UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context…
A week in security (August 17 – August 23)
A list of topics we covered in the week of August 17 to August 23 of 2026
Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks
Malicious npm packages are being used to place a Linux backdoor inside calendar and streak-calculation tools. The packages deliver legitimate date…
AWS Network Firewall Adds Rule Hit Counts to Identify Unused Security Rules
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often…
Cybermes – AI Red Teaming Agent for Automated Penetration Testing
A new open-source project called Cybermes has entered the crowded field of AI-powered offensive security tooling, positioning itself as an…
macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner
A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic…
AWS Network Firewall Now Displays Count of Triggered Security Rules
AWS has introduced rule hit count support for AWS Network Firewall, giving security teams direct visibility into which stateful firewall rules are…
IT Security News Hourly Summary 2026-08-24 09h : 6 posts
6 posts published in the last hour 06:31First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet 06:02New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File 06:02Critical isolated-vm Flaw Lets Attackers Escape Sandbox…
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and…
New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File
A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service.…
Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow
A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm. This flaw could potentially allow untrusted…
Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or…
RedC2 Turns Compromised Linux Machines Into SOCKS5 Proxies for Internal Network Pivoting
A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency…
IT Security News Hourly Summary 2026-08-24 08h : 4 posts
4 posts published in the last hour 05:31Fake bank websites play dead to evade security scanners 05:31Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack 05:02Ransomware attackers are zeroing in on mid-market companies 05:02Anthropic Brings Claude Mythos…
Fake bank websites play dead to evade security scanners
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while…
Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack
A cyberattack linked to Iranian threat actors forced a British power plant offline for four consecutive days in July, reportedly marking the first…
Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between…
Anthropic Brings Claude Mythos 5 to Cyber Defenders for Vulnerability Scanning and Patching
Anthropic has enhanced its AI-driven cyber defense offerings by integrating Claude Mythos 5 into Claude Security. This new feature enables enterprise…
AWS makes it easier to spot firewall rules that have gone quiet
AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them…
Cybersecurity Newsletter Bulletin– Top 50 Biggest Cybersecurity Stories of the Week – Shell & Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064,…
Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet
Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a…
NIUS – 6,090 breached accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses…
IT Security News Hourly Summary 2026-08-24 00h : 3 posts
3 posts published in the last hour 21:58IT Security News Weekly Summary 34 21:55IT Security News Daily Summary 2026-08-23 21:31Phishing Campaign Exploits COLDCARD Vulnerability Fears to Spread ScreenConnect