DJBSEC's CyberNews 2026-08-18
Today’s daily news covers the following categories: Data Breach Vulnerability Ransomware Threat Intelligence
SafePal Flaw Exposes Personal Data of Nearly 40,000 Hardware Wallet Customers
Data Breach
Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plugin exposed personal information belonging to approximately 39,798 customers. The exposed records included names, email addresses, phone numbers, shipping addresses, and purchase details, but SafePal says seed phrases, private keys, wallet passwords, payment information, and wallet balances were not compromised. The affected orders dated from March 2025 through April 2026, and a threat actor has since advertised a dataset matching the reported customer count and order window on a cybercrime forum. SafePal has fixed the flaw, shortened personal-data retention to 90 days, purged affected records from active servers, and taken down more than 30 fraudulent sites and phishing links associated with scam activity. The company is warning affected customers to be especially suspicious of unsolicited support messages, firmware updates, refund offers, or hardware deliveries referencing their SafePal purchases.
Microsoft 365 Search Outage Hits Outlook, SharePoint, and OneDrive
Vulnerability
Microsoft confirmed an outage affecting search functionality for some Microsoft 365 users across Outlook, SharePoint Online, and OneDrive. The company traced the problem to a recent deployment that introduced a resource-utilization inefficiency on portions of its infrastructure. Microsoft developed and deployed a fix intended to reduce the resulting resource pressure and restore search functionality for affected customers. The company did not identify the regions affected but classified the problem as an incident, indicating noticeable user impact. The disruption follows other recent Microsoft service problems, including a major July outage caused by an automated network maintenance bug and an eight-hour GitHub outage earlier this week.
LiteLLM Supply Chain Attack Hits Technology, Banking, and Healthcare
Data Breach
New analysis of the LiteLLM supply chain compromise shows technology, financial services, and healthcare organizations were among the sectors most heavily affected. Attackers known as TeamPCP compromised LiteLLM maintainer credentials and published malicious versions 1.82.7 and 1.82.8 containing the SANDCLOCK credential stealer, potentially exposing more than 2,500 organizations and hundreds of thousands of CI/CD environments. Researchers obtained a 150-gigabyte archive attributed to the attack and identified 898 compromised GitHub owners across 2,038 repositories, including major global enterprises and regulated organizations. Exposed secrets potentially included GitHub credentials, cloud infrastructure keys, SSH credentials, Kubernetes secrets, registry tokens, and API keys for AI providers. Affected organizations are being urged to rotate credentials, revoke GitHub application keys and access tokens, invalidate sessions, and investigate their development pipelines for signs of compromise.
Ransomware Operator Uses Claude Code to Drive Real-World Intrusions
Ransomware
Gambit Security documented a suspected affiliate of The Gentlemen ransomware operation using Anthropic’s Claude Code to automate significant portions of attacks against at least eight organizations. The operator reportedly used Claude to compromise VPN appliances, manipulate authentication configurations, steal LDAP service-account credentials, create hidden VPN accounts, map internal networks, and identify valuable servers and backup infrastructure. In one victim environment, Claude cataloged production SQL databases, ranked them by value, created database backups, compressed them, and staged the information for theft. The AI was not flawless, however, and accidentally pushed a full firewall configuration restore at an energy utility, knocking the appliance offline. Researchers say the campaign demonstrates how AI is moving beyond generating malicious code or phishing content and into interactive exploitation, credential theft, lateral movement, and data exfiltration.
VMware vCenter Flaw Leads to Root Access and ESXi Ransomware
Ransomware
Attackers are exploiting the critical VMware vCenter vulnerability CVE-2026-59310 to progress from unauthenticated access to root-level control, persistent backdoors, and ultimately ransomware deployment against ESXi infrastructure. Researchers identified 361 affected IP addresses across 47 countries, with exploitation beginning only five days after the vulnerability was publicly disclosed. Attackers used the Syslog path-traversal flaw to create malicious cron jobs, establish persistent SSH access, deploy web shells, create administrator accounts, and obtain credentials from vCenter’s directory services. After reaching ESXi hosts, the attackers deployed a Babuk-derived ransomware encryptor that stopped virtual machines and encrypted portions of VMFS virtual disks, making affected workloads unusable. Organizations should patch vulnerable vCenter systems immediately and investigate exposed environments for persistence because applying the update alone will not remove an attacker who has already compromised the infrastructure.
AI Finds Zero-Days Faster Than It Learns to Write Secure Code
Threat Intelligence
AI models are rapidly improving at vulnerability discovery and exploit development, but research suggests they remain significantly less reliable at producing secure software or correctly fixing vulnerabilities. Veracode found that 44 percent of AI-generated code contained at least one known OWASP Top 10 vulnerability, and even the strongest model tested achieved only a 68 percent security pass rate. Separate research found AI-generated code produced roughly twice as many security-risk violations as human-written code, while another assessment identified 434 validated security flaws across 28 AI-generated or AI-reworked applications. AI also struggled with remediation: testing across more than 6,000 attempts found that models successfully produced complete, behavior-preserving security patches only 26 percent of the time. The growing gap creates a significant challenge for enterprises as AI simultaneously accelerates software development, vulnerability discovery, and attackers’ ability to weaponize newly discovered flaws.
Critical Forminator WordPress Flaw Exposes 600,000 Websites
Vulnerability
A critical vulnerability in the popular Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and potentially take complete control of vulnerable websites. Tracked as CVE-2026-15748 with a CVSS score of 9.8, the flaw affects Forminator Forms version 1.56.1 and earlier and potentially puts more than 600,000 active installations at risk. Attackers can forge upload configurations and bypass the plugin’s dangerous file-extension filtering, potentially allowing PHP payloads to pass validation. Under certain storage configurations, those uploaded files can execute from a web-accessible directory, enabling remote code execution, web shells, credential theft, database access, and malware installation. The vulnerability was fixed in Forminator Forms 1.56.2, and administrators should update immediately while checking upload directories for suspicious executable files.
Enjoy Reading This Article?
Here are some more articles you might like to read next: