1. Thousands of WordPress sites are being infected by the StopAndProtect ransomware family using ClickFix social engineering techniques (https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/).
2. A critical vulnerability in the Ray distributed computing framework is currently being exploited in the wild (https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html).
3. Ransomware gangs are actively exploiting a high severity Windows Task Host vulnerability (https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/).
4. A critical flaw in the Forminator WordPress plugin allows unauthenticated remote code execution (https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html).
5. A critical GitLab GraphQL vulnerability allows unauthenticated attackers to delete public projects and user data (https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html).
6. A suspected China nexus APT group is exploiting a directory traversal flaw in VMware vCenter to deploy Babuk derived ransomware (https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html).
7. The TWINLOOT Python implant framework is abusing SharePoint and Teams to steal credentials and move laterally (https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html).
8. A threat actor is selling 3.6 million records allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies (https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/).
9. A typosquatting campaign on RubyGems is distributing a Windows based information stealer to harvest browser credentials and crypto wallets (https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html).
10. SafePal disclosed a data breach exposing personal information of nearly 40000 customers due to an authorization flaw (https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html).
11. Pokémon Center suffered a data breach after hackers compromised a third party logistics provider (https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/).
12. Researchers demonstrated that self propagating payloads can spread between AI agents through persistent prompt files (https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html).
Be First to Comment