Press "Enter" to skip to content

OSINT / CyberSec report 25.08.2026 00:04

1. The Chinese speaking cybercrime group UAT 10147 is using AI to scale attacks against web servers in the education and technology sectors (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html).

2. UAT 10147 deploys the SPECTRE malware alongside EDR bypass techniques and a Linux rootkit to maintain persistence (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html).

3. The ToxicPanda Android malware has been updated to target 349 applications and now utilizes VPN permissions to block Google Play (https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/).

4. A supply chain attack is infecting Android based car head units with malware that turns devices into a proxy botnet (https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/).

5. TrueConf server vulnerabilities that allow attacks on meeting participants have been added to the CISA Known Exploited Vulnerabilities catalog (https://www.reddit.com/r/cybersecurity/comments/1vwdq35/trueconf_flaws_enabling_attacks_on_meeting/).

6. The Head Mare campaign is actively transforming TrueConf servers into platforms for malware distribution (https://www.reddit.com/r/cybersecurity/comments/1vwj0cv/head_mare_transforma_servidores_trueconf_em/).

7. TikTok has agreed to a 400 million dollar settlement regarding a lawsuit over child privacy law violations in the United States (https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html).

8. Microsoft has released a temporary fix for Windows 11 gaming performance issues introduced by the August 2026 Patch Tuesday updates (https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-temporary-fix-for-windows-11-gaming-issues/).

9. Researchers identified a critical vulnerability in Microsoft Entra ID that impacts cloud identity security (https://www.reddit.com/r/cybersecurity/comments/1vvnv7s/critical_microsoft_entra_id_vulnerability_raises/).

10. New research highlights that unprotected Time Sensitive Networking protocols in industrial environments could allow attackers to manipulate physical processes (https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protocol-family-put-ot-at-risk).

11. Security researchers demonstrated a Spectre based attack against Cloudflare Workers that leaks JSON Web Tokens at a rate of 12 bits per second (https://www.reddit.com/r/cybersecurity/comments/1vu5r6h/cloudflare_workers_spectre_attack_leaks_jwt_at_12/).

12. Investigations revealed that the Grok AI model can be manipulated to exfiltrate user data when malicious instructions are encrypted (https://www.reddit.com/r/cybersecurity/comments/1vug0v1/grok_exfiltrates_user_data_when_malicious/).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *