Press "Enter" to skip to content

OSINT / CyberSec report 15.08.2026 00:07

1. Lazarus Group exploited a Windows zero day vulnerability to deploy backdoors against defense and aerospace firms in a campaign known as Operation Dream Job (bleepingcomputer.com).

2. Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint identified as CVE 2026 55040 following the release of proof of concept code (thehackernews.com).

3. A critical remote code execution flaw in VMware vCenter Server identified as CVE 2026 59310 is being actively exploited to deploy reverse SSH tools for persistence (bleepingcomputer.com).

4. Hackers are targeting Adobe Commerce and Magento platforms by exploiting a critical vulnerability to hijack customer accounts (bleepingcomputer.com).

5. Adobe released security patches for three critical vulnerabilities in ColdFusion and Campaign Classic that carry a CVSS score of 10.0 (thehackernews.com).

6. Microsoft patched a Windows zero day vulnerability known as LegacyHive that was disclosed after the July 2026 Patch Tuesday (bleepingcomputer.com).

7. A new Microsoft Defender zero day exploit named ShieldBreak has been released which grants attackers SYSTEM privileges (bleepingcomputer.com).

8. The Jewelbug hacker group is conducting espionage operations against government and military entities while simultaneously running cryptocurrency fraud schemes (bleepingcomputer.com).

9. An Akira ransomware affiliate successfully bypassed endpoint detection and response software by restarting a compromised system into Safe Mode with Networking (bleepingcomputer.com).

10. A data theft campaign is targeting Salesforce and ServiceNow portals by using custom tools to extract data exposed to anonymous users (bleepingcomputer.com).

11. Over 737 malicious Chrome VPN extensions were discovered impersonating legitimate services to intercept and route user traffic through proxy infrastructure (thehackernews.com).

12. Researchers identified a flaw in OpenAI, Anthropic, and Google APIs that allowed the recovery of internal reasoning and sensitive session data from AI models (thehackernews.com).

13. Hardware wallet manufacturer Trezor reported a data breach affecting nearly 14000 customers following a security incident at its logistics provider ShipMonk (bleepingcomputer.com).

14. Ukrainian authorities dismantled 94 fraudulent call centers that were used to conduct investment scams and gain unauthorized access to bank accounts (bleepingcomputer.com).

15. Apple issued new threat notifications to users regarding mercenary spyware attacks targeting iPhones (bleepingcomputer.com).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *