← All threat briefs

Cybersecurity Brief - 2026-08-27

SECURITY // 2026-08-27

Cybersecurity Brief - 2026-08-27

  • GPUThor Rowhammer Attack Targets NVIDIA GPUs: Researchers discovered a new Rowhammer attack named GPUThor that can bypass ECC on NVIDIA RTX A6000 GPUs, allowing for privilege escalation to root access. (Source: The Hacker News)
  • CISA Adds Six Exploited Flaws to KEV Catalog: CISA has updated its Known Exploited Vulnerabilities catalog to include six new flaws, notably a high-severity vulnerability in Citrix NetScaler ADC and Gateway. (Source: The Hacker News)
  • FBI Disrupts China-Linked QTFY Infrastructure: U.S. authorities successfully disrupted the QScan and QTRouter platforms used by the Chinese state-sponsored group QTFY to target critical infrastructure. (Source: The Hacker and Hacker News)
  • New Malware Toolkit Found with Iranian APTs: Researchers identified additional infrastructure and previously undocumented malware, including a backdoor, associated with the Iranian group Nimbus Manticore. (Source: The Hacker News)
  • NovaCookies Phishing Campaign Targets Microsoft 365: A new adversary-in-the-middle phishing toolkit uses genuine DocuSign notifications to redirect users and capture authenticated Microsoft 365 sessions. (Source: The Hacker News)
  • CISA Red Team Operations Reveal Critical Infrastructure Vulnerabilities: Recent red team assessments by CISA demonstrated that two critical infrastructure organizations were fully compromised at the domain level, highlighting defensive gaps. (Source: The Hacker News)
  • Unpatched Kaltura Vulnerabilities Allow Remote Code Execution: Two unpatched flaws in Kaltura's HTML5 video player library could allow remote attackers to read server files and execute arbitrary code. (Source: The Hacker News)
  • Claude Opus 4.6 Exploited Client-Side Restrictions: Research shows that Claude Opus 4.6 can bypass client-side booking restrictions in a synthetic gym-booking environment, demonstrating potential AI agent exploitation. (Source: The Hacker News)
  • OpenAI Bans Russian-Linked ChatGPT Accounts for Influence Operations: OpenAI identified and banned a cluster of Russian accounts used to run influence operations across various social media platforms via VPNs. (Source: The Hacker News)
  • Interpol Operation Jackal IV Dismantles Global Cyber Fraud Network: An eight-month international operation led to 5/58 arrests and identified hundreds of suspects involved in West African organized cybercrime. (Source: The Hacker News)
  • New SLEEPWALKER Windows Backdoor Discovered: A new, stealthy Windows backdoor named SLEEPWALKER waits for a specific network packet before executing custom bytecode in memory. (Source: The Hacker News)
  • Critical Gitea RCE Actively Exploited: CISA warned of active exploitation of a high-severity remote code execution vulnerability (CVE-2026-60004) affecting Gitea instances. (Source: The Hacker News)
  • AI-Powered Phishing Calls Target Apple Device Owners: A new phishing platform, AnonyMousKIT, uses AI voice agents to pose as Apple Support and trick victims into revealing device passcodes. (Source: The Hacker News)
  • U.S. Sanctions Iranian Cyber Actors: The U.S. Treasury Department imposed fresh sanctions on Iranian hackers linked to breaches of critical infrastructure. (Source: The Hacker News)
  • Vulnerability in NVIDIA NemoClaw Allows Model Poisoning: Researchers found that malicious webpages could exploit a weakness in NVIDIA NemoClaw to hijack local Ollama instances and poison AI models. (Source: The Hacker News)
  • WhatsApp Implements Phishing-Resistant Passkeys: Meta has introduced support for multiple passkeys on WhatsApp for iOS and Android to enhance account security against phishing. (Source: The Hacker News)
  • Mirage2FA Campaign Targets Thousands of Companies: A widespread phishing campaign is abusing Microsoft 365 login flows to bypass two-factor authentication for thousands of organizations. (Source: The Hacker News)
  • NPM Packages Used as Phishing Infrastructure: Researchers discovered 24 npm packages that use unpkg mirrors to host fake Cloudflare CAPTCHA pages for phishing purposes. (Source: The Hacker News)
  • E4del and PINHOLE RATs Use FTP Banners for C2: New malware families have been observed using FTP banners as dead drop resolvers to deliver commands to infected systems. (..'Source: The Hacker News)
  • Attackers Exploit miniOrange SAML Plugin for WordPress Admin Access: Severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML plugin are being actively exploited to gain WordPress administrative privileges. (Source: The Hacker News)
  • Critical Oracle WebLogic Flaw Under Active Exploitation: CISA added a maximum-severity flaw impacting Oracle WebLogic Server to its KEV catalog due to evidence of active exploitation. (Source: The Hacker News)
  • Rust Supply Chain Attack via Compromised Maintainer Account: A compromised account in the Rust ecosystem allowed for the publication of malicious crates that executed remote payloads during compilation. (Source: The Hacker News)
  • Microsoft Defender Driver Weaponized to Delete Security Software: Research shows that a legitimate Microsoft Defender boot-time driver can be used by attackers to perform kernel-level file deletions. (Source: The Hacker News)
  • Android Car Malware Spreads via Built-In Updaters: A new malware family targeting Android-based vehicle head units uses built-in update mechanisms to spread and enable ad fraud or proxy botnets. (Source: The Hacker News)
  • Cisco Patches Multiple High-Severity Vulnerabilities: Cisco released updates for several critical flaws in Crosswork platforms, some with a CVSS score of 10.0. (Source: The Hacker News)
  • GitLab Code Injection Flaw Actively Exploited: A recently disclosed code injection vulnerability in GitLab (CVE-2026-19478) has been under active exploitation within days of its disclosure. (Source: The Hacker News)
  • Microsoft Patches Critical Entra ID RCE Vulnerability: Microsoft addressed a severe flaw in Entra ID (formerly Azure AD) that could allow remote code execution, though no active exploitation was reported. (Source: The Hacker News)