A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks on 3 518 organizations, with 4 532 Microsoft 365 accounts potentially compromised, researchers at ANY.RUN report. Active since September 2024, it skips malware entirely — a browser-executed HTML, XHTML or SVG attachment, or a QR code, steers the victim to a fake Microsoft login page.
Whatever the victim types — password and live 2FA code alike — an adversary-in-the-middle proxy passes through to Microsoft in real time. What the attacker keeps is the authenticated session cookie sent back on success, and it works until it expires or someone revokes it — no password or MFA needed.
Cookie theft was the largest single outcome — 4,561 of 9,332 recorded compromise events, just under half — affecting 2,541 accounts. Of the 4,532 accounts potentially compromised overall, 63.7% were in the U.S.; technology, manufacturing and education were the hardest-hit sectors.
A password reset won't fix this. Revoke every active session, and move high-risk users to phishing-resistant MFA — FIDO2 keys or passkeys, which are bound to the real site and can't be relayed. ANY.RUN also recommends blocking those attachment types and shortening session lifetimes.
Source: Cybersecurity News
A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks on 3 518 organizations, with 4 532 Microsoft 365 accounts potentially compromised, researchers at ANY.RUN report. Active since September 2024, it skips malware entirely — a browser-executed HTML, XHTML or SVG attachment, or a QR code, steers the victim to a fake Microsoft login page.
Whatever the victim types — password and live 2FA code alike — an adversary-in-the-middle proxy passes through to Microsoft in real time. What the attacker keeps is the authenticated session cookie sent back on success, and it works until it expires or someone revokes it — no password or MFA needed.
Cookie theft was the largest single outcome — 4,561 of 9,332 recorded compromise events, just under half — affecting 2,541 accounts. Of the 4,532 accounts potentially compromised overall, 63.7% were in the U.S.; technology, manufacturing and education were the hardest-hit sectors.
A password reset won't fix this. Revoke every active session, and move high-risk users to phishing-resistant MFA — FIDO2 keys or passkeys, which are bound to the real site and can't be relayed. ANY.RUN also recommends blocking those attachment types and shortening session lifetimes.
Source: Cybersecurity News
George House Trust, a Manchester-based HIV charity, has warned users that their sensitive health data may have been stolen by hackers. The breach, which occurred at the end of July, exposed personal details including addresses, phone numbers, and case notes about users' engagement with the charity.
The incident stems from a cyberattack on Beacon, a tech company whose database system is used by 1.5K+ UK charities. George House Trust was notified on 3 August but waited three weeks before alerting users. So far, no stolen data appears to have been misused. Investigations are ongoing.
Source: BBC News
George House Trust, a Manchester-based HIV charity, has warned users that their sensitive health data may have been stolen by hackers. The breach, which occurred at the end of July, exposed personal details including addresses, phone numbers, and case notes about users' engagement with the charity.
The incident stems from a cyberattack on Beacon, a tech company whose database system is used by 1.5K+ UK charities. George House Trust was notified on 3 August but waited three weeks before alerting users. So far, no stolen data appears to have been misused. Investigations are ongoing.
Source: BBC News
CISA added a Zimbra vulnerability, CVE-2026-73570 (CVSS 8.9, High), to its Known Exploited Vulnerabilities catalog on August 21, giving federal civilian agencies until August 24 to patch or stop using the software — a deadline that has now passed. The fix is Zimbra Collaboration Suite 10.1.20, released July 20.
The flaw lets unauthenticated attackers run arbitrary OS commands as the Zimbra user through crafted SMTP requests. Exposure is narrower than it sounds — only servers with the optional zimbra-snmp package installed and SNMP notifications enabled are affected. CERT Polska flagged an active campaign hunting them on August 16.
Merlin Group's Robert Costello notes that compromising a Zimbra server exposes messages, calendars, contacts and attachments, along with internal naming conventions and maintenance schedules — enough to fuel follow-on attacks. Patching won't evict an intruder already inside, so exposed servers need checking against CERT Polska's indicators, not just updating.
Black Hills Information Security's John Strand argues AI is compressing the gap between disclosure and working exploit, pushing urgent patching closer to incident response than routine maintenance.
Source: Dark Reading
CISA added a Zimbra vulnerability, CVE-2026-73570 (CVSS 8.9, High), to its Known Exploited Vulnerabilities catalog on August 21, giving federal civilian agencies until August 24 to patch or stop using the software — a deadline that has now passed. The fix is Zimbra Collaboration Suite 10.1.20, released July 20.
The flaw lets unauthenticated attackers run arbitrary OS commands as the Zimbra user through crafted SMTP requests. Exposure is narrower than it sounds — only servers with the optional zimbra-snmp package installed and SNMP notifications enabled are affected. CERT Polska flagged an active campaign hunting them on August 16.
Merlin Group's Robert Costello notes that compromising a Zimbra server exposes messages, calendars, contacts and attachments, along with internal naming conventions and maintenance schedules — enough to fuel follow-on attacks. Patching won't evict an intruder already inside, so exposed servers need checking against CERT Polska's indicators, not just updating.
Black Hills Information Security's John Strand argues AI is compressing the gap between disclosure and working exploit, pushing urgent patching closer to incident response than routine maintenance.
Source: Dark Reading
A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek
A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek
Expel researcher Marcus Hutchins and colleagues found SynkLoader in a client's network on August 18, 2026, and believe it was first deployed around July 28. It spreads through Microsoft Teams messages in which the attacker poses as the target company's own IT help desk, steering users to a fake "PowerShell Cleaner" installer hosted on Azure storage.
The toolkit pairs a bundled Python environment with DLLs disguised as Microsoft runtime files, running native Windows behaviour inside Python processes to cut the signals EDR relies on. Its PhishLocker module raises a fake Windows lock screen and traps the user until they enter a password — and in SSO environments, that credential opens more than the desktop.
PhishLocker is one of seven modules; the others include a remote shell, a reverse proxy into the internal network, and desktop streaming with input takeover. A profiler module counts the size of the victim's Active Directory domain — the reconnaissance ransomware crews use to size a ransom demand.
Expel puts only low-to-medium confidence on its assessment that the toolkit belongs to a ransomware group or an initial access broker. In the meantime, verify help-desk requests through a known channel, treat unsolicited MSI installers as hostile, and if a lock screen appears unexpectedly, hit Alt+Tab — the fake one is just a window.
Source: Dark Reading
Expel researcher Marcus Hutchins and colleagues found SynkLoader in a client's network on August 18, 2026, and believe it was first deployed around July 28. It spreads through Microsoft Teams messages in which the attacker poses as the target company's own IT help desk, steering users to a fake "PowerShell Cleaner" installer hosted on Azure storage.
The toolkit pairs a bundled Python environment with DLLs disguised as Microsoft runtime files, running native Windows behaviour inside Python processes to cut the signals EDR relies on. Its PhishLocker module raises a fake Windows lock screen and traps the user until they enter a password — and in SSO environments, that credential opens more than the desktop.
PhishLocker is one of seven modules; the others include a remote shell, a reverse proxy into the internal network, and desktop streaming with input takeover. A profiler module counts the size of the victim's Active Directory domain — the reconnaissance ransomware crews use to size a ransom demand.
Expel puts only low-to-medium confidence on its assessment that the toolkit belongs to a ransomware group or an initial access broker. In the meantime, verify help-desk requests through a known channel, treat unsolicited MSI installers as hostile, and if a lock screen appears unexpectedly, hit Alt+Tab — the fake one is just a window.
Source: Dark Reading
The Department for Energy Security and Net Zero has contacted power companies to advise them about the risk of cyberattacks, after a small UK generator was taken offline for four days last month. The Telegraph reported the attack was carried out by hackers affiliated with the Iranian regime.
Neither the government nor the National Cyber Security Centre would identify the site, citing security reasons. DESNZ said the incident affected a small-scale generator and that at no point was there a risk to the UK's energy system. Britain's network runs a number of smaller gas units that supply short-term power when demand spikes.
The government is updating its cyber security regulations and working on a new energy resilience strategy, due later this year. Iran has long been rated a capable cyber power, and Western defenders have spent this year braced for state-linked activity amid its conflict with the US — while seeing little of it so far..
Source: BBC News
The Department for Energy Security and Net Zero has contacted power companies to advise them about the risk of cyberattacks, after a small UK generator was taken offline for four days last month. The Telegraph reported the attack was carried out by hackers affiliated with the Iranian regime.
Neither the government nor the National Cyber Security Centre would identify the site, citing security reasons. DESNZ said the incident affected a small-scale generator and that at no point was there a risk to the UK's energy system. Britain's network runs a number of smaller gas units that supply short-term power when demand spikes.
The government is updating its cyber security regulations and working on a new energy resilience strategy, due later this year. Iran has long been rated a capable cyber power, and Western defenders have spent this year braced for state-linked activity amid its conflict with the US — while seeing little of it so far..
Source: BBC News
A critical vulnerability in the Node.js sandboxing library isolated-vm can let untrusted JavaScript break out of its sandbox and hijack the host process. Tracked as GHSA-864f-rcv7-6rh4, the flaw affects versions before 7.0.1 and 6.2.0, with fixes released August 8, 2026.
Endor Labs researchers found the bug in native C++ binding code handling data transfers between V8 Isolates. An attacker can exploit a type-confusion and TOCTOU gap in ExternalCopy's transferList option using a JavaScript getter — swapping a valid ArrayBuffer for malicious data between validation and transfer.
At minimum, this crashes the host process. At worst, it enables arbitrary code execution outside the sandbox. Upgrade immediately.
Source: Cybersecurity News
A critical vulnerability in the Node.js sandboxing library isolated-vm can let untrusted JavaScript break out of its sandbox and hijack the host process. Tracked as GHSA-864f-rcv7-6rh4, the flaw affects versions before 7.0.1 and 6.2.0, with fixes released August 8, 2026.
Endor Labs researchers found the bug in native C++ binding code handling data transfers between V8 Isolates. An attacker can exploit a type-confusion and TOCTOU gap in ExternalCopy's transferList option using a JavaScript getter — swapping a valid ArrayBuffer for malicious data between validation and transfer.
At minimum, this crashes the host process. At worst, it enables arbitrary code execution outside the sandbox. Upgrade immediately.
Source: Cybersecurity News
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
A critical GitLab vulnerability (CVE-2026-19478) is being actively exploited, and administrators of self-managed instances need to patch immediately. Rated 9.4/10, the flaw lets unauthenticated attackers inject code through GitLab's GraphQL interface — no account or user interaction required.
Attackers can delete repositories, manipulate merge records, and ban legitimate maintainers from public projects. Security firm WatchTowr reproduced the exploit within minutes of disclosure and confirmed its honeypot network recorded live exploitation attempts.
The vulnerability spans GitLab CE/EE versions 18.2 through 18.11.10, 19.0 through 19.0.7, 19.1 through 19.1.5, and 19.2 through 19.2.3. Patched builds (18.11.11, 19.0.8, 19.1.6, 19.2.4) are available now. GitLab.com and Dedicated users are already protected. If you can't upgrade immediately, restrict GraphQL endpoint access and treat exposed servers as potentially compromised.
Source: Cybersecurity News
A critical GitLab vulnerability (CVE-2026-19478) is being actively exploited, and administrators of self-managed instances need to patch immediately. Rated 9.4/10, the flaw lets unauthenticated attackers inject code through GitLab's GraphQL interface — no account or user interaction required.
Attackers can delete repositories, manipulate merge records, and ban legitimate maintainers from public projects. Security firm WatchTowr reproduced the exploit within minutes of disclosure and confirmed its honeypot network recorded live exploitation attempts.
The vulnerability spans GitLab CE/EE versions 18.2 through 18.11.10, 19.0 through 19.0.7, 19.1 through 19.1.5, and 19.2 through 19.2.3. Patched builds (18.11.11, 19.0.8, 19.1.6, 19.2.4) are available now. GitLab.com and Dedicated users are already protected. If you can't upgrade immediately, restrict GraphQL endpoint access and treat exposed servers as potentially compromised.
Source: Cybersecurity News