Data BreachThe Hacker News·4 days ago

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Cybersecurity researchers at Hunt.io have disclosed Operation CameraSwarm, a campaign that compromised over 14,530 Dahua devices between June and July 2026 through credential attacks and two authentication-bypass vulnerabilities. The attackers leveraged a peer-to-peer relay technique to facilitate the compromise, with evidence reconstructed from an exposed working directory containing 2,616 files totaling 407 MB.

PhishingThe Hacker News·4 days ago

Phishing 3.0: The Fight Moves to Agent Versus Agent

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad

MalwareThe Hacker News·4 days ago

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have identified a global cybercrime operation dubbed StopAndProtect that leverages nearly 2,000 compromised WordPress sites as infrastructure for distributing malware and exfiltrating sensitive data including documents, screenshots, and activity logs. The operation employs a diverse toolkit of criminal software rather than relying on a single malware variant, enabling attackers to commandeer infected hosts and maintain persistent control over victim systems.

VulnerabilityThe Hacker News·4 days ago

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild across macOS, SharePoint, vCenter, and Microsoft IKE implementations. One of the flaws affecting Apple macOS, CVE-2026-65400 with a CVSS score of 9.8, involves an improper authentication vulnerability that could enable unauthorized access. Security teams should prioritize patching these actively exploited vulnerabilities across their affected systems.

PhishingMalwarebytes Labs·4 days ago

Scammers are using fake crypto AML checkers to drain your wallet

Scammers have created fraudulent wallet-checking websites that impersonate legitimate anti-money laundering services to deceive users into granting unauthorized access to their cryptocurrency wallets. These fake AML checkers exploit users' trust in compliance tools, enabling attackers to drain funds from victims' digital assets. Security professionals should alert users to verify the authenticity of AML services and be cautious when approving wallet access permissions.

Policy & LegalSchneier on Security·4 days ago

ICE Collecting DNA Samples

ICE collected nearly a million DNA samples last year.

VulnerabilityMalwarebytes Labs·4 days ago

Update Chrome now: Two critical vulnerabilities fixed

Google has released a Chrome desktop update addressing 15 security vulnerabilities, two of which are critical buffer overflow flaws. Security professionals should prioritize updating to the latest version to mitigate these high-severity issues.

Data BreachWired Security·4 days ago

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

A reverse image search service operated by ClarityCheck failed to secure its database, leaving over 9 million facial image files publicly accessible despite claims of privacy and security. The exposure represents a significant breach of personal data through an improperly protected people-search tool, potentially affecting millions of individuals whose photos were indexed in the service.

PhishingMalwarebytes Labs·4 days ago

Your polite reply to that text is worth $2 on the dark web

Scammers exploit victims' politeness by using replies to wrong-number texts as a profiling mechanism, gathering intelligence that feeds into larger fraud operations worth billions of dollars. What appears to be a harmless courtesy response can mark someone as an engaged target, with that information reportedly valued at approximately $2 on dark web markets. This tactic highlights how even minor interactions can expose users to coordinated social engineering schemes.

OtherWired Security·4 days ago

Flock Has a Powerful New AI Tool for Police. We Got Its Code

Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.

OtherThe Cyber Express·4 days ago

UT San Antonio Shuts Systems, Delays Classes After Cyber Incident

UT San Antonio delayed the start of fall classes by three days following a cyber incident detected over the weekend, with the semester now beginning August 24 to allow time for system restoration. The university's immediate response involved taking systems and services offline as a precaution, temporarily disrupting connectivity and email, though investigation found no evidence of data access or exfiltration. Technology teams working with expert partners continue restoring services and strengthening security safeguards across the campus network.

VulnerabilityThe Cyber Express·4 days ago

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

GitLab has patched two critical vulnerabilities, including CVE-2026-19478, a code injection flaw with a CVSS score of 9.4 that allows unauthenticated attackers to modify or delete public projects and user data through GraphQL directive exploitation. The second vulnerability, CVE-2026-19650, is a high-severity CSRF flaw in GitLab's GraphQL multiplex query handler that could enable unauthorized mutations via GET requests. Organizations running self-managed GitLab CE/EE versions 18.2 through 19.2 are urged to upgrade immediately to the patched releases (18.11.11, 19.0.8, 19.1.6, or 19.2.4).

OtherGraham Cluley·4 days ago

Prison for data analyst who tried to extort $2.5 million from his employer

A 27-year-old data analyst from Charlotte, North Carolina, faced prison time after attempting to extort $2.5 million from his employer upon learning his contract would not be renewed. Rather than pursuing legitimate job search options, Cameron Curry chose extortion as his response to the employment setback. The case highlights how employment disputes can escalate into serious criminal activity with severe legal consequences.

MalwareThe Hacker News·4 days ago

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Microsoft Defender Experts have attributed over 30 rotating web domains to MacSync Stealer, a macOS-focused information stealer, by correlating endpoint and network behaviors across the shifting infrastructure. The investigation traced the malware's activity chain from payload retrieval through data collection, staging, and exfiltration phases. Microsoft's analysis required aligning multiple endpoint and network behavioral patterns to establish the connection between these domains and the stealer's operations.

VulnerabilityThe Hacker News·4 days ago

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JSP web shell linked to the Clop threat actor has been discovered targeting PTC Windchill and FlexPLM servers following exploitation of a critical vulnerability, designed to decrypt credentials and exfiltrate engineering data from enterprise PLM environments. ReliaQuest researchers identified the malware as a sophisticated extortion platform with capabilities to map sensitive vault contents, indicating attackers are leveraging compromised PLM systems for targeted data theft operations.

Data BreachThe Cyber Express·4 days ago

Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender

Ukraine's Asset Recovery and Management Agency (ARMA) experienced a cyberattack on its servers ahead of the August 22 deadline for selecting a manager for assets linked to sanctioned Russian oligarch Mikhail Fridman, prompting investigations by the Security Service of Ukraine and the National Anti-Corruption Bureau into whether the incident was part of a broader coordinated campaign. ARMA has documented signs of unauthorized interference since spring, including unauthorized access to officials' email accounts and inquiries, raising concerns about possible coordinated efforts to disrupt operations, apply pressure, or affect the competition, though the agency has not identified the alleged perpetrators. Despite the incident, ARMA said it will proceed with the IDS Ukraine asset manager competition according to established legal procedures and timelines.

Load more