National Cyber Warfare Foundation (NCWF)

Security Affairs newsletter Round 593 by Pierluigi Paganini INTERNATIONAL EDITION


0 user ratings
2026-09-06 08:12:11
milo
Blue Team (CND)
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attacks on U.S. and European Schools Broadcom Patches Critical VMware Workstation and Fusion […


A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.





Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.





PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Google fixes the sixth actively exploited Chrome zero-day of 2026
Dark Web Service Nexus Sells 153M+ Driver’s Licenses
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
$536 and 8 Hours: AI Learns to Attack a Different PLC
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Hackers Target Langflow in CVE-2026-0768 Attacks
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt
North Korea-linked IT Workers Are Getting Hired Inside Western Companies
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
China-linked Fire Ant Hides Inside Trusted Infrastructure
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch




International Press – Newsletter





Cybercrime





FulcrumSec claims Manchester Airports hack, theft of 86 GB of data





Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation  





FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs  





FBI Probes Service Selling 153M+ Drivers Licenses





Two Nigerian Nationals Extradited from Nigeria to the United States to Face Sextortion Charges in North Carolina and Mississippi  





The Town 2025 ticketing data sold as a Ticketmaster breach 





Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026  





Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal   





Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities





ASCII smuggling crosses over from AI prompt injection to phishing evasion





Malware





Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts





Gryxa: The AI-Built Toolkit That Watches How You Remove It





ValleyRAT masquerading as adware  





13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  





Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  





Hacking





Eclypsium flags 1,051 CVEs in infrastructure advisories 





Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP  





Kaspersky zero-day exploit HardBreacher 





PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability  





Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack 





Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet  





Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain





FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon 





Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking  





Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day





When Sorting Leads To Confusion  





Intelligence and Information Warfare  





Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist





Fire Ant Evolves: From Hypervisors to Trusted Infrastructure





Insights into Suspected DPRK Workers: Red Flags to Look Out For   





Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set  





Leaked Russian Cyber-Operations Training Materials  





Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline  





Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia





How the Russians Got Inside My Phone





DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors    





Cybersecurity





Judge says Pentagon’s measures against Anthropic were ‘illegal and baseless’  





How AI could make it harder for governments to use hacking tools  





Own a gun? Go to church? Do yoga? AI can find out in seconds        





Path to Astra: critical capabilities and frontier safeguards  





PostGREShell: The database powering much of the internet had an open door for 12 years 





Fighting AI with AI: The US’s New Cyber Rules of Engagement 





ATM Flaws Reveal Key Weaknesses in the Software Supply Chain 





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, newsletter)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/198495/breaking-news/security-affairs-newsletter-round-593-by-pierluigi-paganini-international-edition.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.