Cybersecurity Brief - 2026-08-27
- GPUThor Rowhammer Attack Targets NVIDIA GPUs: Researchers discovered a new Rowhammer attack named GPUThor that can bypass ECC on NVIDIA RTX A6000 GPUs, allowing for privilege escalation to root access. (Source: The Hacker News)
- CISA Adds Six Exploited Flaws to KEV Catalog: CISA has updated its Known Exploited Vulnerabilities catalog to include six new flaws, notably a high-severity vulnerability in Citrix NetScaler ADC and Gateway. (Source: The Hacker News)
- FBI Disrupts China-Linked QTFY Infrastructure: U.S. authorities successfully disrupted the QScan and QTRouter platforms used by the Chinese state-sponsored group QTFY to target critical infrastructure. (Source: The Hacker and Hacker News)
- New Malware Toolkit Found with Iranian APTs: Researchers identified additional infrastructure and previously undocumented malware, including a backdoor, associated with the Iranian group Nimbus Manticore. (Source: The Hacker News)
- NovaCookies Phishing Campaign Targets Microsoft 365: A new adversary-in-the-middle phishing toolkit uses genuine DocuSign notifications to redirect users and capture authenticated Microsoft 365 sessions. (Source: The Hacker News)
- CISA Red Team Operations Reveal Critical Infrastructure Vulnerabilities: Recent red team assessments by CISA demonstrated that two critical infrastructure organizations were fully compromised at the domain level, highlighting defensive gaps. (Source: The Hacker News)
- Unpatched Kaltura Vulnerabilities Allow Remote Code Execution: Two unpatched flaws in Kaltura's HTML5 video player library could allow remote attackers to read server files and execute arbitrary code. (Source: The Hacker News)
- Claude Opus 4.6 Exploited Client-Side Restrictions: Research shows that Claude Opus 4.6 can bypass client-side booking restrictions in a synthetic gym-booking environment, demonstrating potential AI agent exploitation. (Source: The Hacker News)
- OpenAI Bans Russian-Linked ChatGPT Accounts for Influence Operations: OpenAI identified and banned a cluster of Russian accounts used to run influence operations across various social media platforms via VPNs. (Source: The Hacker News)
- Interpol Operation Jackal IV Dismantles Global Cyber Fraud Network: An eight-month international operation led to 5/58 arrests and identified hundreds of suspects involved in West African organized cybercrime. (Source: The Hacker News)
- New SLEEPWALKER Windows Backdoor Discovered: A new, stealthy Windows backdoor named SLEEPWALKER waits for a specific network packet before executing custom bytecode in memory. (Source: The Hacker News)
- Critical Gitea RCE Actively Exploited: CISA warned of active exploitation of a high-severity remote code execution vulnerability (CVE-2026-60004) affecting Gitea instances. (Source: The Hacker News)
- AI-Powered Phishing Calls Target Apple Device Owners: A new phishing platform, AnonyMousKIT, uses AI voice agents to pose as Apple Support and trick victims into revealing device passcodes. (Source: The Hacker News)
- U.S. Sanctions Iranian Cyber Actors: The U.S. Treasury Department imposed fresh sanctions on Iranian hackers linked to breaches of critical infrastructure. (Source: The Hacker News)
- Vulnerability in NVIDIA NemoClaw Allows Model Poisoning: Researchers found that malicious webpages could exploit a weakness in NVIDIA NemoClaw to hijack local Ollama instances and poison AI models. (Source: The Hacker News)
- WhatsApp Implements Phishing-Resistant Passkeys: Meta has introduced support for multiple passkeys on WhatsApp for iOS and Android to enhance account security against phishing. (Source: The Hacker News)
- Mirage2FA Campaign Targets Thousands of Companies: A widespread phishing campaign is abusing Microsoft 365 login flows to bypass two-factor authentication for thousands of organizations. (Source: The Hacker News)
- NPM Packages Used as Phishing Infrastructure: Researchers discovered 24 npm packages that use unpkg mirrors to host fake Cloudflare CAPTCHA pages for phishing purposes. (Source: The Hacker News)
- E4del and PINHOLE RATs Use FTP Banners for C2: New malware families have been observed using FTP banners as dead drop resolvers to deliver commands to infected systems. (..'Source: The Hacker News)
- Attackers Exploit miniOrange SAML Plugin for WordPress Admin Access: Severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML plugin are being actively exploited to gain WordPress administrative privileges. (Source: The Hacker News)
- Critical Oracle WebLogic Flaw Under Active Exploitation: CISA added a maximum-severity flaw impacting Oracle WebLogic Server to its KEV catalog due to evidence of active exploitation. (Source: The Hacker News)
- Rust Supply Chain Attack via Compromised Maintainer Account: A compromised account in the Rust ecosystem allowed for the publication of malicious crates that executed remote payloads during compilation. (Source: The Hacker News)
- Microsoft Defender Driver Weaponized to Delete Security Software: Research shows that a legitimate Microsoft Defender boot-time driver can be used by attackers to perform kernel-level file deletions. (Source: The Hacker News)
- Android Car Malware Spreads via Built-In Updaters: A new malware family targeting Android-based vehicle head units uses built-in update mechanisms to spread and enable ad fraud or proxy botnets. (Source: The Hacker News)
- Cisco Patches Multiple High-Severity Vulnerabilities: Cisco released updates for several critical flaws in Crosswork platforms, some with a CVSS score of 10.0. (Source: The Hacker News)
- GitLab Code Injection Flaw Actively Exploited: A recently disclosed code injection vulnerability in GitLab (CVE-2026-19478) has been under active exploitation within days of its disclosure. (Source: The Hacker News)
- Microsoft Patches Critical Entra ID RCE Vulnerability: Microsoft addressed a severe flaw in Entra ID (formerly Azure AD) that could allow remote code execution, though no active exploitation was reported. (Source: The Hacker News)