LIVE · cybersecurity feed
Live wire
CVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreCISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
breach

24th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The […] The post 24th August – Threat

zeroday.news ·

Several organizations have recently confirmed data breaches and system compromises, while cybersecurity researchers have identified critical vulnerabilities in widely used software and observed new tactics involving artificial intelligence in cyberattacks.

Latvia's Road Traffic Safety Directorate (CSDD) confirmed a breach impacting payment records for over 1.2 million individuals, representing approximately two-thirds of the country's population, as well as 200,000 organizations. The stolen data includes identification numbers, license plates, payment amounts, dates, and addresses. Attackers reportedly exploited a vulnerability in an internet-facing system.

In Japan, cloud and hosting provider Sakura Internet disclosed unauthorized access to its rental server environments and a separate sales management system, potentially exposing up to 1.36 million customer accounts. Attackers also accessed hundreds of rental server accounts and installed malware. Canada's Hospital for Sick Children, a major pediatric hospital, reported data theft from a third-party application used for its careers website, affecting information belonging to employees, applicants, and staff at related organizations. The hospital stated that clinical systems and patient information were not impacted.

Berlin authorities isolated the city’s urban development and mobility ministries from government IT networks following a security breach. This measure disrupted email and internet access, forcing employees to use alternative communication channels and delaying public services while the ministries remained disconnected.

Researchers demonstrated an autonomous AI agent exploiting a GitHub Actions flaw in Snowflake’s public repository, gaining read access to the company’s internal Jira system and exfiltrating tokens within seconds without human intervention. Snowflake subsequently patched the workflow and rotated credentials. US authorities have also warned of active AI-assisted attacks targeting Siemens S7 industrial controllers in critical sectors like manufacturing, energy, and water. Attackers are using AI-generated scripts disguised as monitoring tools and open-source libraries to probe internet-exposed systems, attempting to cause unauthorized configuration changes, operational disruption, or damage to industrial equipment.

Further analysis revealed 'Kriminal,' a publicly accessible AI platform marketed as uncensored, offering social engineering and exploit assistance through cryptocurrency subscriptions. The service combines models such as Grok, Claude, and Llama, enabling users to generate phishing content, malicious code, and other cybercrime material, thereby reducing reliance on a single provider.

In terms of vulnerabilities, GitLab released out-of-band fixes for CVE-2026-19478, a critical unauthenticated code injection vulnerability (CVSS 9.4) affecting self-managed Community and Enterprise editions. This flaw could allow remote attackers to alter or delete public projects and user data, with exploitation attempts observed after disclosure. Cisco issued fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, including six rated CVSS 10.0, addressing authentication, access-control, and file-system weaknesses.

Citrix published patches for CVE-2026-19489 and CVE-2026-19490 affecting NetScaler ADC and NetScaler Gateway. The first is a critical authentication bypass flaw that could allow unauthenticated attackers to access appliances configured with SAML authentication, while the second can cause a denial of service. NASA/JPL fixed a critical vulnerability (CVSS 9.4) in the open-source AMMOS Instrument Toolkit (AIT-GUI) that enables unauthenticated command execution through its web console, allowing remote command execution, script launches, and sequence execution. AIT-GUI version 2.5.2 contains the fix.

Researchers have investigated the "StopAndProtect" campaign, which abuses thousands of compromised WordPress sites to distribute malware and store stolen data, combining ransomware with data theft and using a "ClickFix" technique to infect visitors. Operational mistakes exposed logs, screenshots, and victim IP addresses. Another investigation revealed that Microsoft's Windows Defender Boot-Time Removal driver, BTR.sys, a signed remediation component, can be repurposed to perform privileged file and registry changes during startup. Researchers developed BTR_CLI to craft encrypted tasks and found that multiple versions share a hard-coded RC4 key.

Ahead of the school year, the education sector has seen increased targeting, with organizations averaging 4,696 weekly attacks from January through July 2026, an 8% increase. Attackers registered education-themed domains and used seasonal phishing lures impersonating schools and student reward programs to steal credentials. Finally, a Cl0p extortion campaign exploiting CVE-2026-12569 in PTC Windchill and FlexPLM has been tracked, with over 40 organizations named by the group. Analysis identified a custom implant capable of decrypting credentials, accessing databases, and supporting bulk data theft from compromised product lifecycle management environments.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise already finds and verifies leaked credentials across 800+ secret types, and with TruffleHog Analyze, it can also provide

breach

HOL Guard: Open-source antivirus for AI agents

HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files are never uploaded, and the whole thing works with no internet connection. The people exposed here ar

CVE-2026-21962

CISA Warns of Exploited Oracle WebLogic Vulnerability

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek.

CVE-2026-21962critical

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

ai

AI supply chain risk is showing up in developer workflows first

In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. He explains why segmentation buys more risk reduction per dollar than tooling, where self-hostin

ransomware

The cybercrime supply chain has five stages, each with a price

In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers who verify and resell access, ransomware-as-a-service operators who build the toolkit, affiliates who run the intrusion, a