Sam's News โ tech โ 2026-08-21¶
Security¶
8.5 Rust Supply Chain Attack Compromises Three Popular Crates with 245M Downloads¶
The Rust Project removed malicious versions of three widely-downloaded crates published by a compromised maintainer account that injected a typosquatted dependency with a remote-executing build script.
- arrayref crate: 244 million downloads compromised
- Infostealer malware executes at developer compile time
- append-only-vec also targeted in same attack
- Supply chain compromise of widely-used Rust ecosystem packages
- Malicious arrayref v0.3.10 published August 20, 2026 on crates.io
- Depends on typosquatted crate proc-macro1 executing remote binary at build time
- Maintainer account droundy compromised; GitHub repos now unavailable (404)
- proc-macro1 published by dtolney account forging David Tolnay authorship
- Crates.io team removed malicious versions
Sources: The Hacker News RSS, The Register RSS Update to: Hackers Compromise Arrayref Rust Crate to Distribute Infostealer Malware
8.5 Microsoft Entra ID Critical Flaw (CVSS 10.0) Exploited in Wild; No Customer Action Required¶
Microsoft disclosed CVE-2026-69836, a maximum-severity remote code execution flaw in Entra ID with a CVSS score of 10.0, being exploited in the wild. Microsoft stated the vulnerability is fully mitigated and requires no customer action.
- CVE-2026-69836: remote code execution, CVSS 10.0 (maximum severity)
- Affects Microsoft Entra ID (formerly Azure AD)
- Being actively exploited in the wild
- Microsoft claims full mitigation; no customer remediation required
- CVSS 10.0 severity vulnerability in Microsoft Entra ID
- Unsafe deserialization flaw enables unauthenticated remote code execution
- Exploitation detected in the wild at time of disclosure, August 21, 2026
- Microsoft patched directly; no customer action required
- Discovered and reported by principal security engineer Robert Fitzpatrick
Sources: The Hacker News AI Web Searched, The Register AI Web Searched
7.5 Cisco Secure Workload Software Flaws with Critical Severity Ratings¶
Cisco disclosed five vulnerabilities in Secure Workload Software, including two critical flaws rated 10.0 for improper access control. The company has patched its SaaS offering, while on-premises users must upgrade to specific versions. No active exploitation has been detected.
- Two critical CVEs (10.0 CVSS): CVE-2026-20315, CVE-2026-20317
- One 9.9-rated flaw (CVE-2026-20231: command/OS/argument injection)
- On-premises versions 3.10 and earlier must upgrade to 3.10.9.1; v4.0+ to 4.0.4.16
- Vulnerabilities identified via AI-assisted internal security review
- No malicious exploitation detected to date
Sources: The Register AI Web Searched, The Hacker News RSS
7.5 Supermicro Terminates Staff After GPU Smuggling Investigation¶
Supermicro terminated staff following an investigation into alleged smuggling of $2.5 billion in GPU-equipped servers to China in violation of export controls. Three individuals, including co-founder Yih-Shyan Liaw, were indicted by the U.S. Department of Justice in March 2026. The company found no knowledge of the scheme among current senior management.
- $2.5 billion in servers with Nvidia GPUs allegedly diverted to China
- Three individuals indicted: Yih-Shyan Liaw (co-founder), Ruei-Tsang Chang, Ting-Wei Sun
- Staff in sales, technical support, and business development terminated for export control failures
- No current senior management involved in alleged scheme
- Board adopted enhanced export compliance program recommendations
Sources: The Register AI Web Searched
7.5 CISA Urges Immediate Patching of Actively Exploited TrueConf Vulnerabilities¶
CISA warned on 21 August 2026 that threat actors are actively exploiting two critical vulnerabilities in TrueConf video conferencing software to deploy PhantomCore malware. The flaws allow remote code execution and privilege escalation on unpatched TrueConf Server instances since 2022.
- CVE-2026-72529 and CVE-2026-72530: critical-severity flaws in TrueConf Server
- Affect all versions from 2022; patched in June 2026 (5.3.9, 5.4.9, 5.5.5)
- Exploit vector: remote access via port 4307/TCP
- Actively exploited by hacktivist group Head Mare to deploy PhantomCore malware
- CISA KEV catalog: federal agencies must patch within 3 days (72529) or 2 weeks (72530)
- CVE-2026-72529 and CVE-2026-72530 added to CISA Known Exploited Vulnerabilities catalog on August 21, 2026
- Attacker: Ukrainian hacktivist group Head Mare
- Targeted Russian sectors: transport, energy, electronics, IT, software development
- Unauthenticated access via TCP port 4307 (open by default)
- Combined vulnerabilities allow arbitrary code execution and server control
Sources: SecurityWeek AI Web Searched, The Register AI Web Searched
7.5 iAuthFlow V2 phishing toolkit exploits passkeys for persistent access¶
iAuthFlow V2, a phishing toolkit sold on Russian-language cybercrime forums for $10,000 base price, enables attackers to maintain persistent access by silently registering attacker-controlled passkeys during authentication. Victims cannot revoke access through standard password resets or session revocation, as the registered passkey circumvents typical account recovery measures.
- iAuthFlow V2 base price: $10,000 with additional modules sold separately
- Attacker registers passkey during authentication, persisting through password resets and session revocation
- Attack uses attacker-controlled server browser environment relaying victim's credentials and auth responses
- Device fingerprinting applied to target's browser; all entries logged
- Toolkit demonstrated against Gmail accounts; passkey module analysis performed without running malware
Sources: SecurityWeek AI Web Searched, The Register RSS
7.5 Apollo private equity firm confirms data breach amid financial sector hacking wave¶
Apollo Global Management, managing $938 billion in assets, confirmed a data breach involving names, birth dates, addresses, and Social Security numbers after hackers used social engineering to access its cloud environment between July 6โ10, 2026. The breach follows weeks after Google disclosed a widespread campaign targeting financial firms, where similar attacks have netted hackers ransoms as high as $750,000.
- Apollo AUM: $938 billion; approximately 5,000 employees as of February 2026
- Social engineering attack accessed cloud environment July 6โ10, 2026
- Data compromised: names, birthdates, addresses, Social Security numbers
- Google identified hackers as Falcon, Helix, Pink, and Redact targeting financial/PE firms
- Ransoms from similar attacks reached $750,000; Apollo did not confirm if ransom was paid
Sources: TechCrunch AI Web Searched
Technology¶
8 Meta Faces Landmark Child Safety Lawsuit¶
Meta is defending a significant court case alleging inadequate child safety protections on Facebook and Instagram that could force changes to core platform features.
Sources: Wired RSS
Autonomous Vehicles¶
7.5 Tesla, Uber, and Waymo cleared to deploy thousands of robotaxis in Nevada¶
Nevada regulators approved permits for Tesla, Uber, and Waymo to deploy up to 8,000 robotaxis combined in Clark County over the next 12 months. Tesla received the largest allocation at 5,000 vehicles but expects to deploy approximately 2,500 initially. Local taxi operators opposed the approvals citing congestion concerns.
- Combined approval: up to 8,000 robotaxis over 12 months
- Tesla authorized for up to 5,000 (expects ~2,500 deployment)
- Waymo: 1,000 vehicles; Uber: 1,000 (via Motional/Zoox partnerships)
- Approval unanimous on August 20, 2026
- Livery Operators Association opposed citing oversaturation and congestion risks
Sources: TechCrunch AI Web Searched
Hardware¶
7.5 Apple lays off 60 employees from Vision Products group¶
Apple cut more than 200 jobs from its Siri and Vision Pro divisions, including largely shutting down a Vision Pro gaming team and reducing immersive content production.
Sources: MacRumors Web Search, The Verge RSS, Bloomberg.com Web Search