Threat Intelligence

The latest vulnerabilities, exploits, and threat actor activity — curated by the Lost Edges Security research team.

50 items · sorted by date

Severity: Critical High Medium Low
Informational
Breach

Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil's Health Surveillance Informa

breach policy
Security Affairs
High
Research

Ransomware Moves up the Org Chart - Managers Are Prime Targets

New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. ThreatLabz identified victims of a campaign a

research ransomware
Zscaler ThreatLabz
Informational
Research

Black Hat - NatJack exploits test NAT security assumptions

NatJack attack class exposes design flaw across decades of network infrastructure. At Black Hat USA 2026, researcher Malcolm Stagg, an independent researcher and Synack Red Team member, disclosed NatJack, an attack class that manipulates the NAT connection tracking table. An atta

research
CSO Online
Medium
Vulnerability

Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

Three WebKit mechanisms have been discovered to bypass Apple's iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo's proxy, Tor-on-iOS proxy setups, and so on. Private Relay is a VPN-like system for Safari on iOS which i

vulnerability vpn
Malwarebytes Labs
Informational
Malware

ENDLESSDOORS Is Phoning Home. Pick Up.

Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way. These routers are made by Zbtlink, a brand of Shenzhen Zhibotong Electronics, a Chinese manufacturer that builds routers and white-labels them for sale globally. The

malware linux
Vulncheck
High
Breach

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. 26-year-old Connor Riley Moucka, also known as Alexander Mou

breach malware cloud
Bleeping Computer
Informational
Breach

London cops handed victim's new address and number to her stalker, watchdog says

The UK's data protection regulator has criticized London's Metropolitan Police Service (MPS) after its officers handed a victim's stalker details about her new phone number and home address, among other failures. The Information Commissioner's Office (ICO) today issued the MPS wi

breach policy
The Register Security
Informational
Malware

Don't Revoke That Token Yet - Inside the keyv/cacheable npm Worm

In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first -- because revoking the stolen token is exactly what arms the payload. On August 4, 2026, an attacker took over the maintainer account behind the widely used keyv

malware cloud kubernetes github-actions
SANS Internet Storm Center
Critical
Malware

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all

supply-chain malware github-actions
Bleeping Computer
Informational
AI

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

'The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and then tried to make the

ai
Security Affairs
High
Breach

SplitVPN Data Breach Exposes 865k Users' Personal Records

A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique users. The incident, which occurred in July 2026, has raised fresh concerns about the reliability of "no-logs" promises made by pri

breach vpn
Cyber Security News
Low
Vulnerability

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. BleepingComputer spotted the protection in a chain of work-in-progress Chromium Gerrit changes. It has not shipped

vulnerability windows policy
Bleeping Computer
Medium
Vulnerability

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Digital asset research firm Galaxy Research says

vulnerability
Bleeping Computer
Medium
AI

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, op

ai
Palo Alto Unit42 Research
Informational
Policy

Headteacher had the most guessable username-password combo you could imagine

Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher's (aka principal's) laptop. At the bottom of the laptop there was a sticker with the woman's username and passw

policy
The Register Security
Informational
Research

The 73,000-server market reselling Western frontier AI into China

Western frontier AI is not sold in mainland China. It is used there every day. This report maps the infrastructure that makes that possible, and counts it for the first time: 73K internet-facing servers, tracked continuously by Infrawatch, reselling access to the models the Weste

research
Infrawatch
Medium
Vulnerability CVE-2026-12927

Schneider Electric IGSS

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a de

vulnerability iot energy
ICS-CERT Advisories
Critical
Vulnerability

CosmosEscape - Taking Over Every Database in Azure Cosmos DB

A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure's flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have

vulnerability cloud
Wiz Research
Medium
Vulnerability CVE-2026-68563

CVE-2026-68563 - Ansible-collection-redhat-leapp - ansible-collection-redhat-leapp - information disclosure of postgresql data via insecure backup permissions

CVE-2026-68563 describes an information disclosure vulnerability in `ansible-collection-redhat-leapp` related to insecure backup permissions for PostgreSQL data. A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and

vulnerability
CVE Feed
Medium
Vulnerability CVE-2026-5846

Watchfire Controller Software

Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of Watchfire Controller Software are affected: BC550 12.30, BC750 11.33|12.35, BC76

vulnerability
ICS-CERT Advisories
Medium
Vulnerability CVE-2026-18064

NASA Core Flight System (cFS) Health & Safety (HS) Application

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0

vulnerability
ICS-CERT Advisories
Informational
AI

Securing Agents Across Perplexity's Client Endpoints with Numbat

Numbat is Perplexity's open-source agent security suite for client endpoints. It detects, prevents, and investigates risky AI agent behavior on macOS, Linux, and Windows. Recent advances in agent autonomy give rise to security incidents that need not assume the existence of adver

windows linux ai
Perplexity Research
High
Breach

The Average Cost of a Data Breach Rises to $5 Million

The average cost of a data breach has risen to almost $5m, analysis of the consequences of cyber incidents which took place during the last year has revealed. The figure was published in the 2026 edition of the annual IBM Cost of a Data Breach Report, released on July 29, and bas

breach
Infosecurity Magazine
Informational
Vulnerability CVE-2026-15157

CVE-2026-15157 - undici vulnerable to CRLF Injection via blob-like body 'type' property

CVE-2026-15157 has been identified, where `undici` does not validate the `type` property of a duck-typed blob-like request body before using it as the `Content-Type` header on the HTTP/1.1 dispatcher. In `undici` before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to

vulnerability
CVE Feed
Medium
APT

Dear Diary Today I Found A Ghost In The Network

Guangdong Chanming. If you were looking for them, you'd be disappointed. No public website, no storefront, and certainly no obvious product line to speak of. On the surface, they are a ghost. But for those of us that know how to look for the cracks in the Great Firewall, the brea

apt
Intrusiontruth
Informational
Breach

What's your data worth on the dark web? (Lock and Code S07E15)

Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data's relationship with the entire global economy: "Data is the new oil." Pithy as the phrase sounds, it is undeniably true. Data steers decisions at businesses of every size.

breach energy
Malwarebytes Labs
Critical
Breach

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party s

breach supply-chain
Bleeping Computer
High
Malware

MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data

MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. BlackFog's research team recently dissected this new remote access trojan. According to the report published by Blackfog, "We recently cam

malware windows
Security Affairs
Critical
Malware

GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates

GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted pac

malware supply-chain
Cyber Security News
High
Policy

The evidence paradox behind bulletproof hosting

Earlier this month, the European Union sanctioned the Russian hosting provider Media Land and associated individuals and companies, following US criminal charges that the company knowingly operated a 'bulletproof hosting' service for ransomware groups including LockBit, BlackSuit

policy ransomware malware
Bindinghook
High
Vulnerability

'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

Confused Deputy" flaws persist in Google Cloud and Microsoft Azure, a category of vulnerabilities that allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls. Significant cracks in the managed identity trust chains of the

vulnerability cloud
Dark Reading
Informational
Vulnerability

Java Spring Boot "heapdump" scans

Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with

vulnerability
SANS Internet Storm Center
High
Malware

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026,

malware windows
The Hacker News
Medium
AI

Google wants to store a selfie video of your face

Google has started rolling out a new way to recover access to your account if you've lost your phone or forgotten your password: a "selfie video" verification option. In practice, it introduces new security and privacy questions, raises concerns about deepfakes, and creates anoth

ai
Malwarebytes Labs
Informational
APT

Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors

A widespread DNS poisoning campaign is targeting hotels, conference venues, and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the

apt credential-theft
Infosecurity Magazine
Medium
Breach

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people's names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no av

breach
The Register Security
Medium
Breach

Call of Duty Mobile scam uses fake free points to steal player accounts

Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game's premium currency. Following this, they're th

breach phishing
Malwarebytes Labs
Medium
Vulnerability CVE-2026-32194

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so

vulnerability linux
The Hacker News
Medium
APT

Ta458 Roundpress Exploits

The Russia-aligned threat actor TA458, the group behind Operation RoundPress, continues to focus on webmail targeting using half-click exploits as a way to steal highly sensitive email data. TA458 is likely aligned with Russia's General Staff Main Intelligence Directorate (GRU).

apt supply-chain
Proofpoint Threat Insight
High
Breach

Australian energy provider Origin says data breach exposes client data

Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). Origin Energy is Australia's largest energy retailer, providing electricity, natural gas, and broadband internet serv

breach energy
Bleeping Computer
High
Malware CVE-2025-66376

Ta488 Targets Zimbra Mailservers Half Click Exploits

Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. After successful exploitat

malware data-exfiltration iot
Proofpoint Threat Insight
Informational
Policy

China Rolls out the ROAs

Long a laggard in RPKI adoption, China has dramatically increased its ROA coverage from 4% to 81% since April, signaling a major commitment to securing the internet's routing system. This marks a significant milestone in global routing security, helping to protect networks from B

policy
Kentik
Informational
Vulnerability

Millions of cars could be tracked and unlocked by a hidden security flaw

A car alarm vendor's coding mistake has left millions of vehicles vulnerable to theft and location tracking. The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It's installed by dealers, primarily at Honda, Toyota, Ma

vulnerability
Malwarebytes Labs