> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 23/08/2026 08:29] [LANGUAGE: EN]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 CountriesMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogYour Shredded Visa Card May Still Work at the CheckoutSix Maximum-Severity Flaws Found in Cisco ProductsFake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage TacticsGitLab Warns of Active Exploitation of Critical GraphQL FlawPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawU.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalogCl0p Targets 40+ Organizations Through PTC Windchill FlawManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalogUS Indicts 17 Iranians Over Years-Long Cyber Espionage CampaignStopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal NetworkInside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua CamerasMicrosoft Tracks MacSync Stealer by Its Behavior, Not Its Domains50,000 Stripe Secrets Leaked in Public CodeU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalogHackers Expose Data of 1.2 Million Heights Finance CustomersProject noRecognition: Teaching AI to Fool Surveillance CamerasGitLab Patches Critical Unauthenticated GraphQL VulnerabilityU.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalogNew Mirai-Based Evooo1Bot Botnet Targets Linux DevicesSafePal Says 39,798 Customers Hit by Data BreachLiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most AffectedInvisible AI Prompts Trigger Court SanctionsMcDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records StolenAkira Ransomware Uses Safe Mode to Bypass EDRDDoS Attacks Cause Major Threema OutagesMustang Panda Upgrades CoolClient With a Kernel RootkitSophisticated Cyberattack Exposes Data of 678,000 French TaxpayersAPT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 International Press – Newsletter Cybercrime McDonald’s employee data listed for sale in wider Entra campaign       $7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret  Live Stripe keys for 659 merchants, published for free   Clop Returns with Custom Implant in Mass-Extortion Campaign  Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation        Malware Akira Hits Safe Mode: Ransomware Rebooting Around EDR  Hunting MacSync Stealer infrastructure through behavioral pivots  Manic: Blend between Banking Malware & Spyware   The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile The invisible passenger in your car Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign   Hacking Large-scale DDoS attacks disrupted Threema secure messaging service The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign via a Backdoored Trivy GitHub Action   Actively exploited vulnerability in Zimbra Collaboration Suite AI-assisted tool helped secure satellite communication system after 2022 Russian hacking Expired credit cards revived by researchers to make unauthorized payments      CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks When the NASA Ground Station Has No Lock on the Door: Unauthenticated Command Execution in AIT-GUI (GHSA-p9r8-2q67-fp86)       Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories   Intelligence and Information Warfare   Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia  17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities   Defending Against an Active Threat to Siemens S7 Series PLCs   Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns   Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia   SilkParasite: Tracking a China-Nexus APT Across Central Asia Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network     Cybersecurity France probes unprecedented cyberattack after tax data of 678,000 users stolen  Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them   SafePal Unauthorized Access To A Subset Of Customer Order Information  This ‘adversarial’ pattern can prevent surveillance cameras from detecting you  France’s cybersecurity problem demands strong political will   The Powerful Chinese AI Model Experts Warned About—and Waited for—Is Here  OpenAI president says companies should do 10 things ASAP to defend against AI cyber threats  Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
[messages.read_original_source] →