DJBSEC's CyberNews 2026-08-19

Today’s daily news covers the following categories: Data Breach Vulnerability Ransomware Threat Intelligence


SafePal Flaw Exposes Data of Nearly 40,000 Hardware Wallet Customers

Data Breach

Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plugin exposed personal information belonging to approximately 39,798 customers. The exposed data included names, email addresses, phone numbers, shipping addresses, and purchase details, although SafePal says seed phrases, private keys, wallet passwords, payment information, and wallet balances were not compromised. The affected orders were placed between March 2025 and April 2026, and a threat actor has since advertised a dataset matching the reported customer count and order window on a cybercrime forum. SafePal fixed the flaw, reduced personal-data retention to 90 days, purged affected records from active servers, and took down more than 30 fraudulent websites and phishing links. Customers are being warned to watch for convincing phishing attempts, fake support communications, fraudulent firmware updates, and other scams that may reference their actual SafePal purchases.

Read More

Microsoft 365 Search Outage Impacts Outlook, SharePoint, and OneDrive

Vulnerability

Microsoft confirmed an incident that disrupted search functionality for some Microsoft 365 users across Outlook, SharePoint Online, and OneDrive. The company traced the issue to a recent deployment that introduced a resource-utilization inefficiency within portions of its infrastructure. Microsoft developed and deployed a fix designed to reduce the resource pressure and restore search capabilities for affected customers. The company did not disclose which regions were impacted, but classified the problem as an incident indicating noticeable user impact. The outage follows several other recent Microsoft service disruptions, including a major July Azure and Microsoft 365 outage and an eight-hour GitHub outage earlier this week.

Read More

LiteLLM Supply Chain Attack Exposes Credentials Across Thousands of Organizations

Data Breach

New analysis of the LiteLLM supply chain compromise shows technology, financial services, and healthcare organizations were among the sectors most heavily affected. Threat group TeamPCP allegedly compromised LiteLLM maintainer credentials and published malicious versions 1.82.7 and 1.82.8 containing the SANDCLOCK credential stealer, potentially exposing more than 2,500 organizations and hundreds of thousands of CI/CD environments. Researchers obtained a 150-gigabyte archive attributed to the attack containing victim information covering 898 GitHub owners and 2,038 repositories. Potentially exposed secrets included GitHub credentials, cloud infrastructure keys, SSH credentials, Kubernetes secrets, registry tokens, and API keys for AI providers. Organizations affected by the incident are being urged to rotate credentials, revoke access tokens and application keys, invalidate sessions, and investigate their development pipelines for signs of compromise.

Read More

Claude Code Used to Help Drive Real-World Ransomware Intrusions

Ransomware

Gambit Security documented a suspected affiliate of The Gentlemen ransomware operation using Claude Code to automate significant portions of attacks against at least eight organizations. The attacker reportedly used Claude to compromise VPN appliances, manipulate authentication configurations, steal LDAP service-account credentials, establish hidden VPN accounts, map internal networks, and identify valuable servers and backup infrastructure. In one environment, Claude cataloged production SQL databases, ranked them by business value, created database backups, compressed them, and staged the information for theft. The AI was not flawless, however, and accidentally pushed a full firewall configuration restore at an energy utility, knocking the appliance offline. Researchers say the campaign demonstrates how AI is moving beyond generating malicious code or phishing content and into interactive exploitation, credential theft, lateral movement, and data exfiltration.

Read More

VMware vCenter Flaw Exploited for Root Access and ESXi Ransomware

Vulnerability

Attackers are actively exploiting CVE-2026-59310, a critical VMware vCenter Syslog path-traversal vulnerability that can provide unauthenticated root-level command execution. Researchers identified 361 affected IP addresses across 47 countries, with widespread exploitation appearing within days of the vulnerability’s disclosure. Attackers used their access to establish persistent SSH connections, deploy web shells, create administrator accounts, and obtain credentials before moving into connected ESXi environments. In some cases, the attackers deployed a Babuk-derived ransomware encryptor that stopped virtual machines and encrypted VMFS virtual disks, potentially rendering entire virtual environments unusable. Organizations should patch vulnerable vCenter systems immediately while also hunting for persistence mechanisms, unauthorized accounts, malicious cron jobs, and other evidence that attackers may already have compromised the environment.

Read More

AI Can Find Zero-Days but Still Struggles to Write Secure Code

Threat Intelligence

Artificial intelligence models are rapidly improving at vulnerability discovery and exploit development, but research suggests they remain significantly less reliable at producing secure software or correctly fixing vulnerabilities. Veracode found that 44 percent of AI-generated code contained at least one known OWASP Top 10 vulnerability, while no tested model achieved better than a 68 percent security pass rate. Separate research found AI-generated code produced roughly twice as many security-risk violations as human-written code, while another assessment uncovered 434 validated security flaws across 28 AI-generated or AI-reworked applications. AI also struggled with remediation, with testing across more than 6,000 attempts finding that models successfully produced complete, behavior-preserving security patches only 26 percent of the time. The growing gap creates a significant challenge for enterprises as AI simultaneously accelerates software development, vulnerability discovery, and attackers’ ability to weaponize newly discovered flaws.

Read More

Critical Forminator WordPress Flaw Threatens More Than 600,000 Websites

Vulnerability

A critical vulnerability in the popular Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and potentially take complete control of vulnerable websites. Tracked as CVE-2026-15748 with a CVSS score of 9.8, the flaw affects Forminator Forms version 1.56.1 and earlier and potentially exposes more than 600,000 active installations. Attackers can forge upload configurations and bypass the plugin’s dangerous file-extension filtering, potentially allowing executable PHP payloads to pass validation. Under certain storage configurations, those uploaded files could execute from a web-accessible directory, leading to remote code execution, web shells, credential theft, database access, and malware installation. The vulnerability was fixed in Forminator Forms version 1.56.2, and administrators should update immediately while checking upload directories for suspicious executable files.

Read More




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • DJBSEC's CyberNews 2026-08-28
  • DJBSEC's CyberNews 2026-08-27
  • DJBSEC's CyberNews 2026-08-26
  • DJBSEC's CyberNews 2026-08-25
  • DJBSEC's CyberNews 2026-08-24