Press "Enter" to skip to content

OSINT / CyberSec report 19.08.2026 05:41

1. Thousands of WordPress sites are being infected by the StopAndProtect ransomware family using ClickFix social engineering techniques (https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/).

2. A critical vulnerability in the Ray distributed computing framework is currently being exploited in the wild (https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html).

3. Ransomware gangs are actively exploiting a high severity Windows Task Host vulnerability (https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/).

4. A critical flaw in the Forminator WordPress plugin allows unauthenticated remote code execution (https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html).

5. A critical GitLab GraphQL vulnerability allows unauthenticated attackers to delete public projects and user data (https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html).

6. A suspected China nexus APT group is exploiting a directory traversal flaw in VMware vCenter to deploy Babuk derived ransomware (https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html).

7. The TWINLOOT Python implant framework is abusing SharePoint and Teams to steal credentials and move laterally (https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html).

8. A threat actor is selling 3.6 million records allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies (https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/).

9. A typosquatting campaign on RubyGems is distributing a Windows based information stealer to harvest browser credentials and crypto wallets (https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html).

10. SafePal disclosed a data breach exposing personal information of nearly 40000 customers due to an authorization flaw (https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html).

11. Pokémon Center suffered a data breach after hackers compromised a third party logistics provider (https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/).

12. Researchers demonstrated that self propagating payloads can spread between AI agents through persistent prompt files (https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *