# Archive

Browse past daily curated stories

Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25

Wednesday, August 26, 2026

  1. 1
    0
    The Hacker News general
    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    CISA added CVE-2026-21962 (CVSS 10.0) to its Known Exploited Vulnerabilities catalog — a maximum-severity unauthenticated RCE flaw affecting Oracle HTTP Server and Oracle WebLogic Server exploitable via HTTP without credentials. Security teams running WebLogic should treat this as an emergency patch priority given the CVSS 10.0 score and confirmed active exploitation in the wild.

  2. 2
    0
    BleepingComputer general
    Hackers breached over 270 Zimbra servers in ongoing attacks

    Threat actors have already compromised over 270 Zimbra Collaboration Suite instances by exploiting CVE-2026-73570, a high-severity RCE flaw, with CISA issuing a three-day remediation deadline for federal agencies. The rapid exploitation of 270+ servers underscores how quickly Zimbra vulnerabilities are weaponized post-disclosure, making this critical for any organization running ZCS.

  3. 3
    0
    The Hacker News general
    Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

    Attackers are actively exploiting two unauthenticated authentication bypass vulnerabilities — CVE-2026-61979 (CVSS 8.1) and CVE-2026-15981 — in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, allowing privilege escalation to administrator-level access. Any WordPress site using this plugin is at immediate risk of full compromise and should apply Patchstack-disclosed patches without delay.

  4. 4
    0
    The Hacker News general
    Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

    The Mirage2FA phishing-as-a-service toolkit has targeted 4,500 US and EU companies between 2024 and 2026, abusing legitimate Microsoft 365 login flows to bypass two-factor authentication, with ANY.RUN research indicating 48% of targeted email addresses were potentially compromised. The campaign's multi-year persistence and scale make it a significant threat to enterprise Microsoft 365 deployments.

  5. 5
    0
    The Hacker News general
    A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

    Oasis Security disclosed a vulnerability in NVIDIA NemoClaw (OpenClaw) that allows an attacker-controlled webpage to gain unauthenticated access to a local Ollama API instance, enabling persistent poisoning of AI agent model instructions. The attack requires no authentication and can persist hidden instructions inside the model itself, representing a novel supply-chain-style risk for AI agent deployments.

  6. 6
    0
    BleepingComputer general
    Police arrests dozens of suspects in global cybercrime crackdown

    A coordinated Interpol operation involving 22 countries identified 263 suspects and arrested 58 individuals tied to cybercrime networks operated by African organized crime groups including Black Axe, which ran a Crime-as-a-Service network in Argentina with 196 members providing domains and money laundering support. The operation uncovered CaaS infrastructure spanning four continents and resulted in millions in seized assets.

  7. 7
    0
    The Record threat-intel
    US sanctions Iranian cyber actors as UK discloses power plant attack

    The U.S. Treasury sanctioned multiple Iranian nationals affiliated with the Mabna Institute for cyberattacks on critical infrastructure, coinciding with UK disclosure of a cyber intrusion on a small British power plant. The dual announcements signal coordinated Western attribution and escalating response to Iranian state-sponsored cyber operations targeting energy and critical sectors.

  8. 8
    0
    BleepingComputer general
    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

    A newly identified phishing-as-a-service platform called AnonyMousKIT uses AI voice agents to automate social engineering calls that trick iPhone owners into revealing passcodes needed to unlock stolen devices and disable Apple's Activation Lock. The platform industrializes iPhone theft follow-through, lowering the skill barrier for criminals targeting Apple device ecosystems at scale.

  9. 9
    0
    Dark Reading general
    ToxicPanda Banking Trojan Matures into Enterprise Threat

    The ToxicPanda Android banking trojan has matured with new capabilities that extend beyond financial applications, expanding its global target base and increasing its threat to enterprise environments. The evolution of ToxicPanda into a broader credential and data theft tool means security teams should update mobile threat detection rules beyond banking app monitoring.

  10. 10
    0
    BleepingComputer general
    TikTok reaches $400M settlement with US over COPPA violations

    The U.S. Department of Justice announced a $400 million COPPA settlement with TikTok, ByteDance, and affiliated companies over alleged illegal collection of children's personal data. This represents one of the largest children's privacy enforcement actions on record and sets a significant precedent for platform accountability under federal child privacy law.