Skip to content

Sam's News β€” security β€” 2026-08-26

Security

8.5 CISA alerts of actively exploited Gitea remote code execution vulnerability

CISA warns of active exploitation of a critical remote code execution flaw in Gitea with CVSS 9.8 being used to deliver miner-like payloads.

  • CVE-2026-60004: Gitea RCE flaw actively exploited in the wild
  • Patched in Gitea version 1.27.1 (late July 2026)
  • Requires repository write access to inject malicious Git hooks
  • Federal agencies must patch by August 28, 2026
  • No prior public reports of exploitation before CISA warning

Sources: SecurityWeek AI Web Searched, The Hacker News RSS

8.5 Clop ransomware exploits PLM zero-day in massive breach affecting Shell, GE, Philips

Russian hackers exploit a zero-day vulnerability in product lifecycle management software to breach nearly 50 companies including Shell, GE, and Philips.

Sources: Cyber Magazine Web Search Update to: Clop Ransomware Gang Breaches 50+ Organizations via Windchill and FlexPLM Vulnerability

8 AnonyMousKIT PhaaS platform uses voice AI to steal iPhone passcodes

Cybersecurity researchers disclose a PhaaS platform using AI voice agents impersonating Apple Support to steal device passcodes and 2FA codes from theft victims.

Sources: BleepingComputer RSS, The Hacker News RSS

8 CISA confirms Iran-backed hackers targeted over 100 U.S. water systems in July

Iran-backed hackers targeted over 100 U.S. water utility systems in July 2026, exploiting vulnerable industrial control equipment from Rockwell, Schneider Electric, and Siemens. Some intrusions allowed attackers to disable safety shutdown processes and alarms, though water supplies to communities remained largely unaffected.

  • Over 100 internet-exposed water systems targeted in July 2026
  • Attacks affected providers in Michigan, Minnesota, and at least 5 other states
  • Hackers targeted programmable logic controllers (PLCs) from Rockwell, Schneider Electric, and Siemens
  • Some intrusions disabled shutdown processes and alarms without notifying operators
  • U.S. intelligence believes Iran is likely responsible, though no formal attribution made
  • Over 100 water and wastewater systems targeted in July 2026
  • Attacks linked to Iranian threat actors
  • Affected systems in at least 12 U.S. states including Minnesota, Michigan, Georgia, New Jersey, Alabama
  • Targeted industrial control systems (PLCs) connected to cellular modems
  • No significant operational disruptions reported
  • CISA guidance recommends reducing internet exposure and implementing multifactor authentication

Sources: TechCrunch AI Web Searched, SecurityWeek AI Web Searched

8 CISA red team assessment exposes critical infrastructure defense gaps

CISA released red team assessments comparing two critical infrastructure organizations using identical attack tradecraft. One organization (government services) was fully compromised with zero detection; the other (water and wastewater) detected and isolated phishing within 2–20 minutes, highlighting stark defensive capability gaps.

  • Organization A completely compromised at domain level; no detection
  • Organization B detected initial payloads within 2–20 minutes
  • Organization A failures: thousands of false-positive alerts, multiple SOCs without shared visibility, analysts lacking escalation authority
  • Key vulnerabilities exploited: default Machine Account Quota, misconfigured AD CS templates (ESC1), cleartext credentials, static AWS keys with no expiration
  • Attacker stole Primary Refresh Token and abused over-permissioned Entra ID applications to read security team email

Sources: The Hacker News AI Web Searched

8 US Disrupts Chinese State-Backed Hacking Tools Targeting Federal Agencies

The FBI and Justice Department disrupted QTFY hacking platforms (QScan and QTRouter) operated by Chinese state-sponsored actors targeting U.S. critical infrastructure.

  • QScan automatically infected IoT devices; QTRouter concealed attack origins
  • Targeted 130+ countries including Federal Reserve, DOJ, Senate, NASA
  • Investigation began 2018; takedown followed 2026 Senate attack
  • Nanjing Xinjiuwei sold stolen data to Chinese military and intelligence agencies

Sources: The Record AI Web Searched, The Hacker News RSS, TechCrunch RSS

7.5 FBI disrupts Chinese cyber espionage infrastructure network

The FBI disrupted Chinese cyber espionage infrastructure that functioned as a technical quartermaster supplying reconnaissance tools, templates, and proxy services to enable cybercrimes at scale. The disruption involved seizure of domains, cryptocurrency assets, and infrastructure components.

  • Infrastructure supplied reconnaissance tools and proxy services for multiple cybercrimes
  • FBI seized domains, cryptocurrency assets, and infrastructure components
  • Operation targeted U.S. and international victims across multiple sectors

Sources: BleepingComputer AI Web Searched, Bank Info Security AI Web Searched

7.5 Ubiquiti patches three critical security vulnerabilities

Ubiquiti released patches in May 2026 for three critical vulnerabilities (CVSS 10.0) in UniFi OS Server 5.0.8 allowing unauthenticated remote compromise. By June 2026, CISA warned threat actors were actively exploiting these flaws in the wild to create rogue administrator accounts, with nearly 100,000 internet-exposed endpoints predominantly in the U.S.

  • Three maximum-severity vulnerabilities (CVSS 10.0) in UniFi OS Server 5.0.8
  • CVE-2026-34908: improper access control enabling unauthorized changes
  • CVE-2026-34909: path traversal allowing system file access and account manipulation
  • CVE-2026-34910: command injection via insufficient input validation
  • Threat actors actively exploiting in wild by June 2026; created rogue admin account 'John Sim' in automated attacks
  • Nearly 100,000 internet-exposed UniFi OS endpoints, mostly in United States

Sources: SecurityWeek AI Web Searched, SC Media AI Web Searched, The Hacker News AI Web Searched, BleepingComputer RSS

7.5 Unpatched Kaltura mwEmbed Flaws Allow Remote File Read and Code Execution

Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 video player (CVE-2026-19913, CVE-2026-19912) allow unauthenticated attackers to read arbitrary files and execute remote code via unsafe deserialization in mwEmbedLoader.php. No patch is available; CERT/CC was unable to coordinate with Kaltura.

  • CVE-2026-19913: unsafe deserialization allows file read via ServiceUrl parameter
  • CVE-2026-19912: RCE via same deserialization using malicious serialized objects
  • Researcher demonstrated retrieval of /opt/kaltura/app/configurations/local.ini containing plaintext credentials
  • No authentication or Kaltura session token required; network access to endpoint is only precondition
  • Affects both individual installations and all tenants in Kaltura's multi-tenant CDN infrastructure
  • No patch available; CERT/CC unable to reach Kaltura for coordination
  • No exploitation reported as of August 25, 2026

Sources: The Hacker News AI Web Searched

Policy

8 Meta Agrees to $18 Billion Settlement Over Teen Social Media Harms

Meta reached a settlement worth up to $18 billion with 52 attorneys general over allegations that Facebook and Instagram were designed to encourage compulsive use by minors.

  • $18 billion total settlement: $16.7 billion from 47 states plus DC and territories, $1 billion from Texas
  • 10-year requirement: 2-hour daily limit on teen use (both Facebook and Instagram combined)
  • Midnight–6 am block and school mode (8 am–3 pm) with default notification mute
  • 15-minute continuous-use prompts and alerts at 60 and 90 minutes of daily use
  • Bans on plastic surgery filters and similar compulsive-use features
  • Payment reduced by $5 billion if other major social media firms don't adopt similar terms

Sources: BleepingComputer RSS, Ars Technica AI Web Searched, The Verge RSS