A researcher known as MSNightmare — also tracked as Nightmare Eclipse and Chaotic Eclipse — has published a proof-of-concept called HardBreacher, claiming a local privilege-escalation zero-day in Kaspersky Endpoint Security on fully patched Windows 11 (version 25H2), running product version 14.0.0.504.
If real, a low-privileged user could write a DLL to System32 — normally off-limits — and seize a Kaspersky UI process, letting them stop the product, override its allow-or-block decisions, and destabilize the operating system. The researcher's previous drops have a mixed record: some stayed proof-of-concept, others ended up in active attacks.
Kaspersky says it has already addressed the issue, with the fix delivered through an automatic update — users can also trigger a database update manually. No CVE has been assigned. The PoC is unstable, error-prone, and requires multiple attempts.
Organizations should confirm their Kaspersky databases are current, review process telemetry, and avoid running the public code on production systems.
Source: Cybersecurity News
A researcher known as MSNightmare — also tracked as Nightmare Eclipse and Chaotic Eclipse — has published a proof-of-concept called HardBreacher, claiming a local privilege-escalation zero-day in Kaspersky Endpoint Security on fully patched Windows 11 (version 25H2), running product version 14.0.0.504.
If real, a low-privileged user could write a DLL to System32 — normally off-limits — and seize a Kaspersky UI process, letting them stop the product, override its allow-or-block decisions, and destabilize the operating system. The researcher's previous drops have a mixed record: some stayed proof-of-concept, others ended up in active attacks.
Kaspersky says it has already addressed the issue, with the fix delivered through an automatic update — users can also trigger a database update manually. No CVE has been assigned. The PoC is unstable, error-prone, and requires multiple attempts.
Organizations should confirm their Kaspersky databases are current, review process telemetry, and avoid running the public code on production systems.
Source: Cybersecurity News
Norcross, Georgia is dealing with the fallout from a ransomware attack that hit some of the city's computer systems on August 1. Officials didn't go public until August 28 — nearly four weeks later — saying they responded as soon as the incident was detected, bringing in cybersecurity experts and notifying law enforcement.
Most city systems are back up and running, but some disruptions may continue as restoration work wraps up. The city is also rolling out new security measures.
Details are still limited given the ongoing investigation. Norcross hasn't said whether any resident or employee data was taken, nobody has claimed the attack, and the city hasn't disclosed a ransom demand. It says it will share more as things develop.
Source: CBS News Atlanta
Norcross, Georgia is dealing with the fallout from a ransomware attack that hit some of the city's computer systems on August 1. Officials didn't go public until August 28 — nearly four weeks later — saying they responded as soon as the incident was detected, bringing in cybersecurity experts and notifying law enforcement.
Most city systems are back up and running, but some disruptions may continue as restoration work wraps up. The city is also rolling out new security measures.
Details are still limited given the ongoing investigation. Norcross hasn't said whether any resident or employee data was taken, nobody has claimed the attack, and the city hasn't disclosed a ransom demand. It says it will share more as things develop.
Source: CBS News Atlanta
Healthcare giant McKesson confirmed hackers stole customer data after discovering a breach on August 25. Attackers had been pulling data since the 21st. The company, which delivers roughly one-third of North American prescription medicines, said unauthorized access affected its Oncology & Multispecialty and Medical-Surgical business units — though it hasn't disclosed how many people were impacted.
The ShinyHunters extortion group is claiming responsibility, alleging they stole 284 million customer records including medical histories, prescriptions, billing data, and employee files. The group has since conceded that figure counts rows of raw data, not individual people, and that it hasn't finished going through what it took.
They're demanding around $55 million and threatening to publish everything unless McKesson opens payment negotiations by September 1 — that deadline expires today. McKesson hasn't engaged, says its services remain operational, and still hasn't determined how much data was taken. None of ShinyHunters' claims have been verified.
Source: SecurityWeek
Healthcare giant McKesson confirmed hackers stole customer data after discovering a breach on August 25. Attackers had been pulling data since the 21st. The company, which delivers roughly one-third of North American prescription medicines, said unauthorized access affected its Oncology & Multispecialty and Medical-Surgical business units — though it hasn't disclosed how many people were impacted.
The ShinyHunters extortion group is claiming responsibility, alleging they stole 284 million customer records including medical histories, prescriptions, billing data, and employee files. The group has since conceded that figure counts rows of raw data, not individual people, and that it hasn't finished going through what it took.
They're demanding around $55 million and threatening to publish everything unless McKesson opens payment negotiations by September 1 — that deadline expires today. McKesson hasn't engaged, says its services remain operational, and still hasn't determined how much data was taken. None of ShinyHunters' claims have been verified.
Source: SecurityWeek
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News
The Bureau of Alcohol, Tobacco, Firearms, and Explosives confirmed on Wednesday, August 26, 2026, that a cyberattack hit a standalone system containing information about its investigation targets. Senior Justice Department officials have designated the compromise a major incident under federal guidelines.
The agency says it was contained: the standalone system was not connected to any other ATF systems — including case management, laboratory, and eForms systems — and it was shut down as soon as it was discovered. ATF says its operations remain fully functional.
The Russian-speaking ransomware group Qilin claimed responsibility by adding ATF to its leak site, but published no samples and gave no indication of what or how much it took.
ATF declined to comment on Qilin's alleged involvement or say when the attack occurred. Qilin has claimed hundreds of victims across more than 60 countries since 2022, and was among the five most-reported ransomware variants in complaints to the FBI's Internet Crime Complaint Center in 2025.
Source: CyberScoop
The Bureau of Alcohol, Tobacco, Firearms, and Explosives confirmed on Wednesday, August 26, 2026, that a cyberattack hit a standalone system containing information about its investigation targets. Senior Justice Department officials have designated the compromise a major incident under federal guidelines.
The agency says it was contained: the standalone system was not connected to any other ATF systems — including case management, laboratory, and eForms systems — and it was shut down as soon as it was discovered. ATF says its operations remain fully functional.
The Russian-speaking ransomware group Qilin claimed responsibility by adding ATF to its leak site, but published no samples and gave no indication of what or how much it took.
ATF declined to comment on Qilin's alleged involvement or say when the attack occurred. Qilin has claimed hundreds of victims across more than 60 countries since 2022, and was among the five most-reported ransomware variants in complaints to the FBI's Internet Crime Complaint Center in 2025.
Source: CyberScoop
Microsoft has confirmed a critical remote code execution vulnerability in Entra ID, its cloud identity platform used across Microsoft 365, Azure, and thousands of third-party apps. Tracked as CVE-2026-69836, the flaw carries a CVSS score of 10.0 — the maximum possible — and stems from a deserialization bug that let attackers run arbitrary code remotely, with no login required.
Microsoft disclosed it on August 20, 2026, with the advisory's exploitation flag set to "Yes." A day later the company flipped that flag to "No," and has not explained why. No exploitation has ever been confirmed, and the flaw was found by one of Microsoft's own security engineers.
Because Entra ID is a managed cloud service, Microsoft patched it server-side; the company says the issue is fully mitigated and there is no action for customers to take. What it hasn't said is how long the service was vulnerable, whether any tenant data was reached, or why the exploitation flag changed.
With exploitation unconfirmed, there's no incident to respond to — but the audit is easy to do. Review Entra ID sign-in logs, conditional access policies, and privileged role assignments for anything anomalous predating the fix.
Source: Cybersecurity News
Microsoft has confirmed a critical remote code execution vulnerability in Entra ID, its cloud identity platform used across Microsoft 365, Azure, and thousands of third-party apps. Tracked as CVE-2026-69836, the flaw carries a CVSS score of 10.0 — the maximum possible — and stems from a deserialization bug that let attackers run arbitrary code remotely, with no login required.
Microsoft disclosed it on August 20, 2026, with the advisory's exploitation flag set to "Yes." A day later the company flipped that flag to "No," and has not explained why. No exploitation has ever been confirmed, and the flaw was found by one of Microsoft's own security engineers.
Because Entra ID is a managed cloud service, Microsoft patched it server-side; the company says the issue is fully mitigated and there is no action for customers to take. What it hasn't said is how long the service was vulnerable, whether any tenant data was reached, or why the exploitation flag changed.
With exploitation unconfirmed, there's no incident to respond to — but the audit is easy to do. Review Entra ID sign-in logs, conditional access policies, and privileged role assignments for anything anomalous predating the fix.
Source: Cybersecurity News
Manchester Airports Group (MAG), which operates Manchester, East Midlands, and London Stansted, has confirmed a cyberattack that exposed the personal data of around 8.7 million customers. Hackers took contact details, vehicle registrations and postcodes over the weekend of August 22–23, then demanded a ransom for the data's return — which MAG refused to pay.
MAG only became aware on Tuesday, August 25, and says it cut off further access and notified affected customers. For the majority, the data was limited to the email address given when signing up to airport WiFi; the more detailed records came from car park, lounge, and fast-track bookings.
The hacked system didn't hold bank or payment card details, MAG says, and at no point was passenger safety or aviation security compromised. The group says it knows the hackers' identity and has informed the relevant authorities.
The Information Commissioner's Office has received MAG's breach report and says it is assessing the information provided. Affected customers should watch for suspicious emails, texts or calls, and avoid opening unknown attachments.
Source: BBC News
Manchester Airports Group (MAG), which operates Manchester, East Midlands, and London Stansted, has confirmed a cyberattack that exposed the personal data of around 8.7 million customers. Hackers took contact details, vehicle registrations and postcodes over the weekend of August 22–23, then demanded a ransom for the data's return — which MAG refused to pay.
MAG only became aware on Tuesday, August 25, and says it cut off further access and notified affected customers. For the majority, the data was limited to the email address given when signing up to airport WiFi; the more detailed records came from car park, lounge, and fast-track bookings.
The hacked system didn't hold bank or payment card details, MAG says, and at no point was passenger safety or aviation security compromised. The group says it knows the hackers' identity and has informed the relevant authorities.
The Information Commissioner's Office has received MAG's breach report and says it is assessing the information provided. Affected customers should watch for suspicious emails, texts or calls, and avoid opening unknown attachments.
Source: BBC News
CISA gave federal agencies until 24 August 2026 to patch CVE-2026-73570, a Zimbra flaw allowing unauthenticated remote code execution through crafted SMTP requests. That deadline has now expired. The CVE record scores it 8.9 (High); Zimbra and CERT Polska both describe it as critical.
The flaw only bites where three things line up: the optional zimbra-snmp package is installed, SNMP notifications are enabled via snmp_notify, and the swatchdog service is running. Only the last of those is on by default. Zimbra shipped the permanent fix in ZCS 10.1.20 on 20 July, and every earlier version is affected.
Exploitation was confirmed on 17 August, when Poland's CERT Polska flagged an ongoing campaign. CISA added the flaw to its KEV catalog on 21 August and gave three days, under the tiered model it adopted in June citing AI-accelerated exploit development. Shadowserver counted 155 compromised internet-facing instances on 20 August and 274 by the 22nd, plus roughly 8,200 unpatched.
Patching closes the entry point but does not remove persistence installed before it, Sectigo's Jason Soroko notes. CERT Polska says to check /var/log/zimbra.log for unexpected "Service status change" entries, and anything the zimbra user created in the last 30 days under the Jetty webapps directories or /tmp. Treat an exposed server as an incident, not a patch.
Source: Dark Reading
CISA gave federal agencies until 24 August 2026 to patch CVE-2026-73570, a Zimbra flaw allowing unauthenticated remote code execution through crafted SMTP requests. That deadline has now expired. The CVE record scores it 8.9 (High); Zimbra and CERT Polska both describe it as critical.
The flaw only bites where three things line up: the optional zimbra-snmp package is installed, SNMP notifications are enabled via snmp_notify, and the swatchdog service is running. Only the last of those is on by default. Zimbra shipped the permanent fix in ZCS 10.1.20 on 20 July, and every earlier version is affected.
Exploitation was confirmed on 17 August, when Poland's CERT Polska flagged an ongoing campaign. CISA added the flaw to its KEV catalog on 21 August and gave three days, under the tiered model it adopted in June citing AI-accelerated exploit development. Shadowserver counted 155 compromised internet-facing instances on 20 August and 274 by the 22nd, plus roughly 8,200 unpatched.
Patching closes the entry point but does not remove persistence installed before it, Sectigo's Jason Soroko notes. CERT Polska says to check /var/log/zimbra.log for unexpected "Service status change" entries, and anything the zimbra user created in the last 30 days under the Jetty webapps directories or /tmp. Treat an exposed server as an incident, not a patch.
Source: Dark Reading
Medical device maker Boston Scientific confirmed on 26 August 2026 that a cyberattack is disrupting its global operations, after identifying the incident the day before. The company says a network outage has left it unable to fully process or ship customer orders, and that the timeline for a full restoration is not yet known.
Boston Scientific filed a Form 8-K with the SEC and brought in outside cybersecurity experts to investigate and contain the threat. Shares dropped as much as 6% on the news. The filing adds that the full scope and impacts remain unknown and that the company has not yet determined whether the incident is reasonably likely to have a material impact.
No attacker has been named, no group has claimed responsibility, and the company has not confirmed ransomware or any data theft. It also hasn't said whether the disruption reaches customers with its devices and implants.
Downstream buyers are already being warned: NHS Supply Chain issued a supplier notice to its customers about the disruption on 27 August.
Source: CBS News
Medical device maker Boston Scientific confirmed on 26 August 2026 that a cyberattack is disrupting its global operations, after identifying the incident the day before. The company says a network outage has left it unable to fully process or ship customer orders, and that the timeline for a full restoration is not yet known.
Boston Scientific filed a Form 8-K with the SEC and brought in outside cybersecurity experts to investigate and contain the threat. Shares dropped as much as 6% on the news. The filing adds that the full scope and impacts remain unknown and that the company has not yet determined whether the incident is reasonably likely to have a material impact.
No attacker has been named, no group has claimed responsibility, and the company has not confirmed ransomware or any data theft. It also hasn't said whether the disruption reaches customers with its devices and implants.
Downstream buyers are already being warned: NHS Supply Chain issued a supplier notice to its customers about the disruption on 27 August.
Source: CBS News
Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop
Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop