National Cyber Warfare Foundation (NCWF)

Security Affairs newsletter Round 590 by Pierluigi Paganini INTERNATIONAL EDITION


0 user ratings
2026-08-16 08:47:54
milo
Blue Team (CND)
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited […


A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.





Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.





Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
Apple warned hundreds of users of mercenary spyware attacks
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping
US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
ExfilSquad Targets New Victims, Shares Data via Torrents
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
The inconvenient truth about AI pentesting: someone has to check all the work
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Gym Booking Task Turns Into Real-World AI Cyberattack
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools




International Press – Newsletter





Cybercrime





ExfilSquad Targets New Victims, Shares Data via Torrents  





Israeli population registry for sale, but the data is old  





Before Fraud Transacts  





ExfilSquad Targets New Victims, Shares Data via Torrents





Fake CAPTCHA, Real Business: Traffic Distribution for Hire  





7.3M chess.com records leaked, and the data is real





Drop Something? Don’t Worry, Someone Caught it      





Malware





ShieldBreak – August 2026 disclosure  





Kimwolf v7: An Evolution of the Kimwolf Botnet 





AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers  





Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme  





737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection  





Hacking





Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations  





AI assistant hacks gym website in first known Australian autonomous cyber attack  





Zoomsday





Attackers Exploit SharePoint Authentication Bypass After Public PoC Release





Hackers exploit macOS Screen Sharing flaw to deploy Monero miner





It’s a pre-auth, stupid!  





A root remote command execution on macOS with M5 in 2026?





Intelligence and Information Warfare  





Follow-Up Analysis of the 29 December 2025 Energy Sector Incident    





New Jersey, Alabama Join States Targeted in Water Cyberattacks 





Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM  





China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack  





State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit  





Social engineering performed by UAC-0145: compromising in the employment process 





Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side  





PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure 





APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit





North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring





How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved  





Cybersecurity





How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta





Responding to the next frontier of critical cyber capabilities      





Facebook is paying controversial creators to produce rage-bait content  





Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC  





The August 2026 Security Update Review 





Cyberattack on logistics giant CEVA delivers customer data into the wrong hands





About Apple threat notifications and protecting against mercenary spyware





If Apple sends you a push notification alerting you to a spyware attack, take it seriously 





AI isn’t changing how companies work. It’s changing what a company is 





Swarms of OpenAI systems set up their own chatrooms to discuss and carry out hacks, company reveals 





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, newsletter)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/197288/breaking-news/security-affairs-newsletter-round-590-by-pierluigi-paganini-international-edition.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.