# Archive
Browse past daily curated stories
Tuesday, August 25, 2026
-
1SecurityWeek generalIran-Linked Hackers Shut Down UK Power Plant for Four Days
Iran-linked hackers shut down a UK power plant for four days, causing real-world operational disruption to Britain's distributed energy infrastructure. This attack coincided with the U.S. Treasury sanctioning several Iranian nationals — including individuals affiliated with the Mabna Institute — for cyberattacks on critical infrastructure. The incident raises serious concerns about the repeatability of such attacks against small, distributed energy assets that may lack enterprise-grade defenses.
-
2The Hacker News generalCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
A critical vulnerability (CVE-2026-18963, CVSS 9.1) in Keycloak, the widely-deployed open-source identity and access management server maintained by Red Hat, allows unauthenticated remote attackers to take over any user account by forcing a password reset. Red Hat and the Keycloak project have released patches, making immediate upgrade essential for any organization using Keycloak for SSO or OAuth flows.
-
3BleepingComputer generalCISA orders urgent patching of actively exploited Zimbra flaw
CISA issued an urgent three-day patching deadline for CVE-2026-73570, an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) that enables full takeover of a user's communications. The extremely short remediation window signals active in-the-wild exploitation and applies mandatory action for all U.S. federal agencies under BOD 22-01.
-
4SecurityWeek generalUber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
The Dutch Data Protection Authority (AP) has fined Uber €825 million (~$1 billion) for GDPR violations related to the automated suspension of driver accounts, making it one of the largest GDPR fines ever issued. The ruling centers on Uber's use of algorithmic decision-making that affected drivers' livelihoods without adequate transparency or human oversight, a precedent with broad implications for platform operators using automated enforcement systems.
-
5SecurityWeek general91 Vulnerabilities Patched in Spring Application Framework
VMware's Spring Application Framework received patches for 91 vulnerabilities in a single update cycle, bringing the 2026 total to over 200 — a dramatic increase from just 16 in 2025 and 22 in 2024. The surge suggests either significantly increased research focus or expanding attack surface in the widely-used Java enterprise framework, and security teams managing Spring-based applications should prioritize this patching cycle.
-
6SecurityWeek generalTikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
TikTok, ByteDance, and affiliated companies reached a $400 million settlement with the U.S. Department of Justice over COPPA violations, with $300 million due immediately and $100 million contingent on vacating a prior consent decree against predecessor company Musical.ly. The settlement is one of the largest children's privacy enforcement actions in U.S. history and signals continued regulatory pressure on platforms handling minors' data.
-
7The Hacker News generalUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Chinese-speaking threat actor UAT-10147 is using AI to scale attacks against Windows and Linux web servers in the education, media, technology, and gaming sectors, deploying a backdoor called SPECTRE alongside EDR bypass techniques and a Linux rootkit. Primary targets are concentrated in Brazil, Bolivia, China, Canada, and Vietnam, and the group's AI-assisted operations represent a concrete example of AI lowering the barrier for high-volume server compromise campaigns.
-
8The Hacker News generalOperation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
A China-nexus espionage campaign dubbed Operation QUICSILVER is targeting Myanmar's government and IT sectors using graduation ceremony invitation lures to deliver QUICAgent, a Go-language backdoor, as reported by Seqrite Labs. The use of QUIC protocol-based C2 infrastructure is notable for its ability to blend with legitimate traffic and complicate network-level detection.
-
9BleepingComputer generalHackers target WordPress sites in miniOrange auth bypass attacks
Active exploitation attempts are underway against two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, which can be abused to forge SAML responses and authenticate as administrators without credentials. WordPress site administrators running this plugin should apply patches immediately, as SAML auth bypass flaws provide direct privileged access to affected installations.
-
10BleepingComputer generalUnpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers — deployed by multiple U.S. broadband ISPs — allows remote unauthenticated attackers to create arbitrary port-forwarding rules, effectively bypassing NAT and exposing internal network devices directly to the public internet. With no patch currently available, ISPs and their subscribers face persistent exposure, and the scope across multiple broadband providers amplifies the potential attack surface.