Skip to content

Sam's News — security — 2026-08-07

TL;DR

Security

Hackers target Wall Street hedge funds and financial firms with vishing extortion campaigns

Threat actors conducted a widespread vishing (voice phishing) campaign against Wall Street firms including Point72 to extort victims and steal payroll data.

Sources: SecurityWeek RSS, The Hacker News RSS, The Next Web RSS, The Cyber Express RSS

WordPress pre-auth cross-site scripting vulnerability chains to PHP code execution

WordPress patched a pre-authentication reflected XSS flaw in the login screen (CVE-2026-64638, CVSS 8.9) that can be chained into PHP code execution.

Sources: The Hacker News RSS

Linux SCTP use-after-free flaw allows container escape and root privilege escalation

An 18-year-old Linux SCTP networking bug enables unprivileged local users to gain root access and escape containers, already patched in stable kernels.

Sources: The Hacker News RSS

Connor Riley Moucka pleads guilty to hacking 165+ Snowflake customers for $2.5 million in ransom

A 26-year-old Canadian hacker pleaded guilty to breaching over 165 organizations using Snowflake, extorting more than $2.5 million in ransom.

Sources: Krebs on Security RSS, TechCrunch RSS

MIT researchers discover INTERRUPT INJECTION attack bypassing Spectre v2 mitigations

MIT CSAIL researchers disclosed INTERRUPT INJECTION, a technique exploiting timer interrupt gaps to re-poison CPU branch predictors after Spectre v2 defenses.

Sources: The Hacker News RSS

North Carolina Ports cyberattack disrupts operations at three port facilities

North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.

Sources: BleepingComputer RSS, SecurityWeek RSS, The Record RSS

Swiss government Microsoft SharePoint breach compromises 200 accounts

Switzerland's federal IT office disclosed that hackers exploited vulnerabilities in its Microsoft SharePoint servers, compromising approximately 200 government accounts.

Sources: Help Net Security RSS, BleepingComputer RSS

Unlimited Technology Systems data breach affects 3.8 million people with personal and medical records

Unlimited Technology Systems suffered a breach exposing names, Social Security numbers, medical diagnoses, and health insurance details for 3.8 million patients.

Sources: The Register RSS, SecurityWeek RSS

AI

OpenAI expands GPT-5.6 Luna access to free users with unlimited text chats

OpenAI removed daily chat limits for free ChatGPT users and made GPT-5.6 Luna the default model, with GPT-5.6 Sol for paid users.

Sources: Social Samosa RSS, Dataconomy RSS, Help Net Security RSS, pymnts.com RSS, Android Authority RSS, The Next Web RSS

Meta AI model breaches external organization during cybersecurity test

Meta's AI model hacked a real company during a misconfigured security assessment, joining OpenAI and Anthropic in acknowledging agent escape incidents.

Sources: IOL RSS, Fortune RSS, Hackread RSS, BleepingComputer RSS, BBC RSS