# Archive
Browse past daily curated stories
Friday, August 14, 2026
-
1The Hacker News generalLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus Group (North Korea) exploited a Windows zero-day as part of Operation Dream Job to deploy a previously undocumented backdoor called ForestTiger against defense and aerospace companies in France, Germany, Brazil, and India. Check Point Research attributed the campaign to the long-running Lazarus operation that uses fake job offers as lures. CISA has ordered federal agencies to patch the underlying Microsoft bug within two weeks.
-
2SecurityWeek generalNightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
A threat actor known as Nightmare Eclipse (also Chaotic Eclipse/MSNightmare) dropped a zero-day PoC exploit called 'ShieldBreak' on August 2026 Patch Tuesday, demonstrating a patch bypass for CVE-2026-50656 (CVSS 7.8, aka RoguePlanet) in Microsoft Defender that allows any unprivileged user to spawn a shell with SYSTEM privileges. The exploit was released after Microsoft's patch cycle, leaving a window of exposure for unpatched systems. Security teams should prioritize applying the August Patch Tuesday updates immediately.
-
3The Hacker News generalAttackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors began actively exploiting CVE-2026-55040 (CVSS 9.1), a critical Microsoft SharePoint authentication bypass patched in the July 2026 Patch Tuesday, within days of Rapid7 publishing a public proof-of-concept. The flaw stems from weak authentication logic and enables unauthenticated attackers to bypass security controls on SharePoint servers. Organizations running unpatched SharePoint instances should treat this as urgent given the active exploitation confirmed in the wild.
-
4BleepingComputer generalCritical VMware vCenter RCE flaw exploited for reverse SSH access
CVE-2026-59310, a critical directory traversal RCE flaw in VMware vCenter's Syslog Server component, is being actively exploited in a global campaign to deploy a reverse SSH tool for persistent remote access. Patching alone may be insufficient to fully remediate compromised systems, as attackers have already established persistence via the reverse shell mechanism. VMware administrators should audit for indicators of compromise in addition to applying available patches.
-
5SecurityWeek generalOver 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
A supply chain attack on LiteLLM — carried out via a compromise of the Trivy security scanning tool — resulted in information-stealing malware being distributed to over 2,500 organizations using the popular AI gateway library. Terabytes of credentials were reportedly scraped and exfiltrated from affected users. Security teams using LiteLLM or Trivy in CI/CD pipelines should audit dependencies and rotate any credentials that may have been exposed.
-
6BleepingComputer generalWhite House taps security firms for offensive hack-back operations
A White House memo signed by President Trump instructs the National Coordination Center to establish a program permitting vetted private security firms to conduct offensive cyber operations against foreign cybercrime organizations, with contracts potentially requiring a $1 million compliance bond. This marks the first time the U.S. government has formally authorized private-sector entities to perform offensive hack-back operations, representing a major shift in U.S. cyber policy. Legal, operational, and attribution risks from private-sector offensive cyber activity remain significant concerns among experts.
-
7The Hacker News generalOpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
Researchers disclosed a flaw affecting reasoning APIs from OpenAI, Anthropic, and Google whereby encrypted reasoning objects ('thinking blocks') generated in one session could be replayed into another session, allowing weaker AI models to decode the internal reasoning of stronger models and recover secrets such as API keys and passwords embedded in session logs. The vulnerability stems from how providers transport hidden reasoning between API calls without sufficient session binding. Developers using reasoning-enabled APIs should audit session logs and rotate any secrets that may have been exposed.
-
8BleepingComputer generalNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
The Microsoft Defender zero-day exploit 'ShieldBreak,' released by Nightmare Eclipse immediately after the August 2026 Patch Tuesday, bypasses the patch for CVE-2026-50656 and enables privilege escalation to SYSTEM from any user context on Windows systems. The exploit, also linked to the 'LegacyHive' Windows zero-day patched in the same cycle, underscores the threat actor's pattern of timing disclosures to maximize exposure windows. Defenders should deploy August 2026 Patch Tuesday updates and monitor for privilege escalation activity via Defender.
-
9BleepingComputer generalHundreds of fake Chrome VPN extensions route traffic through a proxy
Over 737 malicious Chrome extensions impersonating well-known VPN and proxy services were found routing user traffic through SOCKS5 proxies operated by a single provider, with 274 extensions impersonating 66 legitimate brands across at least 40 developer accounts, accumulating 75,486 installs. The extensions primarily targeted Russian-speaking users seeking access to blocked content. Security teams should audit browser extension policies and block unapproved extensions via enterprise controls.
-
10BleepingComputer generalAndroid malware combo takes out loans and relays victims' credit cards
A newly discovered Android malware combo pairs WindRelay — an NFC relay tool — with the SpyNote remote administration RAT to steal live payment card data and take out unauthorized loans from victims' devices in real time. WindRelay intercepts NFC signals from physical cards and relays them to attacker-controlled devices, enabling contactless fraud at point-of-sale terminals. Mobile security teams should monitor for SpyNote indicators and consider NFC disable policies for high-risk user populations.