Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION
Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
Hack One Robot, Reach the Next: Unitree G1 Security Flaws
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
Love Electric Breach: 877,000 Driver Records Offered for $600
Trump Targets Foreign Technology in New U.S. Power Grid Security Order
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Australian Police Charge Two Over TeamPCP Credential Theft
Meta to Pay Up to $18B Over Teen Social Media Use
CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do
OpenAI banned Russian ChatGPT accounts backing covert influence operation
CISA Red Team Fully Compromised Two Critical Infrastructure Orgs
FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
88 ID Verification Breaches Show the Cost of Collecting Identity Data
WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
When the Algorithm Fires You: Uber Faces €825M Fine
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Cybercriminals Turn GTA VI Leaks Into Malware Bait
Slovakia Warns of Cyber Risks in Road Speed Cameras
TikTok Settles U.S. Child Privacy Case for $400 Million
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
International Press – Newsletter
Cybercrime
iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets
Fake GTA VI ISO circulates on the internet a few days after leak, internet sleuths claim 113GB download is padded malware
Taiwan charges 9 over illegal AI server exports to China, including Nvidia and Super Micro staff
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
58 arrests in global effort to dismantle West African organized crime groups
Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
RTM Locker interview: a ransomware actor on the RaaS market
Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate
Love Electric driver data for sale: NI, licence numbers
Ransomware group says it stole Berlin data, offers it for auction
Malware
FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
SLEEPWALKER: A Passive Backdoor With Its Own Command Language
Hacking
One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
A Tale of Two SOCs: Insights From Two Red Team Assessments
Three UK airports hit by cyber-attack with data of 8.7m customers accessed
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
PaperCut Releases Emergency Patch for Exploited Zero-Day
Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
The Hugging Face incident and the road ahead
Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range
PaperCut Actively Exploited: A Pre-Auth RCE Chain
Intelligence and Information Warfare
Iranian hackers shut down UK power plant
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor
Digdir stabilizes solutions after cyberattack
Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure
The infrastructure quartermaster: inside a China-nexus state enablement model
Disrupting a new covert influence campaign from Russia
Tortoiseshell: New Toolset and Operational Infrastructure Exposed
Treasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-Day
Dark Caracal Reloaded: New Malware, Same Hunting Grounds
Cambodia-focused cluster uses multistage infection chain with localized lures
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Cybersecurity
Warning about the risks of road meters
One billion people are now protected with passkeys on WhatsApp, plus more account security features
An ID Check Breach Timeline: 2011–2026
Internet Exposure Reduction Guidance
Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction
DECLARING A NATIONAL EMERGENCY TO SECURE THE UNITED STATES BULK-POWER SYSTEM
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
( SecurityAffairs – hacking, newsletter )
About Author
Andy Curtis is an award-winning security consultant, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by state and federal government, leading healthcare and banking providers across three continents. He has given talks about computer security for some of the world’s largest companies, worked with law enforcement agencies on investigations into hacking groups, and is a regular voice on TV and radio explaining IT security threats.
Tags: Breaking News , Cybercrime , data breach , hacking , hacking news , information security news , IT Information Security , Malware , Newsletter , Pierluigi Paganini , Security , Security News
0%
Love
0%
Funny
0%
Wow
0%
Sad
0%
Angry
Post navigation