National Cyber Warfare Foundation (NCWF)

Security Affairs newsletter Round 591 by Pierluigi Paganini INTERNATIONAL EDITION


0 user ratings
2026-08-23 08:56:55
milo
Blue Team (CND)
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries Malware Hijacks Android Car Head Units […


A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.





Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.





ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
Malware Hijacks Android Car Head Units
Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution
U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
Your Shredded Visa Card May Still Work at the Checkout
Six Maximum-Severity Flaws Found in Cisco Products
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains
50,000 Stripe Secrets Leaked in Public Code
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Hackers Expose Data of 1.2 Million Heights Finance Customers
Project noRecognition: Teaching AI to Fool Surveillance Cameras
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
SafePal Says 39,798 Customers Hit by Data Breach
LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
Invisible AI Prompts Trigger Court Sanctions
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
Akira Ransomware Uses Safe Mode to Bypass EDR
DDoS Attacks Cause Major Threema Outages
Mustang Panda Upgrades CoolClient With a Kernel Rootkit
Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2




International Press – Newsletter





Cybercrime





McDonald’s employee data listed for sale in wider Entra campaign      





$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret 





Live Stripe keys for 659 merchants, published for free  





Clop Returns with Custom Implant in Mass-Extortion Campaign  
Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation       





Malware





Akira Hits Safe Mode: Ransomware Rebooting Around EDR 





Hunting MacSync Stealer infrastructure through behavioral pivots 





Manic: Blend between Banking Malware & Spyware  





The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile





The invisible passenger in your car





Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign  





Hacking





Large-scale DDoS attacks disrupted Threema secure messaging service





The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign via a Backdoored Trivy GitHub Action  





Actively exploited vulnerability in Zimbra Collaboration Suite





AI-assisted tool helped secure satellite communication system after 2022 Russian hacking





Expired credit cards revived by researchers to make unauthorized payments     





CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks





When the NASA Ground Station Has No Lock on the Door: Unauthenticated Command Execution in AIT-GUI (GHSA-p9r8-2q67-fp86)      





Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories  





Intelligence and Information Warfare  





Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia 





17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities  





Defending Against an Active Threat to Siemens S7 Series PLCs  





Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns  





Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia  





SilkParasite: Tracking a China-Nexus APT Across Central Asia





Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network    





Cybersecurity





France probes unprecedented cyberattack after tax data of 678,000 users stolen 





Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them  





SafePal Unauthorized Access To A Subset Of Customer Order Information 





This ‘adversarial’ pattern can prevent surveillance cameras from detecting you 





France’s cybersecurity problem demands strong political will  





The Powerful Chinese AI Model Experts Warned About—and Waited for—Is Here 





OpenAI president says companies should do 10 things ASAP to defend against AI cyber threats 





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, newsletter)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/197728/breaking-news/security-affairs-newsletter-round-591-by-pierluigi-paganini-international-edition.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.