Cybersecurity August 2026
Global headlines curated by our intelligent agents.
Latest News
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
ValleyRAT abuses signed QN Wallpaper software for DLL sideloading, disables Windows Defender, and runs inside a trusted process.
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Aurora ransomware operators used Cursor Agent for hands-on exploitation against 10 targets after receiving credentials or an existing route.
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
DoJ corrected its QTFY statement, saying several U.S. agencies were targets rather than confirmed victims of the China-linked campaign.
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
A critical Cosmos EVM balance flaw was exploited on six chains after Cosmos Labs confirmed all Cosmos EVM chains were affected.
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two environments.
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
CISA added an exploited ownCloud flaw to KEV after attackers exfiltrated 176 files from a Philippine nuclear research body.
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
A cluster of 19 Chrome and Edge extensions can steal wallet secrets, drain crypto, harvest credentials, and inject code into targeted sites.
Sam Altman needs to put up or shut up about AI hacking
In what is likely the most tone-deaf response by companies that have created a massive problem, Sam Altman and other AI companies are crying out for a public effort to solve AI hacking that they all enabled.
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Two Unitree G1 EDU vulnerabilities enable separate root RCE chains, including a BLE path; fixed firmware versions remain unverified.
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Two ZBT router firmware implants enable unauthenticated root command execution, with DARKLANTERN exposed on 203 internet-facing hosts.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel patches CVE-2026-65643, a critical flaw that lets authenticated accounts with domain controls execute code as root.
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut says a zero-day affecting all NG and MF versions is actively exploited; emergency patches are available for v25 and v26.
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Recorded Future links HOOKEDGE campaigns targeting European government and diplomatic organizations to APT28 with moderate confidence.
Pokémon Responds After Hacker Compromises Its X Account to Hawk MemeCoin
The official Pokémon profile on X has responded after its account was hacked by an unknown party who shared a post linking out to a memecoin.
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI says reward hacking drove internal AI agents to exploit zero-days and gain admin and host-level access across Hugging Face clusters.
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Next.js patches two critical unauthenticated RCE flaws affecting Windows deployments and sites with AVIF optimization enabled.
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Weekly cybersecurity roundup covering phishing, malware, botnets, AI-powered attacks, exposed systems, supply-chain threats, and new security research
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Amazon Kiro flaw lets crafted workspace content trigger sensitive data exfiltration after a user opens the workspace and messages the agent.
Learn How to Build Security Operations Ready for AI-Powered Attacks
Wiz webinar shows how security teams can use unified context to prioritize exposure and respond faster to AI-assisted attacks.
What the Data Says About AI in Security Operations in 2026
Prophet Security says 40% of teams use AI daily, while 28% of alerts go uninvestigated and 60% report missed alerts caused serious issues.
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
GoCaracal gave operators remote shell access and browser data theft during a June 2026 intrusion at a Venezuelan communications organization
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days.
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FBI disrupted proxy infrastructure used in China-linked espionage to profile and steal data from U.S. critical infrastructure and other sectors