About this episode
This week follows a chain of exploited trust: identity and gateway abuse, stolen cloud access, actively exploited services, industrial and engineering systems, repurposed infrastructure, software supply-chain attacks, endpoint control, and AI as both an attack surface and a SOC tool.
This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.
Play the episode, then review the stories and chapter list for the reporting and topics covered.
Stories covered this week
CVE-2026-54121: Enterprise CA Privilege Escalation Risk
CVE-2026-54121 allows a standard domain user to escalate privileges by turning an Enterprise Certificate Authority into a Domain Controller. The vulnerability highlights the risks of implicit trust and standing privilege within PKI infrastructure.
Source: BleepingComputer
Critical Out-of-Bounds Read Vulnerability in Siemens Parasolid
Siemens Parasolid versions prior to V38.0.235 and V38.1.230 are affected by a high-severity out-of-bounds read vulnerability in parsing X_T files, allowing potential arbitrary code execution. Siemens has released patches and advises prompt updates.
Source: CISA
CISA: Ransomware Gangs Exploiting Windows Task Host Flaw
CISA confirms ransomware groups are exploiting a high-severity Windows Task Host vulnerability first noted as actively exploited in April. This flaw poses significant risk to enterprise environments.
Source: BleepingComputer
Critical RCE Flaw in Windows IKE Extension Actively Exploited
CISA has issued a warning about active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions. This flaw allows attackers to execute arbitrary code on vulnerable systems without user interaction.
Source: BleepingComputer
Active Cyber Threat Targets Siemens S7 PLCs Using AI-Generated Exploits
US government agencies warn of an active cyber threat targeting Siemens S7 Series programmable logic controllers using AI-assisted exploitation scripts. Critical infrastructure sectors face risks including operational disruption, safety incidents, and data compromise.
Source: CISA
Critical NetScaler Flaw Can Bypass Authentication on Gateway Servers
Citrix patched two vulnerabilities in NetScaler ADC and Gateway, including a critical authentication bypass impacting certain FIPS and NDcPP builds. The flaw allows attackers to bypass authentication on affected gateway and AAA servers.
Source: The Hacker News
CISA Warns of Active Exploitation of Critical MLflow Vulnerability
CISA has issued a warning that threat actors are actively exploiting a critical vulnerability in the MLflow open-source AI engineering platform, targeting federal agencies and potentially broader organizations. The vulnerability's exploitation poses significant risks to AI development environments.
Source: BleepingComputer
CISA Adds Critical Zimbra OS Command Injection to Known Exploited Vulnerabilities
CISA has added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. This addition reinforces federal requirements to prioritize patching high-risk vulnerabilities under Binding Operational Directive 26-04.
Source: CISA
SilkParasite Espionage Targets Central Asian Governments with Five New RATs
SilkParasite, a newly uncovered cyber espionage campaign, targets Central Asian government bodies using seven remote access tools, five of which are previously undocumented. This operation highlights evolving threats from advanced adversaries in sensitive regions.
Source: The Hacker News
Suspected Russian Hackers Exploit Google OAuth and WhatsApp for Account Hijacking
Three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate Google OAuth flows and WhatsApp linking to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the U.S. These persistent threat actors focus on high-value sectors and employ adaptive tactics to hijack accounts.
Source: The Hacker News
Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes
A new modular Linux botnet called Evooo1Bot targets internet-facing routers to turn them into SOCKS5 proxy relay nodes. Based on Mirai, it leverages gateway devices for anonymized traffic relay, raising network abuse concerns.
Source: BleepingComputer
AmnesiaStealer macOS Malware Hijacks Browsers via Remote Control
AmnesiaStealer is a new macOS malware targeting users via ClickFix attacks, featuring a streaming module that allows attackers to remotely control victim web browsers. This enables interactive session hijacking and data theft.
Source: BleepingComputer
Clop Gang Uses Custom Web Shell for Targeted Windchill Data Theft
The Clop ransomware group developed a custom Java web shell targeting PTC Windchill and FlexPLM servers, enabling credential decryption, file enumeration, and data theft. This specialized malware reflects advanced tactics in enterprise data theft operations.
Source: BleepingComputer
Hackers Compromise Rust Crate to Deliver Infostealer Malware
Attackers compromised the maintainer account of the popular Rust crate arrayref to inject malware executing on developer systems during compilation. This supply chain attack risks sensitive data exposure across projects using the crate.
Source: BleepingComputer
StopAndProtect Uses 2,000 Hacked WordPress Sites to Spread Malware
A global cybercrime operation is abusing nearly 2,000 compromised WordPress sites to distribute malware and steal data using a range of criminal software tools. The campaign stores stolen documents, screenshots, and activity logs on infected hosts to track operations.
Source: The Hacker News
Trojanized npm Packages Deploy AI-Powered RedC2 4.0 Linux Backdoor
Researchers uncovered 14 malicious npm packages disguised as calendar and streak utilities that deliver RedC2 4.0, an AI-assisted Linux backdoor, running stealthily in the background. The implant is launched by marking a bundled binary executable upon module load.
Source: The Hacker News
Thousands of Active Leaked AWS Keys Expose Corporate Accounts
Over 9,300 AWS access keys leaked between August 2022 and August 2026 remain active, risking unauthorized control of corporate accounts. This exposure highlights critical gaps in cloud credential management.
Source: BleepingComputer
Hacker Claims 3.6M Azure Account Records Stolen from Major Companies
A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials. This exposes sensitive Azure account records and poses a high-impact enterprise security risk.
Source: BleepingComputer
CareCloud Data Breach Exposes Records of 3.7 Million Patients
Healthtech firm CareCloud disclosed a data breach impacting over 3.7 million patients. The incident raises concerns about exposed sensitive healthcare information.
Source: BleepingComputer
AI ‘Mind Viruses’ Can Spread Between Agents Via Persistent Prompt Files
Researchers have demonstrated that malicious payloads can propagate across AI agents by exploiting editable system prompt files used to maintain state in autonomous AI agents. This novel attack vector was tested in a simulated environment involving six AI coding agents.
Source: The Hacker News
Wazuh Integrates AI to Enhance SOC Workflows
Wazuh is leveraging AI to automate repetitive SOC tasks and uncover hidden patterns in security data, aiming to accelerate analyst decision-making. This integration reflects a growing trend of AI-driven enhancements in cybersecurity operations.
Source: The Hacker News
Chapters
- Opening
- CVE-2026-54121: Enterprise CA Privilege Escalation Risk
- Critical NetScaler Flaw Can Bypass Authentication on Gateway Servers
- Suspected Russian Hackers Exploit Google OAuth and WhatsApp for Account Hijacking
- Thousands of Active Leaked AWS Keys Expose Corporate Accounts
- Hacker Claims 3.6M Azure Account Records Stolen from Major Companies
- CareCloud Data Breach Exposes Records of 3.7 Million Patients
- Critical RCE Flaw in Windows IKE Extension Actively Exploited
- CISA: Ransomware Gangs Exploiting Windows Task Host Flaw
- CISA Adds Critical Zimbra OS Command Injection to Known Exploited Vulnerabilities
- CISA Warns of Active Exploitation of Critical MLflow Vulnerability
- Critical Out-of-Bounds Read Vulnerability in Siemens Parasolid
- Active Cyber Threat Targets Siemens S7 PLCs Using AI-Generated Exploits
- Clop Gang Uses Custom Web Shell for Targeted Windchill Data Theft
- Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes
- StopAndProtect Uses 2,000 Hacked WordPress Sites to Spread Malware
- Hackers Compromise Rust Crate to Deliver Infostealer Malware
- Trojanized npm Packages Deploy AI-Powered RedC2 4.0 Linux Backdoor
- SilkParasite Espionage Targets Central Asian Governments with Five New RATs
- AmnesiaStealer macOS Malware Hijacks Browsers via Remote Control
- AI ‘Mind Viruses’ Can Spread Between Agents Via Persistent Prompt Files
- Wazuh Integrates AI to Enhance SOC Workflows
- Closing