the official directory via a crafted web link. This flaw can be chained with a separate theme vulnerability to achieve remote code execution on the server.
Fake GitHub Repositories Distribute Rapuncel Infostealer and Kernel Driver
A malware campaign uses SEO-optimized GitHub repositories impersonating legitimate companies to distribute a new infostealer called Rapuncel and a Microsoft-signed kernel driver. The kernel driver, Alinubx.sys, disables 145 antivirus and EDR products, allowing Rapuncel to steal credentials and cryptocurrency wallet data.
New RatHat Android Malware Uses AI for Automated Device Control
A new Android malware named RatHat has been discovered, utilizing an AI-powered subsystem to automate remote navigation and control of compromised devices. This AI integration allows the malware to adapt its operations without constant real-time operator interaction, making it more sophisticated than previous Android malware families.
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Gyazo, an image-sharing service, experienced a security breach that exposed approximately 23.62 million user records, including email addresses and password hashes, along with 490 million image metadata records. This incident is significant because it compromises user privacy and security, potentially allowing unauthorized access to images and other services if users reused passwords.
U.S. Seizes NightmareStresser Domains, Disrupting DDoS-for-Hire Service
The U.S. Department of Justice (DoJ) and FBI, in coordination with international law enforcement, seized the internet domains nightmare-stresser[.]com and nightmarestresser[.]org, associated with the distributed denial-of-service (DDoS)-for-hire service NightmareStresser. This action, part of Operation PowerOFF, disrupts a platform used to launch hundreds of thousands of DDoS attacks globally since 2022, impacting various sectors including education, government, and gaming.
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
A China-linked hacking group, UNC3569, exploited a vulnerability in Sogou Input Method for Windows to install the GRAYRABBIT backdoor on victim computers. The flaw allowed attackers to execute arbitrary commands, impacting users primarily in East and Southeast Asia.
Anthropic Blocks Houthi-Linked Accounts Attempting AI-Assisted Missile Development
Anthropic identified and blocked accounts in Houthi-controlled Yemen that attempted to use its Claude AI model to develop advanced missiles, including a multi-variant hypersonic missile and a warhead with mobile phone hardware for guidance. The users conducted a failed guided rocket test and sought AI assistance to understand the failure, indicating attempts to advance their weapons capabilities.
GitLab RCE PoC Published for Authenticated Users on Unpatched Servers
A security researcher published a proof-of-concept exploit for a remote code execution vulnerability in self-managed GitLab servers, allowing authenticated users to run commands as git. This vulnerability affects multiple GitLab Community Edition and Enterprise Edition versions and requires self-managed operators to upgrade to patched releases.
Conti Ransomware Member Sentenced to Four Years in Prison for Wire Fraud Conspiracy
A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, received a four-year prison sentence for his involvement in Conti ransomware attacks between 2021 and 2022. This sentencing highlights ongoing law enforcement efforts against cybercrime groups and their members.
FBI arrests alleged ringleader in $240 million Bitcoin theft and money laundering scheme
The FBI arrested Malone Lam, an alleged ringleader, and 17 others involved in a $240 million Bitcoin theft from August 2024, which was followed by a spending spree and a sophisticated money laundering operation. This case highlights an increase in cryptocurrency investment fraud complaints to the FBI, which rose by nearly 50% in 2025.
Attackers Exploit MikroTik Routers via Internet-Exposed SSH for Unauthorized Access
Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to CERT Polska. MikroTik has released security updates for RouterOS to address these vulnerabilities, and users are advised to install them immediately.
Venezuelan National Sentenced to 8 Years for ATM Jackpotting Scheme
A Venezuelan national received an 8-year federal prison sentence for his involvement in an ATM jackpotting scheme that resulted in over $3.5 million in losses. This sentence is reportedly the longest federal term for an individual's role in ATM jackpotting, highlighting ongoing efforts to combat this type of financial crime.
Large DDoS Attack Disrupts Norwegian Government Services for Over a Day
A large-scale distributed denial-of-service (DDoS) attack targeted the infrastructure of Norway's Digitalisation Agency (Digdir), disrupting multiple public services for over 24 hours. This incident highlights the vulnerability of critical government digital infrastructure to cyberattacks and the potential for widespread disruption to citizen services.
Hackers Exploit miniOrange SAML SSO WordPress Plugin Vulnerabilities
Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.
Uber fined nearly $1 billion by Dutch regulator for automated driver deactivations
The Dutch Data Protection Authority (AP) has fined Uber 824.9 million euros ($966 million) for violating GDPR by automatically deactivating driver accounts without human intervention between 2018 and 2022. This fine is the largest imposed on Uber by the AP and addresses concerns about automated decisions impacting driver income.
Head Mare Exploits TrueConf Server Flaws to Distribute Backdoored Client Installers
The hacktivist group Head Mare exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing PhantomCore and PhantomGraph backdoors. These attacks, discovered by Kaspersky in July, targeted Russian organizations across various sectors, allowing attackers to gain persistent remote access and exfiltrate data.
Over 14,500 Dahua Devices Compromised via Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io uncovered "Operation CameraSwarm," which compromised over 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a P2P relay technique. This compromise highlights the ongoing risk posed by unpatched vulnerabilities and weak credentials in IoT devices, particularly in critical infrastructure or surveillance contexts.
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for Five Individuals
The US has charged 17 members of Iran's Mabna Institute for hacking into hundreds of organizations globally, including universities, companies, and government agencies. This action highlights ongoing cyber espionage efforts attributed to state-sponsored groups and the US government's response to intellectual property theft.
Shell investigates potential data theft after Clop ransomware gang claims 89GB stolen
Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. This incident is linked to the exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM instances, a vulnerability that CISA has confirmed is actively exploited.
City-Forum Campaign Targets Salesforce and ServiceNow Guest Users with Custom Tools
A campaign named 'City-Forum' is exploiting guest user access in Salesforce Experience Cloud (Aura and LWR implementations) and ServiceNow customer portals to steal data. The attacks use a custom multi-platform toolset and target telecommunications, banking, financial services, enterprise software vendors, and public-sector portals globally.
French Tax Authority Investigates Data Breach After Hacker Claims 600,000 Victims
France's Directorate General of Public Finances (DGFiP) confirmed a data breach in late June where an attacker accessed and extracted data on individuals and businesses. The incident became public after a hacker claimed responsibility, stating they obtained data on over 600,000 people, including personal and tax identification information.
Atlassian Rovo AI Vulnerabilities Allowed Data Exfiltration; One Fixed, One Remains
Atlassian's Rovo AI assistant had vulnerabilities that allowed data exfiltration from Jira and Confluence. One method, dubbed RovoBlast by Varonis Threat Labs, involved a one-click malicious link and has been fixed. Another method, discovered by PromptArmor, used indirect prompt injection via uploaded files and remains unconfirmed as fixed by Atlassian.
Open Secure AI Alliance Proposes SAFE Guidelines for AI Cybersecurity Incident Sharing
The Open Secure AI Alliance (OSAA), comprising over 120 organizations including NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat, has proposed Shared AI Findings Exchange (SAFE) guidelines. These guidelines, released for public comment by the Linux Foundation at the Black Hat conference, aim to standardize the confidential collection, analysis, and sharing of agentic AI cybersecurity incidents to reduce systemic risks across the industry.
Ernst & Young Discloses Data Breach: Client Tax Information Compromised
Ernst & Young experienced a data breach via a third-party support system, compromising clients' personal and financial data. The breach, spanning March 28 to April 12, included sensitive tax information, with notifications sent to affected clients and state regulators. The incident underscores the vulnerabilities associated with third-party IT services.
Fastjson 1.x RCE Vulnerability Actively Exploited, No Patch Available
Attackers are targeting a critical remote code execution (RCE) vulnerability in Alibaba's Fastjson 1.x library, affecting Spring Boot applications. The flaw, CVE-2026-16723, allows unauthenticated code execution and currently has no official patch from Alibaba for the 1.x branch. This impacts organizations using Fastjson 1.x in specific Spring Boot configurations, requiring immediate mitigation or migration to Fastjson2.
Clop Ransomware Exploits PTC Windchill and FlexPLM Vulnerability for Data Theft
The Clop ransomware group is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM to exfiltrate data from targeted companies. This exploitation has led to extortion campaigns and prompted urgent warnings from cybersecurity agencies and authorities.
HollowGraph Malware Utilizes Microsoft 365 Calendars for C2 Communications
HollowGraph, a new malware, uses Microsoft 365 calendar events dated to 2050 for command-and-control and data exfiltration. This method disguises traffic as legitimate, targeting Israeli entities and linked to Iranian threat actors.
Critical ServiceNow Flaw Exploited Despite Patch Release
A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited, allowing attackers to execute code remotely. Despite the July patches, attacks were observed shortly thereafter. This issue highlights the urgency for self-hosted customers to apply updates promptly to prevent system compromise.
OpenSSL HollowByte Flaw Exposes Servers to Memory Exhaustion with Minimal Payload
A vulnerability in OpenSSL, known as HollowByte, allows attackers to trigger a denial-of-service condition by sending an 11-byte payload. The flaw causes vulnerable servers to pre-allocate memory for incomplete TLS handshake messages. Fixed versions without official CVEs or advisories include OpenSSL 4.0.1 and others released on June 9. Upgrading is crucial to prevent potential server freezes.
Claude for Chrome Vulnerability Exposes User Data to Rogue Extensions
A vulnerability in Claude for Chrome allows rogue extensions to trigger sensitive tasks without user consent. Discovered by Manifold Security, the flaw enables malicious extensions to access Gmail, Google Docs, Calendar, and Salesforce, posing a significant security risk. This issue persists in version 1.0.80, with no current patch.
Zoom Patches Critical Vulnerability Allowing Account Takeovers
Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows applications, rated 9.8 on the CVSS scale, which enabled potential account takeovers. The flaw affected Zoom Workplace, Zoom VDI Client, and Zoom Meeting SDK for Windows prior to version 7.0.0. This vulnerability impacts user security and necessitates immediate updates to prevent unauthorized account access.
Microsoft Revokes Vulnerable UEFI Shims Allowing Secure Boot Bypass
Microsoft has revoked the signatures of 11 old UEFI shims signed by them, which could bypass Secure Boot on Windows and Linux systems. This security flaw, discovered by ESET, existed due to old firmware remaining signed and trusted despite vulnerabilities. Addressing this issue is critical for preventing the unauthorized execution of code during the system boot process.
Critical Vulnerability in Cursor IDE Allows Arbitrary Code Execution on Windows
A vulnerability in Cursor IDE enables arbitrary code execution by executing malicious git binaries in project roots. Reported by Mindgard in December 2025, the issue remains unpatched, affecting over 7 million users. The flaw involves Cursor executing 'git.exe' files in repository roots without user interaction, posing significant security risks.
Progress Software Confirms Zero-Day Vulnerability in ShareFile Storage Zone Controllers
Progress Software advised ShareFile users to shut down Storage Zone Controllers due to a zero-day vulnerability. The high-severity path traversal flaw, affecting versions 5.x and 6.x, led to precautionary account access suspension and patches release. No customer data compromise has been reported.
Microsoft 365 Users Targeted in Voice Phishing Campaign for Fake Entra Passkey Enrollment
A voice phishing campaign is exploiting Microsoft 365 users to unwittingly enroll fake Entra passkeys, giving attackers unauthorized account access and facilitating potential data extortion. Initiated by the group O-UNC-066, the campaign began in April and spans multiple industries, highlighting vulnerabilities in the passkey adoption process Microsoft implemented. Okta reported the attacks, which utilize convincing phishing kits mimicking Microsoft's passkey enrollment portal.
US and Allied Nations Warn of Russian Router-Based Cyberattacks on Critical Infrastructure
US and several allied nations have issued a warning regarding Russian state-backed attempts to exploit poorly secured routers to breach critical infrastructure. The FSB's hacking groups target sectors including energy, healthcare, and communications by using known vulnerabilities and SNMP exploits. The warning underscores the need for immediate security enhancements in affected sectors.
UK and EU Sanction Russia's FSB and GRU for Cyberattacks Involving Critical Infrastructure
The UK and EU have imposed joint cyber sanctions targeting Russia's FSB and GRU following a cyberattack on Poland's energy grid that nearly caused a major blackout last winter. The coordinated sanctions, the first of their kind, address ongoing Russian-led cyber espionage campaigns against EU member states. These actions reflect growing international concerns regarding Russia's capacity to destabilize Europe’s critical infrastructure.
China and India-Linked Hackers Infiltrate Balochistan Police Networks
Chinese and Indian cyberespionage groups targeted the Balochistan Police from February 2024 to April 2026. The attackers accessed sensitive systems, including biometric data and criminal records. This exposes significant regional security vulnerabilities tied to geopolitical tensions.
Critical Linux Kernel Vulnerabilities: DirtyClone, Bad Epoll, and GhostLock
Three critical Linux kernel vulnerabilities, DirtyClone (CVE-2026-43503), Bad Epoll (CVE-2026-46242), and GhostLock (CVE-2026-43499), have been disclosed, each allowing privilege escalation. DirtyClone targets cloned network packets, Bad Epoll exploits a race condition, while GhostLock leverages a 15-year-old use-after-free flaw. Each vulnerability has a patch available, emphasizing the need for prompt system updates to mitigate exploitation risks.