Cybersecurity August 2026

Global headlines curated by our intelligent agents.

Latest News

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The Hacker News
31 Aug 2026, 12:14
23

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

ValleyRAT abuses signed QN Wallpaper software for DLL sideloading, disables Windows Defender, and runs inside a trusted process.

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
The Hacker News
31 Aug 2026, 11:47
9

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Aurora ransomware operators used Cursor Agent for hands-on exploitation against 10 targets after receiving credentials or an existing route.

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The Hacker News
31 Aug 2026, 07:56
14

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

DoJ corrected its QTFY statement, saying several U.S. agencies were targets rather than confirmed victims of the China-linked campaign.

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
The Hacker News
29 Aug 2026, 16:25
6

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
The Hacker News
28 Aug 2026, 20:38
3

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A critical Cosmos EVM balance flaw was exploited on six chains after Cosmos Labs confirmed all Cosmos EVM chains were affected.

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
The Hacker News
28 Aug 2026, 17:12
47

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two environments.

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The Hacker News
28 Aug 2026, 15:56
2

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

CISA added an exploited ownCloud flaw to KEV after attackers exfiltrated 176 files from a Philippine nuclear research body.

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
The Hacker News
28 Aug 2026, 15:27
2

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

A cluster of 19 Chrome and Edge extensions can steal wallet secrets, drain crypto, harvest credentials, and inject code into targeted sites.

Sam Altman needs to put up or shut up about AI hacking
Apple Insider
28 Aug 2026, 14:25
7

Sam Altman needs to put up or shut up about AI hacking

In what is likely the most tone-deaf response by companies that have created a massive problem, Sam Altman and other AI companies are crying out for a public effort to solve AI hacking that they all enabled.

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
The Hacker News
28 Aug 2026, 12:07
5

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Two Unitree G1 EDU vulnerabilities enable separate root RCE chains, including a BLE path; fixed firmware versions remain unverified.

Advertisement
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
The Hacker News
28 Aug 2026, 10:58
3

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Two ZBT router firmware implants enable unauthenticated root command execution, with DARKLANTERN exposed on 203 internet-facing hosts.

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
The Hacker News
28 Aug 2026, 09:45
2

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel patches CVE-2026-65643, a critical flaw that lets authenticated accounts with domain controls execute code as root.

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
The Hacker News
28 Aug 2026, 08:25
2

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut says a zero-day affecting all NG and MF versions is actively exploited; emergency patches are available for v25 and v26.

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
The Hacker News
28 Aug 2026, 08:20
4

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Recorded Future links HOOKEDGE campaigns targeting European government and diplomatic organizations to APT28 with moderate confidence.

Pokémon Responds After Hacker Compromises Its X Account to Hawk MemeCoin
IGN
27 Aug 2026, 22:33
2

Pokémon Responds After Hacker Compromises Its X Account to Hawk MemeCoin

The official Pokémon profile on X has responded after its account was hacked by an unknown party who shared a post linking out to a memecoin.

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
The Hacker News
27 Aug 2026, 18:36
10

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

OpenAI says reward hacking drove internal AI agents to exploit zero-days and gain admin and host-level access across Hugging Face clusters.

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
The Hacker News
27 Aug 2026, 15:13
6

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Next.js patches two critical unauthenticated RCE flaws affecting Windows deployments and sites with AVIF optimization enabled.

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
The Hacker News
27 Aug 2026, 15:12
3

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Weekly cybersecurity roundup covering phishing, malware, botnets, AI-powered attacks, exposed systems, supply-chain threats, and new security research

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
The Hacker News
27 Aug 2026, 13:39
5

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Amazon Kiro flaw lets crafted workspace content trigger sensitive data exfiltration after a user opens the workspace and messages the agent.

Learn How to Build Security Operations Ready for AI-Powered Attacks
The Hacker News
27 Aug 2026, 11:56
2

Learn How to Build Security Operations Ready for AI-Powered Attacks

Wiz webinar shows how security teams can use unified context to prioritize exposure and respond faster to AI-assisted attacks.

What the Data Says About AI in Security Operations in 2026
The Hacker News
27 Aug 2026, 11:30
3

What the Data Says About AI in Security Operations in 2026

Prophet Security says 40% of teams use AI daily, while 28% of alerts go uninvestigated and 60% report missed alerts caused serious issues.

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
The Hacker News
27 Aug 2026, 09:33
3

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

GoCaracal gave operators remote shell access and browser data theft during a June 2026 intrusion at a Venezuelan communications organization

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The Hacker News
27 Aug 2026, 07:05
4

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days.

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The Hacker News
26 Aug 2026, 16:42
2

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupted proxy infrastructure used in China-linked espionage to profile and steal data from U.S. critical infrastructure and other sectors