Press "Enter" to skip to content

OSINT / CyberSec report 05.08.2026 00:07

1. CISA added the high severity authentication bypass vulnerability CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed (The Hacker News).

2. INC Ransomware is identified as the primary threat actor exploiting security flaws in SonicWall SMA 1000 series VPN appliances (The Hacker News).

3. Microsoft linked a global campaign targeting hospitality Wi-Fi networks to the Russian state-sponsored actor Midnight Blizzard, which uses custom malware to breach Microsoft 365 accounts (Bleeping Computer).

4. A data breach at the Police National Legal Database in the UK exposed contact information for over 100,000 police officers and criminal justice professionals (Bleeping Computer).

5. A firmware vulnerability in COLDCARD hardware wallets allowed attackers to exploit a random number generator flaw, resulting in the theft of over 88 million dollars in Bitcoin (Bleeping Computer).

6. Security researchers identified three new attack paths known as Pass-ta-key that allow malware on compromised Windows devices to hijack Google Password Manager synced passkeys (Bleeping Computer).

7. A new Russian loader-as-a-service named DOUBLECUP is using ClickFix attacks to hide malicious code in browser cache images to deliver remote access trojans (Bleeping Computer).

8. A Chinese-speaking threat actor is targeting Apple iOS devices by weaponizing a leaked version of the DarkSword exploit kit (The Hacker News).

9. Eighteen malicious npm packages were discovered targeting Alibaba developer tool users with a cross-platform remote access trojan (The Hacker News).

10. A cyberattack on Minnesota IT Services disrupted operations at more than 30 community water utilities and affected industrial control systems (Check Point).

11. Biotech firm Amgen reported that patient data and proprietary information were accessed through a breach of third-party cloud systems (The Record).

12. Hackers compromised 31,000 records identifying individuals behind companies and foundations in Liechtenstein, leading the government to form a crisis unit (The Record).

13. Three high-severity vulnerabilities in the Hugging Face Diffusers library were disclosed that could allow arbitrary code execution on machines loading malicious model repositories (The Hacker News).

14. Thermo Fisher Scientific patched a critical flaw, CVE-2026-17583, in its human identification software that could allow for undetectable tampering with DNA data files (The Hacker News).

15. Scammers are distributing fake IRS letters to cryptocurrency holders to trick them into registering on a fraudulent Digital Asset Compliance Portal (Bitdefender).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *