For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were […] The post 17th August – Threat Intelligence Report appeared first on Check Point Research.
A researcher has discovered ShieldBreak, a new bypass technique that circumvents Microsoft's patch for the previously disclosed RoguePlanet vulnerability in Defender. This attack allows an attacker to achieve SYSTEM-level privileges despite the vendor's remediation efforts. The finding highlights ongoing challenges in securing Windows Defender against privilege escalation attacks.
A critical vulnerability in the WordPress User Profile Builder plugin exposed approximately 40,000 websites to unauthenticated admin account takeover attacks. The flaw allowed attackers without credentials to gain administrator-level access, posing a severe risk to affected installations.
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a
CISA has added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. The vulnerability is classified as a frequent attack vector posing significant risk to federal systems, and federal agencies are required under BOD 26-04 to prioritize its remediation on publicly exposed assets. CISA encourages all organizations to adopt risk-based vulnerability management and address KEV Catalog vulnerabilities with urgency.
MCP servers pose significant security risks to enterprises through plaintext configuration files, excessive permissions, and prompt injection vulnerabilities, often operating without visibility from security teams. As organizations increasingly integrate AI agents into their infrastructure, these MCP server gaps can create substantial exposure to sensitive data and unauthorized access. The Model Context Protocol's design for enabling AI agent access to tools and data creates security challenges that must be addressed before widespread adoption.
A threat actor is selling millions of records allegedly stolen from multiple corporate Azure tenants, with breaches affecting organizations including McDonald's, Vodafone, TCS, and Kyndryl. Researchers have identified compromised credentials as the likely attack vector enabling access to these cloud environments. The incident underscores ongoing risks to enterprises relying on cloud infrastructure when credential security practices are inadequate.
Rapid7 researchers uncovered Operation ASTERIX, an active cryptocurrency fraud pipeline that combined phishing, vishing, and counterfeit wallet applications to steal recovery phrases from crypto users across 54 countries. The exposed infrastructure revealed the operator extensively leveraged AI coding assistants for development—and when one model resisted obfuscation tasks, switched providers and deployed a sophisticated multi-stage jailbreak prompt targeting the new model's safety controls. The campaign demonstrates how threat actors are integrating AI tools throughout malware development workflows rather than using them for isolated code snippets, with account enumeration, enriched lead databases, and coordinated voice-calling automation all supporting the theft operation.
Attackers are compromising public Wi-Fi access points at hotels and conference centers globally to modify DNS configurations and redirect users to fraudulent login pages designed to harvest credentials. This attack vector exploits the trust users place in legitimate network infrastructure at these venues, making it an effective method for large-scale credential theft.
The European Telecommunications Standards Institute has initiated an approval process for 17 cybersecurity standards that vendors must comply with under the Cyber Resilience Act. These standards are designed to establish baseline security requirements for organizations operating within the European regulatory framework. The move aims to strengthen cyber resilience across the region by creating consistent security benchmarks for vendor compliance.
Attackers are actively exploiting a vulnerability in Mac Screen Sharing to achieve root-level access and deploy Monero cryptominers on affected systems. Apple has released patches to address this flaw, making immediate updates essential for Mac users to prevent compromise.
Security researchers at SSD Secure Disclosure have disclosed a two-stage exploit chain affecting Unisoc modem firmware that achieves full Android kernel access via VoLTE video calls, with no patch available from the chipset manufacturer. The vulnerability represents the second stage of an exploit chain that started with a remote code execution disclosure in March 2026, escalating the threat to complete kernel-level compromise on affected devices.
Researchers have identified Evooo1Bot, a previously undocumented Linux botnet derived from the leaked Mirai source code that targets edge devices to convert them into SOCKS5 proxies. The malware retains Mirai's DDoS capabilities while adding extended functionality beyond the original framework, exploiting known vulnerabilities to compromise internet-facing devices.
Hardware wallet provider SafePal has suffered a data breach affecting nearly 40,000 customers. The incident represents a significant security incident for the cryptocurrency storage platform and its user base.
African organizations across Egypt, Nigeria, South Africa, and Kenya are rapidly expanding their use of cloud infrastructure, AI, and digital services, but face a cybersecurity challenge that goes beyond technology access—security teams lack the time, context, and specialized capacity to effectively manage their expanding environments. Rapid7 and StarLink are partnering to address this gap by providing regional partners with technical enablement and expertise to help local organizations connect exposure management, threat detection, and response capabilities into cohesive security operations tailored to their specific needs.