Cybersecurity Brief — 2026-08-26
Law Enforcement & Operations
- INTERPOL Operation Jackal IV nets 58 arrests, 263 suspects across 22 countries — An eight-month coordinated operation targeting West African organized crime groups (including Black Axe) resulted in 58 arrests and 263 identified suspects. The effort uncovered a major crime-as-a-service network providing domains and money laundering support, a Johannesburg romance/investment scam syndicate, a Romanian call center scam netting €143M, and a pan-European money laundering network moving €845K through 560 transactions. This is the fourth iteration of Operation Jackal since 2022. (Source: The Hacker News)
Malware & Threats
- SLEEPWALKER backdoor discovered: fileless, packet-triggered, custom bytecode VM — An independent researcher documented a previously unknown Windows DLL (59,904 bytes) that side-loads into ESET Management Agent (ERAAgent.exe), masquerading as dpapi.dll. It remains dormant until a single crafted network packet arrives, then executes commands from a 23-instruction custom bytecode language. No hardcoded C2, no outbound connections, commands arrive as encrypted bytecode over six transports (TCP, UDP, ICMP, SMB named pipes, raw promiscuous capture, VMware VMCI). Researchers assess it as a targeted, well-resourced post-exploitation implant; attribution unknown. SHA-256:
d347170752a28e2b8c4b8b9f3cab2e3a6541ba11682c94498d26eb9002779d60. (Source: The Hacker News, The Register)
Vulnerabilities & Patching
-
CISA adds CVE-2026-60004 (Gitea code injection) to Known Exploited Vulnerabilities catalog — The remote code execution flaw in Gitea was patched in version 1.27.1 (late July 2026). CISA's Binding Operational Directive 26-04 requires FCEB agencies to prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets. (Source: CISA, SecurityWeek)
-
CISA issues three-day patching deadline for "perfect-10" Oracle flaw — CVE-2026-XXXX (CVSS 10.0) in Oracle products, disclosed in January with honeypot activity observed soon after. CISA's tightest-ever deadline reflects active exploitation risk to federal systems. (Source: The Register)
-
Oracle's 1,449-patch July release would not have stopped novel SQLi-to-Java attack — Huntress documented credential theft via SQL injection in a public-facing web app, followed by deployment of a post-exploitation toolkit ("khunt") via
CREATE JAVA SOURCEcommands executed inside Oracle's embedded JVM. The attack abuses legitimate database functionality (Java stored procedures) rather than a vulnerability; mitigation requires locking down Java compilation in production. (Source: The Register)
Initial Access & Social Engineering
-
Fake OpenAI Codex ads deliver ClickFix malware to Mac users — Sponsored search results direct developers to malicious sites that trick them into running commands via ClickFix-style social engineering, installing macOS malware. (Source: The Register)
-
$1T investment firm Apollo breached via social engineering — Attackers talked their way in and spent four days inside cloud platforms. (Source: The Register)
-
Iran-linked cyberattack shut down a UK power plant — Government confirms no risk to wider energy system. (Source: The Register)
Supply Chain & Development
-
Malicious Rust crates poisoned to steal developer credentials — Routine builds turned into infostealer delivery via compromised crate updates. (Source: The Register)
-
Hackers exploiting TrueConf (Russian "Zoom") vulnerabilities — CISA urges patching; Ukrainian hacktivists actively exploiting, but software reach extends beyond Russia. (Source: The Register)
Data Breaches & Fraud
-
SickKids children's hospital careers website compromised via third-party software vulnerability — Toronto organization says it wasn't the only victim. (Source: The Register)
-
ShinyHunters vs. ReliaQuest: claimed breach disputed — Attackers accessed an employee identity dashboard; security firm says that's the extent. (Source: The Register)
Privacy & Tracking
-
AliExpress accused of ultrasonic fingerprinting — Silent audio trick mutes developers' headphones while tracking shoppers; Firefox and Brave have mitigations. (Source: The Register)
-
Browser fingerprinting tool demonstrates latest tracking techniques — Glassbox developer built locally running tool with AI assistance. (Source: The Register)