Cybersecurity researchers at Hunt.io have disclosed Operation CameraSwarm, a campaign that compromised over 14,530 Dahua devices between June and July 2026 through credential attacks and two authentication-bypass vulnerabilities. The attackers leveraged a peer-to-peer relay technique to facilitate the compromise, with evidence reconstructed from an exposed working directory containing 2,616 files totaling 407 MB.
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad
Cybersecurity researchers have identified a global cybercrime operation dubbed StopAndProtect that leverages nearly 2,000 compromised WordPress sites as infrastructure for distributing malware and exfiltrating sensitive data including documents, screenshots, and activity logs. The operation employs a diverse toolkit of criminal software rather than relying on a single malware variant, enabling attackers to commandeer infected hosts and maintain persistent control over victim systems.
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild across macOS, SharePoint, vCenter, and Microsoft IKE implementations. One of the flaws affecting Apple macOS, CVE-2026-65400 with a CVSS score of 9.8, involves an improper authentication vulnerability that could enable unauthorized access. Security teams should prioritize patching these actively exploited vulnerabilities across their affected systems.
Scammers have created fraudulent wallet-checking websites that impersonate legitimate anti-money laundering services to deceive users into granting unauthorized access to their cryptocurrency wallets. These fake AML checkers exploit users' trust in compliance tools, enabling attackers to drain funds from victims' digital assets. Security professionals should alert users to verify the authenticity of AML services and be cautious when approving wallet access permissions.
Google has released a Chrome desktop update addressing 15 security vulnerabilities, two of which are critical buffer overflow flaws. Security professionals should prioritize updating to the latest version to mitigate these high-severity issues.
A reverse image search service operated by ClarityCheck failed to secure its database, leaving over 9 million facial image files publicly accessible despite claims of privacy and security. The exposure represents a significant breach of personal data through an improperly protected people-search tool, potentially affecting millions of individuals whose photos were indexed in the service.
Scammers exploit victims' politeness by using replies to wrong-number texts as a profiling mechanism, gathering intelligence that feeds into larger fraud operations worth billions of dollars. What appears to be a harmless courtesy response can mark someone as an engaged target, with that information reportedly valued at approximately $2 on dark web markets. This tactic highlights how even minor interactions can expose users to coordinated social engineering schemes.
Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.
UT San Antonio delayed the start of fall classes by three days following a cyber incident detected over the weekend, with the semester now beginning August 24 to allow time for system restoration. The university's immediate response involved taking systems and services offline as a precaution, temporarily disrupting connectivity and email, though investigation found no evidence of data access or exfiltration. Technology teams working with expert partners continue restoring services and strengthening security safeguards across the campus network.
GitLab has patched two critical vulnerabilities, including CVE-2026-19478, a code injection flaw with a CVSS score of 9.4 that allows unauthenticated attackers to modify or delete public projects and user data through GraphQL directive exploitation. The second vulnerability, CVE-2026-19650, is a high-severity CSRF flaw in GitLab's GraphQL multiplex query handler that could enable unauthorized mutations via GET requests. Organizations running self-managed GitLab CE/EE versions 18.2 through 19.2 are urged to upgrade immediately to the patched releases (18.11.11, 19.0.8, 19.1.6, or 19.2.4).
A 27-year-old data analyst from Charlotte, North Carolina, faced prison time after attempting to extort $2.5 million from his employer upon learning his contract would not be renewed. Rather than pursuing legitimate job search options, Cameron Curry chose extortion as his response to the employment setback. The case highlights how employment disputes can escalate into serious criminal activity with severe legal consequences.
Microsoft Defender Experts have attributed over 30 rotating web domains to MacSync Stealer, a macOS-focused information stealer, by correlating endpoint and network behaviors across the shifting infrastructure. The investigation traced the malware's activity chain from payload retrieval through data collection, staging, and exfiltration phases. Microsoft's analysis required aligning multiple endpoint and network behavioral patterns to establish the connection between these domains and the stealer's operations.
A JSP web shell linked to the Clop threat actor has been discovered targeting PTC Windchill and FlexPLM servers following exploitation of a critical vulnerability, designed to decrypt credentials and exfiltrate engineering data from enterprise PLM environments. ReliaQuest researchers identified the malware as a sophisticated extortion platform with capabilities to map sensitive vault contents, indicating attackers are leveraging compromised PLM systems for targeted data theft operations.
Ukraine's Asset Recovery and Management Agency (ARMA) experienced a cyberattack on its servers ahead of the August 22 deadline for selecting a manager for assets linked to sanctioned Russian oligarch Mikhail Fridman, prompting investigations by the Security Service of Ukraine and the National Anti-Corruption Bureau into whether the incident was part of a broader coordinated campaign. ARMA has documented signs of unauthorized interference since spring, including unauthorized access to officials' email accounts and inquiries, raising concerns about possible coordinated efforts to disrupt operations, apply pressure, or affect the competition, though the agency has not identified the alleged perpetrators. Despite the incident, ARMA said it will proceed with the IDS Ukraine asset manager competition according to established legal procedures and timelines.