DJBSEC's CyberNews 2026-08-12
Today’s daily news covers the following categories: Nation-State/APT Vulnerability Malware Threat Intelligence Data Breach
Iran-Linked Hackers Expand Attacks on U.S. Water Infrastructure
Nation-State/APT
Iran-linked hackers have expanded a campaign against U.S. water infrastructure, with confirmed attacks now reaching New Jersey and Alabama and at least 12 states affected since late July. The attackers have been targeting internet-exposed industrial control systems, including equipment from Rockwell Automation, with incidents in New Jersey temporarily affecting remote access while water service and quality remained unaffected. An Alabama utility also disconnected portions of its monitoring and control network after attackers targeted a programmable logic controller, although water service was not disrupted. The incidents follow similar attacks in states including Minnesota, Michigan, South Dakota, and Georgia. CISA has urged water utilities to remove PLCs and industrial control systems from direct internet exposure as attackers continue scanning for vulnerable systems.
Microsoft Patches 398 Vulnerabilities Including Actively Exploited Windows Zero-Day
Vulnerability
Microsoft’s August Patch Tuesday addresses 398 vulnerabilities, including 62 rated Critical and a Windows kernel zero-day already being exploited in attacks. The actively exploited flaw, CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock and allows an attacker who already has code running on a machine to elevate privileges to SYSTEM. Check Point researchers linked exploitation of the vulnerability to North Korea’s Lazarus Group and its Operation Dream Job campaign. Microsoft also patched four remote code execution flaws rated 9.8 that require no authentication or user interaction, including vulnerabilities affecting Windows DNS Server, Deployment Services, QUIC, and HPC Pack. Administrators are advised to prioritize the actively exploited zero-day before addressing exposed systems vulnerable to the critical remote code execution flaws.
Kimwolf v7 Botnet Disguises DDoS Traffic as Chrome Activity
Malware
Researchers have uncovered Kimwolf v7, an upgraded version of the Android TV botnet that uses sophisticated techniques to disguise distributed denial-of-service traffic as legitimate Chrome browsing. The malware generates complete HTTP/2 browser fingerprints that closely resemble Chrome traffic, making malicious requests more difficult for traditional DDoS defenses to identify and block. Kimwolf also uses Ethereum Name Service domains and multiple public blockchain endpoints to locate its command-and-control infrastructure, increasing its resilience against takedowns. The botnet primarily compromises Android TV boxes and set-top boxes and has been operating since 2025 as part of a broader DDoS ecosystem. Researchers say the new version demonstrates how botnet operators are increasingly combining legitimate protocols and decentralized infrastructure to evade detection.
ShieldBreak Zero-Day Bypasses Microsoft’s RoguePlanet Defender Patch
Vulnerability
A security researcher has released proof-of-concept code for a Windows zero-day called ShieldBreak that bypasses Microsoft’s previous fix for the RoguePlanet vulnerability. RoguePlanet, tracked as CVE-2026-50656, is a privilege-escalation flaw in the Microsoft Malware Protection Engine used by Defender, and Microsoft attempted to address it in July. The ShieldBreak bypass can reportedly still allow an attacker with local access to obtain SYSTEM-level privileges and execute arbitrary code despite the earlier patch. The researcher says the proof of concept achieved consistent exploitation on current Windows 11 and Windows Server 2025 systems, while Windows 10 is also believed to remain vulnerable. The disclosure raises concerns that Microsoft’s original remediation did not fully eliminate the underlying attack path.
XSS2Shell WordPress Flaw Can Turn Failed Login Into Server Compromise
Vulnerability
Researchers have disclosed XSS2Shell, a WordPress vulnerability that can turn a specially crafted failed login attempt into a path toward remote PHP code execution. Tracked as CVE-2026-64638 with a severity score of 8.9, the flaw affects WordPress core and begins with a pre-authentication cross-site scripting weakness on the login page. Full exploitation requires an attacker to trick an already authenticated administrator into interacting with a malicious website, after which the attack can abuse the administrator’s session to obtain an application password and upload a malicious plugin. Researchers estimated that more than 500 million websites may have been exposed before corrected versions became available, although there is currently no reported malicious exploitation. WordPress fixed the issue in version 7.0.3 and released corrected maintenance updates for older supported branches.
Bugtraq Vulnerability Disclosure Mailing List Returns
Threat Intelligence
Bugtraq, one of cybersecurity’s oldest vulnerability disclosure mailing lists, has officially returned after security researcher Jonathan Brossard announced its revival at DEF CON 34. Originally founded in 1993, Bugtraq became an important forum where researchers publicly discussed vulnerabilities, mitigations, security advisories, and technical research. The relaunched service is being operated independently through SecurityFocus and is intended to provide a free, moderated, and permanently archived alternative to security information scattered across social media, paywalls, and disappearing websites. The project also includes a separate mailing list dedicated to AI research and formal proofs. Organizers say the revived Bugtraq will remain an open community resource with no paywall or commercial agenda.
CAV3RN Malware Hides Command Traffic Behind Google Apps Script
Nation-State/APT
Researchers tracking the CAV3RN espionage framework have discovered a new communication component that uses Google Apps Script to conceal command-and-control traffic behind legitimate Google infrastructure. CAV3RN, which has been used against targets in Israel, can dynamically choose between direct HTTPS communications and a Google-hosted relay based on instructions delivered through DNS responses. The malware can also rotate its Google Apps Script deployment identifiers without requiring the malware itself to be replaced, making its infrastructure more resilient. Because many organizations routinely allow Google and DNS traffic, the technique can make malicious communications more difficult to distinguish from legitimate activity. Researchers recommend correlating DNS activity, process behavior, and Google-hosted connections instead of automatically treating traffic to trusted cloud services as safe.
Attackers Exploit Critical VMware vCenter Flaw Days After Disclosure
Vulnerability
Threat actors are actively exploiting a critical VMware vCenter vulnerability to execute code and establish persistent remote access on compromised servers. The flaw, CVE-2026-59310, carries a CVSS score of 9.8 and allows an attacker with network access to exploit directory traversal and execute arbitrary code on vulnerable vCenter systems. Researchers observed attackers installing malicious cron jobs and using the open-source reverse_ssh utility to maintain persistent connections to attacker-controlled infrastructure. Exploitation began just five days after Broadcom publicly disclosed the vulnerability, with researchers identifying as many as 361 victim IP addresses across 47 countries. The campaign has not been definitively attributed, although researchers suspect an advanced persistent threat actor may be responsible.
Samsung Patches 176 Vulnerabilities in Preinstalled Android Apps
Vulnerability
Mobile security researchers have disclosed 176 vulnerabilities discovered during a three-year audit of Samsung’s preinstalled Android applications, with some flaws enabling camera recording, screen capture, account-token theft, DNS manipulation, and code execution. Because many of the affected applications run with elevated system privileges and cannot normally be removed, successful exploitation could provide capabilities unavailable to ordinary Android applications. Researchers estimated that more than 100 million devices were potentially exposed before the vulnerabilities were corrected. Samsung patched all 176 issues through security updates and awarded researchers more than $200,000 through its bug bounty program. Samsung users running current security updates are protected from the disclosed vulnerabilities.
Malicious LiteLLM Releases May Have Exposed Thousands of Organizations
Data Breach
Researchers say two malicious versions of the popular LiteLLM Python package may have exposed sensitive credentials and secrets belonging to thousands of organizations. The compromised releases appeared on PyPI for roughly 40 minutes in March and contained credential-stealing code capable of harvesting cloud credentials, SSH keys, Kubernetes tokens, database passwords, and other secrets. CloudSEK analyzed roughly 434,000 files allegedly captured during the campaign and identified potential exposure involving more than 2,500 organizations, although researchers stress that this number should not be interpreted as a confirmed victim count. The malicious LiteLLM releases have also been linked to the broader Trivy supply chain compromise, demonstrating how attacks against development tooling can cascade across organizations. Potentially affected organizations are being urged to rotate exposed credentials rather than wait for evidence that stolen secrets were actually used.
Enjoy Reading This Article?
Here are some more articles you might like to read next: