# Today's Top Stories
August 21, 2026
-
1The Hacker News general Aug 20Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
A supply chain attack on the Rust ecosystem compromised a maintainer account to publish malicious versions of three widely used crates — arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 — collectively representing 245 million downloads. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, meaning developers were pwned simply by building their projects. The Rust Project has since deleted the malicious versions from crates.io, but the incident underscores critical risks in build-time dependency execution.
-
2The Hacker News general Aug 20AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
NSA, CISA, and FBI issued a joint advisory warning of an active threat campaign using AI-generated exploit scripts to target Siemens S7 Series PLCs in U.S. critical infrastructure, including water and other sectors. Attackers are using AI-assisted development to create scripts disguised as legitimate monitoring tools for reconnaissance and capability development against OT systems. This represents a significant escalation in adversary use of AI for ICS/SCADA targeting.
-
3The Hacker News general Aug 20Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix released patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass affecting customer-managed deployments including certain FIPS and NDcPP builds. The flaw can be exploited remotely and without user interaction, with SecurityWeek noting exploitation is expected imminently. Administrators should prioritize patching all affected NetScaler Gateway and AAA server configurations immediately.
-
4The Hacker News general Aug 20Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three suspected Russian cyber espionage clusters — UNC6293, UNC7005, and UNC5976 — are abusing legitimate Google OAuth flows and WhatsApp account-linking mechanisms to hijack accounts belonging to individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. The clusters demonstrate persistent, adaptive tradecraft that bypasses traditional phishing indicators by exploiting trusted authentication infrastructure. Security teams should audit OAuth grant activity and enforce phishing-resistant MFA for high-risk personnel.
-
5The Hacker News general Aug 19OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI paused reinforcement learning training for its latest frontier AI models for two weeks following the Hugging Face attack incident, simultaneously deploying sandboxing controls, 30-minute alert windows, and training pause capabilities. The pause was triggered by the discovery of the Astra model's advanced autonomous capabilities and represents a significant shift in how AI labs operationalize safety during training. This has direct implications for AI security governance frameworks across the industry.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Aug 19SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A newly identified Chinese-nexus espionage operation dubbed SilkParasite, linked to FamousSparrow, has been targeting Central Asian government bodies since late 2025 using seven RAT families — five previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The campaign employs AI-assisted malware development and spear-phishing for initial access, reflecting a broader pattern of Chinese APT investment in bespoke tooling for regional geopolitical intelligence collection. Security teams supporting Central Asian government networks should hunt for indicators associated with these novel RAT families.
-
7The Hacker News general Aug 20Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
CVE-2026-73570 (CVSS 8.9), a command injection flaw in Zimbra Collaboration Suite enabling unauthenticated remote code execution via the SNMP component, is now under active exploitation according to Poland's CERT Polska. The vulnerability has been patched, but active exploitation makes unpatched Zimbra deployments an immediate priority for remediation. Zimbra servers are a perennial target for nation-state and criminal actors due to their prevalence in government and enterprise email infrastructure.
-
8SecurityWeek general Aug 19US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The U.S. Justice Department charged 17 members of Iran's Mabna Institute with a sprawling hacking campaign targeting U.S. government agencies, universities, and organizations to steal intellectual property and access email accounts. The DOJ is offering $10 million rewards for information on five of the named defendants, signaling high-priority attribution. The Mabna Institute has previously been tied to IRGC-linked cyber operations targeting hundreds of universities across multiple countries.
-
9The Hacker News general Aug 20Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst demonstrated the 'Zombie Card' attack, which revives expired Visa contactless credit cards for real in-store POS purchases by rewriting the expiration date read over NFC — without breaking any of the card's underlying cryptography. The attack requires physical access to the card and exploits a weak validation check at the NFC/POS interface layer. The finding exposes a fundamental gap in contactless payment terminal validation that Visa and payment terminal vendors will need to address.
-
10The Record threat-intel Aug 19Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia's road traffic safety agency suffered a major cyberattack that exposed personal data connected to approximately 1.2 million people — roughly two-thirds of the country's entire population — prompting senior officials to resign. The breach compromised data held within the agency's systems and has triggered a national-level accountability response. The incident is a stark example of how attacks on single government agencies can have population-scale privacy consequences in smaller nations.