About this episode
This week, attackers target exposed edge infrastructure, compromise trusted software distribution, steal authenticated sessions and cloud credentials, exploit familiar work flows, and turn third-party access into large-scale data exposure.
This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.
Play the episode, then review the stories and chapter list for the reporting and topics covered.
Stories covered this week
GiveWP WordPress Plugin Flaw Lets Hackers Execute Server Commands
A critical vulnerability in the GiveWP donation plugin for WordPress allows unauthenticated attackers to execute arbitrary commands on the hosting server. This flaw poses a high risk to websites using the plugin without immediate patching.
Source: BleepingComputer
Critical JFrog Artifactory Flaw Exploited Days After Patch
Attackers are actively exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, shortly after its public disclosure and patch release. This flaw allows unauthorized administrative access with a CVSS score of 9.8.
Source: The Hacker News
Critical Langflow Flaw Exploited to Steal OpenAI and AWS Keys
An unauthenticated remote code execution vulnerability in Langflow (CVE-2026-0768) is being exploited to steal sensitive credentials including OpenAI and AWS keys. This open-source AI framework's flaw poses a significant risk to cloud and AI application security.
Source: BleepingComputer
Attackers Exploit Two SonicWall SMA 1000 Zero-Days
SonicWall released updates for two zero-day vulnerabilities in SMA 1000 VPN appliances exploited in the wild, including a critical pre-authentication SSRF flaw scoring 10.0 CVSS. The flaws were internally discovered and could form an attack chain.
Source: The Hacker News
Critical Elementor Pro Flaw Enables Takeover of WordPress Sites
A critical vulnerability (CVE-2026-32475) in Elementor Pro is actively exploited to deliver webshells and execute arbitrary commands on WordPress servers. This flaw was recently patched but ongoing attacks pose significant risks to site security.
Source: BleepingComputer
Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Run Code as Root
Cisco patched a critical vulnerability in Silicon One-based Nexus 9000 switches allowing unauthenticated remote code execution as root, tracked as CVE-2026-20212 with a CVSS score of 9.8. Additionally, IOS XR received a hardening update addressing 7 umbrella CVEs, including two rated 9.8, with no workarounds available.
Source: The Hacker News
CISA Adds Critical Chromium V8 Vulnerability to Exploited Catalog
CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities Catalog due to active exploitation. Federal agencies must urgently patch this vulnerability under BOD 26-04, which prioritizes rapid remediation of such high-risk issues.
Source: CISA
Active Attacks Exploit Critical Citrix NetScaler Auth Bypass
Attackers have begun exploiting a critical authentication bypass vulnerability (CVE-2026-19490) in Citrix NetScaler devices, posing a significant risk to enterprise environments. Security teams are urged to prioritize patching and mitigation to prevent potential breaches.
Source: BleepingComputer
China-Linked Fire Ant Targets Cisco Routers to Steal Credentials
The China-linked Fire Ant group has expanded its cyber espionage operations by compromising Cisco IOS XR routers, TACACS servers, and Linux hosts to steal credentials and disable security logs. This advanced intrusion affects critical network infrastructure used in high-value environments.
Source: The Hacker News
Iranian Hackers Use Coding Tests to Deliver Cross-Platform RATs
The Iranian Nimbus Manticore group deploys novel malware families targeting Linux and macOS via Node.js and JavaScript RATs disguised as recruiter coding tests. Kaspersky tracks this evolution, highlighting expanded platform targeting in state-sponsored campaigns.
Source: The Hacker News
US Charges Russian for Malware Campaign Targeting 80,000 Freelancers
A Russian national has been indicted by a California federal grand jury for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware. This operation represents significant state-sponsored cybercrime targeting remote workers.
Source: BleepingComputer
Anthropic warns of infostealer malware hijacking Claude AI sessions
Anthropic alerts users that infostealer malware is stealing active Claude AI login sessions to fraudulently consume usage. This malware compromise allows attackers to access accounts and drain resources unnoticed.
Source: BleepingComputer
Microsoft alerts on TerminalFix attacks using reverse tunnels
A new ClickFix malware variant called TerminalFix tricks victims into executing malicious PowerShell commands via fake Cloudflare CAPTCHA prompts, enabling reverse tunnels through Windows Terminal. This technique allows attackers to maintain persistent access on compromised systems.
Source: BleepingComputer
BraZetsu Malware Turns Windows Hosts Into Underground Marketplace Assets
Researchers reveal BraZetsu, a Python-based Windows malware that converts compromised systems into inventory for criminal marketplaces. This master toolkit uniquely supports Initial Access Brokers by commercializing infected hosts.
Source: The Hacker News
Guildma (Astaroth) Malware Infection via Brazilian Portuguese Email
A new wave of Guildma (also known as Astaroth) malware infections is spreading through Brazilian Portuguese phishing emails. This malware poses significant risks by stealing sensitive information and evading detection.
Source: SANS ISC
New 'Ted' Backdoor Hides in HAProxy to Intercept Web Traffic
A new Linux backdoor named 'Ted' has been discovered embedded in trojanized HAProxy builds at South Korean organizations, intercepting and altering web traffic. This implant requires code execution on the host and is not a HAProxy vulnerability.
Source: The Hacker News
McKesson Breach Exposes 284 Million Patient Records, ShinyHunters Claims Theft
McKesson disclosed a cybersecurity breach involving unauthorized access to third-party applications, with the extortion group ShinyHunters claiming they stole 284 million patient records. The incident highlights the ongoing risk of large-scale healthcare data breaches by threat actors.
Source: BleepingComputer
Aesto Health Data Breach Exposes Over 9.5 Million Patients
Aesto LLC, operating as Aesto Health, recently disclosed a data breach affecting more than 9.5 million patients. The incident raises significant concerns about patient data security in healthcare.
Source: BleepingComputer
IDScan sued over breach exposing 153 million driver’s licenses
IDScan faces multiple lawsuits after hackers allegedly breached its identity verification service and sold data on over 153 million driver’s licenses. This incident highlights significant risks around personal data security in identity verification platforms.
Source: BleepingComputer
Coder’s registry compromised to distribute malicious Terraform modules
Attackers breached Coder's Cloudflare infrastructure to add unauthorized registry servers pushing malicious Terraform modules embedded with credential-stealing code. This compromise risks widespread credential theft among developers using Coder’s registry.
Source: BleepingComputer
BGP Hijack Delivers Malicious Virtualizor Update with Root Access
Hackers used a BGP hijack to redirect Softaculous update traffic, delivering a malicious Virtualizor package that established persistent root access on some hypervisors. Five hypervisors were confirmed to be compromised during the incident window on August 28.
Source: The Hacker News
ASCII Smuggling Technique Evolves from AI Prompt Injection to Phishing Evasion
Attackers are now using invisible Unicode characters, originally used for hiding instructions from AI models, to obfuscate phishing emails and bypass filters. This technique complicates detection and highlights emerging threats to email security.
Source: Microsoft
The Coding-Agent Trap: Malicious Use of Free LLM Endpoints Exposed
A public LLM inference honeypot was discovered and repurposed by attackers to provide 'free' backend services, exposing sensitive coding-agent session details without tool execution. This highlights risks of using untrusted LLM endpoints in security-critical environments.
Source: SANS ISC
Chapters
- Opening
- Active Attacks Exploit Critical Citrix NetScaler Auth Bypass
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days
- China-Linked Fire Ant Targets Cisco Routers to Steal Credentials
- Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Run Code as Root
- New 'Ted' Backdoor Hides in HAProxy to Intercept Web Traffic
- Critical JFrog Artifactory Flaw Exploited Days After Patch
- Coder’s registry compromised to distribute malicious Terraform modules
- BGP Hijack Delivers Malicious Virtualizor Update with Root Access
- CISA Adds Critical Chromium V8 Vulnerability to Exploited Catalog
- GiveWP WordPress Plugin Flaw Lets Hackers Execute Server Commands
- Critical Elementor Pro Flaw Enables Takeover of WordPress Sites
- Critical Langflow Flaw Exploited to Steal OpenAI and AWS Keys
- Anthropic warns of infostealer malware hijacking Claude AI sessions
- The Coding-Agent Trap: Malicious Use of Free LLM Endpoints Exposed
- Microsoft alerts on TerminalFix attacks using reverse tunnels
- ASCII Smuggling Technique Evolves from AI Prompt Injection to Phishing Evasion
- Guildma (Astaroth) Malware Infection via Brazilian Portuguese Email
- Iranian Hackers Use Coding Tests to Deliver Cross-Platform RATs
- US Charges Russian for Malware Campaign Targeting 80,000 Freelancers
- BraZetsu Malware Turns Windows Hosts Into Underground Marketplace Assets
- McKesson Breach Exposes 284 Million Patient Records, ShinyHunters Claims Theft
- Aesto Health Data Breach Exposes Over 9.5 Million Patients
- IDScan sued over breach exposing 153 million driver’s licenses
- Closing