# cvss (news sources) — RSS Amplifier

Recent posts from the 3 feeds in the RSS Amplifier directory that cover cvss.

Page: <https://rssamplifier.com/topics/cvss/news>  
Feed: <https://rssamplifier.com/topics/cvss/news.md>

---

## [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's

## [Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot](https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

## [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://thehackernews.com/2026/08/android-car-malware-spreads-through.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

## [Lawmakers request watchdog review of federal hacking of Americans](https://hackernews.ae/lawmakers-request-watchdog-review-of-federal-hacking-of-americans/)

_2026-08-21 · News Room · Hacker News_

Two members of Congress have formally requested that a government watchdog agency investigate the extent and oversight of federal agencies’ use of hacking tools, including spyware, against Americans. The lawmakers seek a public report detailing the findings. The request, sent Friday to the Government Accountability Office (GAO), was made by Senator Ron Wyden, a Democrat \[...\]

## [Cisco Addresses Critical Vulnerabilities in Crosswork and Secure Workload Software](https://hackernews.ae/cisco-addresses-critical-vulnerabilities-in-crosswork-and-secure-workload-software/)

_2026-08-21 · News Room · Hacker News_

Cisco has issued a new set of security advisories detailing critical vulnerabilities across its Crosswork platforms and Secure Workload Software. These updates are part of an ongoing, comprehensive internal security review by the networking giant. The identified security flaws, several with maximum or near-maximum CVSS scores, underscore the persistent threat landscape for enterprise security…

## [Wazuh and AI For Enhanced SOC Workflows](https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate

## [Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0](https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -

## [GitLab CVE-2026-19478 exploited days after disclosure](https://hackernews.ae/gitlab-cve-2026-19478-exploited-days-after-disclosure/)

_2026-08-21 · News Room · Hacker News_

A critical GitLab vulnerability, identified as CVE-2026-19478, is being actively exploited in the wild shortly after its public disclosure. This severe code injection flaw allows unauthenticated attackers to compromise publicly accessible GitLab projects, enabling them to modify, delete, or rewrite project data without needing credentials or user interaction, according to a report by preemptive…

## [GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure](https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring

## [Microsoft Entra ID Vulnerability Exploited Remotely](https://hackernews.ae/microsoft-entra-id-vulnerability-exploited-remotely/)

_2026-08-21 · News Room · Hacker News_

Microsoft has issued a critical alert regarding a maximum-severity security flaw, CVE-2026-69836, within its Microsoft Entra ID service, formerly known as Azure Active Directory. The company confirmed that this remote code execution vulnerability has already been exploited in the wild, posing a significant threat. However, Microsoft has stated that no immediate action is required from \[...\]

## [Every Channel. One Login. (Sponsored)](https://crawlproof.com/a/wesnXiQFSjCj)

_2026-08-21 · **Sponsored**_

17,000+ live channels, movies and sports on any device. Free trial, no IP lock.

## [Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution](https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html)

_2026-08-21 · info@thehackernews.com (The Hacker News) · The Hacker News_

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory

## [Critical NetScaler Flaw Bypasses Authentication on Gateway and AAA Servers](https://hackernews.ae/critical-netscaler-flaw-bypasses-authentication-on-gateway-and-aaa-servers/)

_2026-08-20 · News Room · Hacker News_

Citrix has issued critical security updates to address two significant vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The patches are particularly important for organizations using customer-managed NetScaler instances, as one of the flaws allows for a critical-severity authentication bypass, potentially granting unauthorized access. The vulnerabilities were disclosed…

## [Isolated VM vulnerability allows sandboxed JavaScript to escape to host for potential remote code execution.](https://hackernews.ae/isolated-vm-vulnerability-allows-sandboxed-javascript-to-escape-to-host-for-potential-remote-code-execution/)

_2026-08-20 · News Room · Hacker News_

A critical security vulnerability has been discovered in isolated-vm, a widely-used Node.js sandbox library, potentially allowing attackers to escape the confined environment. The flaw, identified by cybersecurity researchers, impacts numerous applications that rely on this library for running untrusted JavaScript code securely. This discovery highlights ongoing challenges in maintaining robust…

## [Researchers Discover Cryptographic Context Injection Attack Targeting Web Pages](https://hackernews.ae/researchers-discover-cryptographic-context-injection-attack-targeting-web-pages/)

_2026-08-20 · News Room · Hacker News_

AI security firm Adversa AI has disclosed a novel attack technique, codenamed “Cryptographic Context Injection,” that it claims can compel xAI’s Grok chatbot to leak sensitive user information to an attacker. This exploit reportedly allows an attacker to obtain a user’s name, approximate location, subscription tier, and current conversation prompts by tricking Grok into summarizing \[...\]

## [Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

## [Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

## [AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure](https://hackernews.ae/ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-critical-infrastructure/)

_2026-08-20 · News Room · Hacker News_

The U.S. government has issued a stark warning about an “active threat” leveraging artificial intelligence (AI) to generate exploit scripts targeting critical infrastructure organizations. This new wave of cyber activity specifically targets Siemens S7 Series Programmable Logic Controllers (PLCs) for reconnaissance and capability development, though the scope is believed to be broader than just…

## [Vulnerabilities disclosed include Gogs 10.0 RCE, n8n workflow-to-RCE, a $10M reward opportunity, and a GLM-5.3 AI exploit.](https://hackernews.ae/vulnerabilities-disclosed-include-gogs-10-0-rce-n8n-workflow-to-rce-a-10m-reward-opportunity-and-a-glm-5-3-ai-exploit/)

_2026-08-20 · News Room · Hacker News_

This week’s cybersecurity landscape is dominated by threats leveraging trusted components for malicious purposes, underscoring the persistent challenges in securing digital infrastructure. From the abuse of signed drivers to the exploitation of legitimate applications, attackers continue to find innovative ways to bypass defenses, making the need for robust cybersecurity measures more critical…

## [ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More](https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

## [CDN Vulnerable to HTTP/3 Amplification Attacks](https://hackernews.ae/cdn-vulnerable-to-http-3-amplification-attacks/)

_2026-08-20 · News Room · Hacker News_

Cybersecurity researchers have uncovered a new threat dubbed “CDN Tsunami,” which exploits how major content delivery networks (CDNs) handle HTTP/3 traffic. These attacks can amplify low-bandwidth requests into massive floods directed at origin servers, potentially leading to significant service disruptions. The findings highlight a critical vulnerability in how CDNs bridge the gap between modern…

## [Sync Bookmarks Everywhere (Sponsored)](https://crawlproof.com/a/7u0zb5q3shrW)

_2026-08-20 · **Sponsored**_

Two-way sync keeps folders and toolbar intact across Chrome, Firefox, and Safari.

## [Retail theft bill sparks surveillance concerns](https://hackernews.ae/retail-theft-bill-sparks-surveillance-concerns/)

_2026-08-20 · News Room · Hacker News_

A bipartisan bill aimed at combating organized retail theft is gaining traction in Congress, though some advocacy groups warn it could lead to expanded surveillance powers. The Combating Organized Retail Crime Act, or CORCA, seeks to create a new coordination center within Immigration and Customs Enforcement (ICE) to share information and prosecute large-scale theft operations. \[...\]

## [Researchers Demonstrate Zombie Card Attack to Reactivate Expired Visa Cards for Contactless Payments](https://hackernews.ae/researchers-demonstrate-zombie-card-attack-to-reactivate-expired-visa-cards-for-contactless-payments/)

_2026-08-20 · News Room · Hacker News_

Researchers at the University of Massachusetts Amherst have uncovered a significant security vulnerability in Visa contactless credit cards, demonstrating a method to revive expired cards for real-world purchases by manipulating the expiration date read by point-of-sale (POS) terminals. This “Zombie Card” attack, as it’s been dubbed, bypasses cryptographic protections, raising concerns about the…

## [New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data](https://thehackernews.com/2026/08/new-cryptographic-context-injection.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the

## [Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE](https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

## [Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

## [Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution](https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra

## [Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack, which the researchers named "Zombie Card," requires physical

## [Why "Shady AI" is Security's Next Big Governance Problem](https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee

## [CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification](https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu,

## [Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices](https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud

## [Know before it drops (Sponsored)](https://crawlproof.com/a/vKQBEzQ2pOyj)

_2026-08-20 · **Sponsored**_

Follow a show, artist, genre or rocket and get notified before release

## [Elementor Pro Vulnerability Allows Unauthenticated Code Execution](https://hackernews.ae/elementor-pro-vulnerability-allows-unauthenticated-code-execution/)

_2026-08-20 · News Room · Hacker News_

Cybersecurity researchers have revealed a critical vulnerability in the popular Elementor Pro WordPress plugin, identified as CVE-2026-32475. This flaw, carrying a severe CVSS score of 9.0, could allow unauthenticated attackers to execute arbitrary code remotely on vulnerable websites. The vulnerability stems from an issue within the Forms module’s File Upload field, specifically how it handles…

## [Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code](https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html)

_2026-08-20 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

## [Cloudflare Workers Vulnerable to Spectre Attack, Leaking JWTs at Low Data Rates](https://hackernews.ae/cloudflare-workers-vulnerable-to-spectre-attack-leaking-jwts-at-low-data-rates/)

_2026-08-19 · News Room · Hacker News_

Cybersecurity researchers have successfully demonstrated a remote Spectre attack targeting Cloudflare Workers, achieving a significant increase in data leakage speed. This advanced attack, detailed in a recent paper, managed to exfiltrate a JSON Web Token (JWT) from a co-located Worker in Cloudflare’s production environment at a rate of up to 12 bits per second. This \[...\]

## [Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second](https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,

## [OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior](https://thehackernews.com/2026/08/openai-pauses-frontier-rl-training-as.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models become more capable, the risks associated with developing and testing them internally also grow," the AI company

## [Hackers compromise over 14,500 Dahua devices](https://hackernews.ae/hackers-compromise-over-14500-dahua-devices/)

_2026-08-19 · News Room · Hacker News_

Cybersecurity researchers at Hunt.io have detailed a large-scale attack campaign, codenamed Operation CameraSwarm, that compromised over 14,530 Dahua devices between June and July 2026. The campaign leveraged a combination of credential attacks, two critical authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique to gain unauthorized access to surveillance systems. The…

## [SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs](https://thehackernews.com/2026/08/silkparasite-espionage-campaign-targets.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

## [Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P](https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

## [Phishing 3.0: The Fight Moves to Agent Versus Agent](https://thehackernews.com/2026/08/phishing-30-fight-moves-to-agent-versus.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad

## [StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data](https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

## [Serious Vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE Under Active Exploitation](https://hackernews.ae/serious-vulnerabilities-in-macos-sharepoint-vcenter-and-microsoft-ike-under-active-exploitation/)

_2026-08-19 · News Room · Hacker News_

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. This move highlights the ongoing threat posed by these security flaws, particularly for organizations that have not yet applied the available patches. The inclusion signifies that these vulnerabilities…

## [Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation](https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

## [Clop-linked Windchill web shell decrypts credentials and maps engineering data.](https://hackernews.ae/clop-linked-windchill-web-shell-decrypts-credentials-and-maps-engineering-data/)

_2026-08-19 · News Room · Hacker News_

A sophisticated, custom-built JavaServer Pages (JSP) web shell has been discovered deployed by threat actors targeting critical vulnerabilities in PTC Windchill and FlexPLM servers. Cybersecurity firm ReliaQuest has detailed how this bespoke tool, specifically crafted for Product Lifecycle Management (PLM) software, acts as a powerful extortion platform, enabling extensive data theft and remote…

## [Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure](https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html)

_2026-08-19 · info@thehackernews.com (The Hacker News) · The Hacker News_

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before

## [Attackers exploit MLflow SSRF flaw to steal cloud credentials and secrets](https://hackernews.ae/attackers-exploit-mlflow-ssrf-flaw-to-steal-cloud-credentials-and-secrets/)

_2026-08-18 · News Room · Hacker News_

Critical vulnerabilities affecting open-source artificial intelligence (AI) platform MLflow and operational technology (OT) software FUXA are currently under active malicious scanning and exploitation. These security weaknesses, identified as CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA, pose significant risks to organizations relying on these platforms for machine learning operations and…

## [Microsoft Copilot security vulnerabilities may allow data exfiltration from connected applications.](https://hackernews.ae/microsoft-copilot-security-vulnerabilities-may-allow-data-exfiltration-from-connected-applications/)

_2026-08-18 · News Room · Hacker News_

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could allow attackers to silently exfiltrate data from connected applications with a single click on a crafted link. The flaws leverage an undocumented URL parameter that the AI assistant itself revealed during Varonis’s security research. Microsoft was notified of the \[...\]

## [Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps](https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html)

_2026-08-18 · info@thehackernews.com (The Hacker News) · The Hacker News_

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

## [Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000](https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html)

_2026-08-18 · info@thehackernews.com (The Hacker News) · The Hacker News_

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research

## [AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files](https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html)

_2026-08-18 · info@thehackernews.com (The Hacker News) · The Hacker News_

Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding

## [TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks](https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html)

_2026-08-18 · info@thehackernews.com (The Hacker News) · The Hacker News_

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

