LIVE · cybersecurity feed
Live wire
CVE-2026-19478high

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

This week's cybersecurity landscape features AI-powered attacks targeting industrial control systems, a critical vulnerability in GitLab being actively exploited, and the discovery of trojanized npm packages delivering a sophisticated Linux backdoor. Additionally, researchers revealed a method to exploit expired credit cards for contactless payments, and several other vulnerabilities across various software platforms were highlighted.

zeroday.news ·

This week's cybersecurity reporting highlights several significant threats, including the emergence of AI-powered attacks against industrial control systems (ICS), active exploitation of a critical vulnerability in GitLab, and the discovery of trojanized npm packages distributing a sophisticated Linux backdoor. Further reports detailed a novel method for exploiting expired credit cards in contactless payment systems, alongside various other software vulnerabilities.

The reported AI-powered attacks on industrial control systems represent a concerning evolution in the threat landscape for critical infrastructure. While specific mechanisms were not detailed, such attacks typically leverage AI or machine learning models to enhance reconnaissance, automate exploit generation, or dynamically adapt attack strategies against programmable logic controllers (PLCs) and other operational technology (OT) components. This could involve intelligent fuzzing, anomaly evasion, or even autonomous decision-making within the attack chain, potentially leading to disruption, manipulation, or sabotage of industrial processes.

The critical vulnerability in GitLab, now under active exploitation, poses a significant risk to organizations using the platform for software development and version control. While the exact nature of the flaw was not specified, critical vulnerabilities in such systems often involve remote code execution, authentication bypass, or privilege escalation. Successful exploitation could grant attackers unauthorized access to source code repositories, CI/CD pipelines, or sensitive developer credentials, leading to supply chain attacks or intellectual property theft. Users are typically advised to apply patches immediately and review logs for signs of compromise.

The discovery of trojanized npm packages delivering a sophisticated Linux backdoor points to ongoing risks within the software supply chain. Attackers often inject malicious code into popular open-source packages, which are then unknowingly incorporated into legitimate applications. The "sophisticated Linux backdoor" likely refers to malware designed for persistence, command and control, data exfiltration, or further compromise of Linux-based systems. Developers are generally urged to exercise caution when integrating third-party packages, verify package integrity, and utilize supply chain security tools.

The reported method for exploiting expired credit cards for contactless payments reveals a novel attack vector in financial systems. This type of vulnerability typically targets weaknesses in the payment terminal's validation process or the underlying payment protocol, allowing transactions to proceed even when the card's validity period has elapsed. Such exploits could lead to unauthorized transactions and financial fraud, underscoring the need for robust validation mechanisms in point-of-sale systems and payment gateways.

Mitigation for these diverse threats generally involves a multi-layered approach. For ICS, this includes network segmentation, robust access controls, continuous monitoring for anomalous behavior, and potentially AI-driven defense mechanisms to counter AI-powered attacks. For software platforms like GitLab, prompt patching, strong authentication, and security audits are paramount. Supply chain attacks via npm packages necessitate careful dependency management, code signing, and vulnerability scanning. For payment systems, regular security audits, updated terminal software, and strict adherence to payment card industry (PCI) standards are crucial.

Collectively, these incidents underscore the dynamic and expanding nature of cybersecurity threats across various sectors. From the evolving sophistication of AI in offensive operations to persistent supply chain risks and novel payment system exploits, the landscape demands continuous vigilance, rapid response capabilities, and proactive security measures from organizations and individuals alike.

aiplcgitlabnpmcredit card fraud
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a vendor for evidence against a written baseline. TCG’s requirements for Trusted Platfor

nation-state

Cybersecurity jobs available right now: August 25, 2026

Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court orders, and provide authorized subscriber, location, and call record information while acting as custodian of

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.