Ticker feed
A critical vulnerability in the Node.js sandboxing library isolated-vm can let untrusted JavaScript break out of its sandbox and hijack the host process. Tracked as GHSA-864f-rcv7-6rh4, the flaw affects versions before 7.0.1 and 6.2.0, with fixes released August 8, 2026.
Endor Labs researchers found the bug in native C++ binding code handling data transfers between V8 Isolates. An attacker can exploit a type-confusion and TOCTOU gap in ExternalCopy's transferList option using a JavaScript getter — swapping a valid ArrayBuffer for malicious data between validation and transfer.
At minimum, this crashes the host process. At worst, it enables arbitrary code execution outside the sandbox. Upgrade immediately.
Source: Cybersecurity News
A critical vulnerability in the Node.js sandboxing library isolated-vm can let untrusted JavaScript break out of its sandbox and hijack the host process. Tracked as GHSA-864f-rcv7-6rh4, the flaw affects versions before 7.0.1 and 6.2.0, with fixes released August 8, 2026.
Endor Labs researchers found the bug in native C++ binding code handling data transfers between V8 Isolates. An attacker can exploit a type-confusion and TOCTOU gap in ExternalCopy's transferList option using a JavaScript getter — swapping a valid ArrayBuffer for malicious data between validation and transfer.
At minimum, this crashes the host process. At worst, it enables arbitrary code execution outside the sandbox. Upgrade immediately.
Source: Cybersecurity News
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
A critical GitLab vulnerability (CVE-2026-19478) is being actively exploited, and administrators of self-managed instances need to patch immediately. Rated 9.4/10, the flaw lets unauthenticated attackers inject code through GitLab's GraphQL interface — no account or user interaction required.
Attackers can delete repositories, manipulate merge records, and ban legitimate maintainers from public projects. Security firm WatchTowr reproduced the exploit within minutes of disclosure and confirmed its honeypot network recorded live exploitation attempts.
The vulnerability spans GitLab CE/EE versions 18.2 through 18.11.10, 19.0 through 19.0.7, 19.1 through 19.1.5, and 19.2 through 19.2.3. Patched builds (18.11.11, 19.0.8, 19.1.6, 19.2.4) are available now. GitLab.com and Dedicated users are already protected. If you can't upgrade immediately, restrict GraphQL endpoint access and treat exposed servers as potentially compromised.
Source: Cybersecurity News
A critical GitLab vulnerability (CVE-2026-19478) is being actively exploited, and administrators of self-managed instances need to patch immediately. Rated 9.4/10, the flaw lets unauthenticated attackers inject code through GitLab's GraphQL interface — no account or user interaction required.
Attackers can delete repositories, manipulate merge records, and ban legitimate maintainers from public projects. Security firm WatchTowr reproduced the exploit within minutes of disclosure and confirmed its honeypot network recorded live exploitation attempts.
The vulnerability spans GitLab CE/EE versions 18.2 through 18.11.10, 19.0 through 19.0.7, 19.1 through 19.1.5, and 19.2 through 19.2.3. Patched builds (18.11.11, 19.0.8, 19.1.6, 19.2.4) are available now. GitLab.com and Dedicated users are already protected. If you can't upgrade immediately, restrict GraphQL endpoint access and treat exposed servers as potentially compromised.
Source: Cybersecurity News
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
Florida's Department of Health is reaching out to people affected by a June 26 cyberattack that exposed a wide range of sensitive personal data. We're talking names, Social Security numbers, banking details, medical history, medication and prescription information, military identification numbers, Nexus numbers, passwords, passport numbers — the works. The department has started mailing letters to those impacted with specifics on what was accessed.
To help, they've partnered with Kroll, an identity-monitoring firm, to provide free credit monitoring services. Law enforcement and cybersecurity experts are actively investigating. If you're a Florida Health Department client and haven't received a letter yet, it's worth keeping a close eye on your accounts.
Source: CBS News Miami
Florida's Department of Health is reaching out to people affected by a June 26 cyberattack that exposed a wide range of sensitive personal data. We're talking names, Social Security numbers, banking details, medical history, medication and prescription information, military identification numbers, Nexus numbers, passwords, passport numbers — the works. The department has started mailing letters to those impacted with specifics on what was accessed.
To help, they've partnered with Kroll, an identity-monitoring firm, to provide free credit monitoring services. Law enforcement and cybersecurity experts are actively investigating. If you're a Florida Health Department client and haven't received a letter yet, it's worth keeping a close eye on your accounts.
Source: CBS News Miami
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
A critical flaw in N-able's Passportal password manager allowed any website — including ones with malicious ads — to silently steal a user's entire password vault. Researcher James Arnott of Bay Area Labs discovered on July 8 that Passportal's browser extension trusted messages from any source without verification, handing over access tokens to anyone who asked.
Those tokens unlock everything: stored credentials, one-time passwords, and with a 100-day refresh token, persistent access long after the initial breach. N-able patched the issue the next day, but the core problem remains — Passportal still decrypts passwords on its own servers rather than locally, leaving users exposed to future attacks.
With roughly 2,500 MSPs using the product, a single compromised account could cascade across dozens of client organizations.
Source: Dark Reading
A critical flaw in N-able's Passportal password manager allowed any website — including ones with malicious ads — to silently steal a user's entire password vault. Researcher James Arnott of Bay Area Labs discovered on July 8 that Passportal's browser extension trusted messages from any source without verification, handing over access tokens to anyone who asked.
Those tokens unlock everything: stored credentials, one-time passwords, and with a 100-day refresh token, persistent access long after the initial breach. N-able patched the issue the next day, but the core problem remains — Passportal still decrypts passwords on its own servers rather than locally, leaving users exposed to future attacks.
With roughly 2,500 MSPs using the product, a single compromised account could cascade across dozens of client organizations.
Source: Dark Reading
A cybercrime group called BlackFile is actively targeting major financial firms, law firms, and rating agencies — and it's not slowing down. Researchers at Google Threat Intelligence Group say the group hits an average of 1.5 new victims daily, with malicious infrastructure spotted targeting Blackstone, Bain Capital, Moody's, CME, and Apollo.
BlackFile runs four extortion brands — Redact, Pink, Helix, and Falcon — using voice-phishing and IT impersonation to gain access. Demands typically start around $3 million but get negotiated below $1 million. Some recent victims have received threatening messages and have even been swatted (a tactic where false emergency calls are used). Mandiant has responded to over two dozen confirmed breaches since January.
Source: CyberScoop
A cybercrime group called BlackFile is actively targeting major financial firms, law firms, and rating agencies — and it's not slowing down. Researchers at Google Threat Intelligence Group say the group hits an average of 1.5 new victims daily, with malicious infrastructure spotted targeting Blackstone, Bain Capital, Moody's, CME, and Apollo.
BlackFile runs four extortion brands — Redact, Pink, Helix, and Falcon — using voice-phishing and IT impersonation to gain access. Demands typically start around $3 million but get negotiated below $1 million. Some recent victims have received threatening messages and have even been swatted (a tactic where false emergency calls are used). Mandiant has responded to over two dozen confirmed breaches since January.
Source: CyberScoop
A Somerset NHS worker accessed up to 200 patient records without permission between August 2017 and October 2023, sharing screenshots of medical information with their partner. The breach at Musgrove Park Hospital included sensitive data — demographic details, A&E visits, and appointment records — and even led to a patient being contacted using a phone number taken from hospital files.
The worker resigned before facing disciplinary action and received only a police caution, with officers concluding the actions weren't malicious. Victims are furious. "She violated families, vulnerable people," one told the BBC. Privacy campaigners are now calling for automatic NHS App notifications whenever patient records are viewed.
Source: BBC News
A Somerset NHS worker accessed up to 200 patient records without permission between August 2017 and October 2023, sharing screenshots of medical information with their partner. The breach at Musgrove Park Hospital included sensitive data — demographic details, A&E visits, and appointment records — and even led to a patient being contacted using a phone number taken from hospital files.
The worker resigned before facing disciplinary action and received only a police caution, with officers concluding the actions weren't malicious. Victims are furious. "She violated families, vulnerable people," one told the BBC. Privacy campaigners are now calling for automatic NHS App notifications whenever patient records are viewed.
Source: BBC News