Arista Networks and F5 have released security updates for two critical zero-day vulnerabilities that are being actively exploited by attackers. Arista Networks patched CVE-2026-93952, a high-severity flaw affecting VeloCloud Orchestrator (VCO) On-Prem deployments. The vulnerability can allow remote attackers to access privileged internal VCO functions without authentication or user interaction.
Separately, F5 released updates for CVE-2026-94127, a high-risk BIG-IP Access Policy Manager (APM) vulnerability being used in remote code execution attacks.
The US CISA has flagged a high-risk JetBrains TeamCity (CVE-2026-63077) as actively exploited by ransomware gangs. The authentication bypass flaw was patched in July in TeamCity On-Premises versions 2025.11.7 and 2026.1.3.
Threat actors are targeting a high-severity Roundcube Webmail vulnerability, tracked as CVE-2026-48842, patched in May. The flaw is a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses. The Canadian Centre for Cybersecurity has also warned that threat actors are exploiting CVE-2026-65660, a code injection in Microsoft SharePoint Server.
Check Point Software has released emergency hotfixes for a critical vulnerability in its Security Management Server that could allow attackers to upload and run malicious scripts. Tracked as CVE-2026-93616, the path traversal flaw can be exploited by unauthenticated attackers to upload arbitrary scripts and execute them on vulnerable systems. Check Point says the attacks are low-complexity and that the vulnerability is already being exploited in the wild.
Cisco has released security updates addressing multiple vulnerabilities in its Secure Email products, including a critical zero-day vulnerability that is being actively exploited in the wild. The security issues affect Cisco Secure Email Gateway (SEG) and Cisco Secure Email and Web Manager (SEWM). The most serious vulnerability, tracked as CVE-2026-76461, can allow a remote, unauthenticated attacker to execute arbitrary commands with root privileges.
Volexity has released a follow-up on its report published earlier this month detailing attacks by two Chinese threat actors involving chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). In the new report, the company said that a third Chinese threat actor, tracked as UTA0565, had used the same chain of Chrome and Windows zero-day exploits.
China-linked espionage group, tracked as FamousSparrow, has been targeting government organizations across Latin America with a new backdoor called SparroWocky. ESET believes the campaign is aimed at gathering intelligence on how Latin American governments are responding to growing US pressure on Chinese economic interests.
SOCRadar Threat Research Unit (STRU) has discovered a cyber-espionage campaign dubbed ‘Operation Conflict Compass’, attributed to the North Korea-aligned threat actor, tracked as Konni. The campaign, observed in early August 2026, appears focused on organizations and individuals connected to Ukraine, with the goal of collecting intelligence about the future direction of the Russia-Ukraine war.
A joint advisory from authorities in Japan, the United States, Australia and Germany has warned that the North Korean hacking group, tracked as WaterPlum, compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026. The attackers also stole cryptocurrency from more than 7,000 wallets and transferred about $10.7 million worth of cryptocurrency to North Korea.
A Chinese-speaking threat actor linked to the Red Heron group has been exploiting known CVEs in ZyXEL GS1900 switches, WordPress, PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox, and Ubiquiti products. On August 17, the actor exploited the high-severity CVE-2026-7273 in ZyXEL GS1900 switches, compromising 996 devices across 48 countries and stealing device configurations, network information, and hashed root credentials.
Government agencies warn that an Iranian state-linked hacking group is using Windows malware called CHOSEN BRICK to spy on dissidents, activists, and journalists. The malware can steal emails and messages from Telegram and WhatsApp, take screenshots, and record audio. Attackers usually contact victims through WhatsApp or Telegram while pretending to be trusted people or technical support. They then trick victims into opening fake apps, such as Telegram, Norton Antivirus, or Adobe Flash Player, which infect the devices with the malware.
A new ClickFix campaign is targeting legitimate Ukrainian business websites. It shows fake Cloudflare verification pages that trick users into running a malicious Windows command, which installs the previously unknown Psychedelic information-stealing malware. The malware can steal browser passwords, account tokens, and cryptocurrency wallet data, maintain access through scheduled tasks, and receive additional commands from its C&C server.
A new malware campaign is using SEO-optimized GitHub repositories to impersonate LastPass and at least 39 other software companies. Researchers from LastPass and Delphos Labs say the campaign delivers a previously undocumented information stealer called Rapuncel.
A new Cisco Talos’ report details ClosedQuorum, a new Windows malware that uses multiple AI models, including Gemini, DeepSeek, Qwen, and Mistral, to autonomously decide what actions to take after compromising a system. It analyzes reconnaissance data and uses a voting system to select its next step, with DeepSeek having priority in tied votes. Talos says ClosedQuorum is the first publicly documented Windows implant to use AI models for tactical C&C decisions, potentially enabling faster and more scalable attacks.
Attackers are using Go Modules and Terraform providers to spread malware via HashiCorp’s official Terraform Registry. The campaign is believed to be linked to a North Korean hacking group and targets developers through fake Web3 companies and job offers on LinkedIn, Facebook, and forums. Victims are given coding tasks that seem legitimate but in reality introduce malware via dependencies hosted on platforms like npm and PyPI. Aikido says the attack overlaps with the Graphalgo NPM malware campaign, first reported by ReversingLabs in February 2026.
A separate Aikido research found that GitLab’s private email addresses for submitting issues can accidentally be exposed in public documentation. The addresses contain long-lasting tokens linked to developer accounts. If attackers obtain them, they may gain unauthorized access to repositories, source code, CI/CD secrets, or confidential issues.
An active TeamFiltration campaign, called ‘UNK_CondorFiltration’, targeted more than 5,700 Microsoft 365 accounts across 28 tenants, mainly in Chile’s retail and financial sectors. The attackers used 1,487 AWS IP addresses and successfully compromised 7 service accounts. The accounts had weak or unchanged passwords and did not have MFA enabled. After gaining access, the attackers attempted VPN access and accessed Microsoft services such as Azure Portal and SharePoint Online.
A new Android spyware campaign called Corp MDM is targeting the logistics sector. Attackers use fake Google Play pages that imitate companies such as CEVA and TKW Logistics to trick users into installing a malicious APK. Once installed, the spyware can secretly read SMS messages, redirect calls, and run hidden background services. According to Have I Been Squatted, the observed campaign was part of a broader operation that included credential phishing and Windows-based malware, with indicators suggesting Armenian and Russian links.
Google has confirmed that its artificial intelligence model Gemini gained unauthorized access to computer systems belonging to three real companies during a cybersecurity test in May. In one case, Gemini accessed a system by repeatedly guessing a password. In two other cases, it used login credentials that had been exposed in a public code repository. Google said all three companies were informed, but it did not name them.
OpenAI agents targeted public data systems in several countries carrying out information-retrieval tasks, according to a report by research lab Transluce. The activity included attempts to find security weaknesses in several organizations.
In one case, the agents exploited a weakness in an Australian government portal and accessed both public and non-public data. Australian Prime Minister Anthony Albanese said the incident involved a Medicare statistics portal operated by Services Australia. According to Albanese, the agents also wrote data to an internal server. He said there is currently no evidence that the incident affected individuals. He also said OpenAI did not notify Australian authorities about the unauthorized activity until September 10.
A 24-year-old member of the Scattered Spider cybercrime group reportedly pleaded guilty to fraud and identity theft charges. The group used social engineering to steal company data and cryptocurrency. He is awaiting sentencing.
Microsoft and police in the US and UK disrupted EvilTokens, a service that helped criminals steal Microsoft 365 accounts and bypass MFA. Around 12,000 email accounts were compromised, and two suspected operators were arrested in the UK.
Karen Vardanyan, an Armenian national, was sentenced in the US to two years in prison for helping carry out Ryuk ransomware attacks that stole more than $1 million. He must also pay over $1.2 million to victims.
Ardit Kutleshi, 28, pleaded guilty to helping create and operate the Rydox marketplace that offered stolen personal information and cybercrime tools. Since at least 2016, Rydox was involved in more than 7,600 transactions and generated at least $232,000. Kutleshi was arrested in Kosovo in December 2024 and extradited to the US in 2025. He pleaded guilty to aggravated identity theft and money laundering conspiracy. He is scheduled to be sentenced on February 9, 2027, and faces at least two years in prison for identity theft and up to 20 years for money laundering conspiracy.
Latvian police arrested a 23-year-old man suspected of hacking at least two companies, including TSC, a subsidiary of LMT. He allegedly exploited website vulnerabilities to steal customers’ personal data and demanded money to keep the information private. Police also found evidence of possible attacks on other companies in Latvia and abroad. The suspect could face up to five years in prison. Authorities said there is currently no evidence that the stolen data was shared with others.
Ukrainian police dismantled several online scam networks and blocked thousands of phishing websites. The suspects allegedly used fake bank, government, and shopping websites to steal money and personal information. Twenty-three people have been formally suspected.
Spanish police arrested 44 people accused of running online scams and laundering the money through cryptocurrency. At least 146 victims reportedly lost more than €430,000. Police also seized cash, cryptocurrency, bank cards, SIM cards, and electronic devices.