Microsoft released its August 2026 Patch Tuesday to fix around 400 vulnerabilities, including the actively exploited zero-day (CVE-2026-68820), which can allow SYSTEM-level access. Check Point says North Korean Lazarus exploited the flaw to deploy the FudModule rootkit. Lazarus also exploited CVE-2025-49113 in Roundcube servers to deploy the RelayShell webshell.
Metabase has warned that hackers exploited a serious SQL injection vulnerability in zero-day attacks to break into customer systems and steal data. The company said its Metabase Cloud platform was targeted through a previously unknown flaw affecting versions 1.58 and later. Self-hosted installations are also vulnerable.
Threat actors are exploiting a recently disclosed Microsoft SharePoint vulnerability (CVE-2026-55040) after proof-of-concept code was released. The flaw is an authentication bypass flaw that Microsoft patched in its July 2026 security updates. If exploited, attackers can access vulnerable SharePoint servers without authentication and perform actions as a user or administrator.
Another recent flaw that has come under exploitation is CVE-2026-71362, an incorrect authorization issue in Adobe Commerce and Magento that could allow threat actors to take over customer accounts. Security researchers have already detected exploitation attempts, although Adobe said it had not seen attacks in the wild.
Also, threat actors are actively exploiting a critical security flaw in Broadcom’s VMware vCenter Server. The vulnerability, tracked as CVE-2026-59310, allows attackers with network access to use directory traversal to execute arbitrary code on affected vCenter servers. Broadcom released patches for the flaw in late July.
Microsoft Threat Intelligence has observed a financially motivated cybercriminal group, tracked as Storm-1175, deploying a new ransomware strain called StormEncryptor. Previously, the threat actor leveraged the Medusa ransomware in its attacks. Microsoft has not confirmed which vulnerability was used in the latest campaign, but Storm-1175 is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed at the beginning of this month.
Separately, Microsoft released a report detailing recent activities of the DeadLock ransomware operation, which now uses the Polygon blockchain to store configuration data and information used by its leak site.
US federal agencies and South Korea’s National Policy Agency are warning government and critical infrastructure organizations worldwide to protect their networks against Gunra ransomware attacks. The ransomware gang has been observed targeting Fortinet firewalls to get access to victims' networks using two authentication flaws (CVE-2024-55591 and CVE-2025-24472) in FortiOS and FortiProxy software. Gunra also exploits credential-exposure and Secure Shell (SSH) access control security issues in internet-facing VPN gateways to gain remote access to victims' systems.
Ukraine’s Computer Emergency Response Team (CERT-UA) has warned of a new campaign linked to the UAC-0145 threat cluster, specifically subcluster UAC-0002, also known as Sandworm, APT44, or Seashell Blizzard. The campaign uses job offers and fake recruitment processes to target system administrators and other IT professionals.
Poland’s CERT disclosed that the destructive December 2025 cyberattack attributed to Russia's FSB Center 16 targeted two power plants, including a previously unreported facility. Hackers disrupted industrial control systems managing a steam turbine and water treatment, but staff restored them before services were affected. Authorities found the attackers gained access through a FortiGate device at a wind farm, compromised a router, and moved into the plant through a mobile APN connection.
New Zealand has imposed new sanctions against Russian hackers and people involved in online disinformation. The sanctions target members of the RaHDit and Cyber Army of Russia Reborn hacktivist groups, individuals and organizations spreading disinformation, and the director of a cloud provider MediaLand linked to Russian hacking and fake news websites.
Afghan telecom providers and South Asian critical infrastructure organizations are being targeted in an ongoing campaign that leverages a new backdoor called PATCHCORD. Attackers use fake VPN installers and telecom tools to deliver the malware. The campaign also includes SHEETCORD, a Go-based backdoor that uses Google Sheets for command-and-control and targets organizations through fake domains impersonating India’s National Informatics Center (NIC).
China-based hackers-for-hire group, tracked as Jewelbug, is targeting government organizations across the Middle East and Asia. In its most recent campaign, the threat actor compromised webmail accounts at 15 government organizations. The group uses a backdoor called Antino, along with fake browser extensions and Microsoft Edge components to gain control of infected computers. The same infrastructure is also linked to a large-scale cryptocurrency fraud operation.
A data-theft campaign called City-Forum is targeting organizations worldwide via misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The attacks don’t involve exploitation of any Salesforce or ServiceNow vulnerability—the threat actors are simply using organizations’ data accidentally made available to anonymous guest users through weak permissions, sharing rules, or portal settings.
More than 737 Chrome extensions were found impersonating popular VPN and proxy services, routing users’ traffic through SOCKS5 proxies controlled by a single provider. The extensions mimicked well-known brands such as Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1. Researchers found that the campaign used 40 publisher accounts and a shared analytics account. The extensions were downloaded nearly 75,000 times, mostly by Russian users seeking to bypass blocked services. The campaign appears to have been designed to direct users toward a paid VPN service in Russia.
Researchers spotted a new Linux-based malware called Evooo1Bot linked to the Mirai botnet. The malware targets devices from several manufacturers, including D-Link, Netgear, Tenda, and others. It can spread through unpatched vulnerabilities and perform DDoS attacks. It also scans for vulnerable devices, searches for unchanged default passwords, and communicates with attackers via encrypted connections. Researchers have detected Evooo1Bot activity in North and South America, Europe, India, China, and Japan.
Hardware wallet maker Trezor disclosed a data breach affecting nearly 14,000 customers after its shipping provider ShipMonk was hacked. The attackers accessed customers’ names, addresses, emails, and phone numbers. Trezor said its own systems and devices were not compromised and remain secure.
Mozilla has updated the GPG signing key used for some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. Mozilla said the risk of a supply chain attack is low because access to the repository was limited to a small group of employees. The company also said it found no evidence that an unauthorized person accessed the exposed key.
The US government is launching a program that will allow private US cybersecurity companies to take part in government-authorized operations against foreign cybercrime groups. Contractors will be authorized to break into criminal networks, gather intelligence, and disrupt or damage digital infrastructure. Each operation will require prior approval from the US Department of Justice and Department of Homeland Security.
Croatian authorities have reportedly arrested 33-year-old Serbian businessman suspected of hacking several Croatian government institutions and public databases. The targets reportedly included the Interior Ministry, Tax Administration, and automobile, pension, and health insurance systems. Croatian officials suspect he worked for Serbia’s intelligence agency BIA.
A South Korean court sentenced two executives of a data recovery company to three years in prison each for working with a ransomware group. The company helped victims recover encrypted files and sent part of their payments to the hackers in Bitcoin. From 2018 to 2022, the scheme handled 730 cases and earned about 2.6 billion won (€1.5 million).
Spain’s National Police arrested a cybercriminal who allegedly used artificial intelligence to fool a digital identity verification system. The suspect changed his face in real time during video calls to impersonate other people and made 38 attempts using more than 30 identities. He also used fake IDs, manipulated photos, VPNs, and many mobile phones to hide his identity. Police believe he wanted to obtain valid digital signatures that could later be used for financial fraud.
Ukrainian law enforcement agencies have shut down 94 fraudulent call centers in a nationwide operation. Police conducted 411 searches and charged 26 suspects. Authorities seized thousands of computers and phones, over 5,200 SIM cards, large amounts of cash, cryptocurrency access tools, cars, gold and other assets. The call centers used scams involving fake bank employees, investments and law enforcement officers to steal money and banking information. Some operations targeted victims abroad. Suspects face fraud and money-laundering charges and could receive up to 12 years in prison and have their property confiscated.
A 20-year-old British man, Justin Swaddle, has been jailed for two years for abusing 117 girls aged 13–17 online. He used Snapchat, Telegram and Discord to threaten and manipulate victims into sending sexual images and harming themselves. He was part of an online “Com” group whose members pressure victims into self-harm and sexual abuse for the recognition among peers. Swaddle pleaded guilty and will also be monitored as a sex offender for 10 years.