Security Affairs
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109|Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION|Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools|Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions|Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data|U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog|Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients|WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover|Hackers Impersonate IT Support to Breach Leading Financial Companies|Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case|Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access|AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109|Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION|Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools|Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions|Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data|U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog|Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients|WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover|Hackers Impersonate IT Support to Breach Leading Financial Companies|Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case|Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access|AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild, […]

newsletter

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
Hackers Impersonate IT Support to Breach Leading Financial Companies
Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
Ransom Cartel Leader Sentenced to 16 Years in U.S.
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
PNLD Confirms Data Breach Affecting UK Police and Justice Staff
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
CareCloud Breach Exposes Medical and Financial Data of 345,000
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

International Press – Newsletter

Cybercrime

CareCloud begins to notify hundreds of thousands after hackers stole medical records  

Żabka alleged data leak: 541k Jira tickets, 89 repos  

ExfilSquad Targets Misconfigured Microsoft Power Pages Portals  

Cyberattack hits Liechtenstein’s register of people behind companies and foundations  

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions   

Major hedge funds targeted in wave of attempted cyberattacks

Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison  

Scammers target OnlyFans users with deepfakes

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments  

Malware

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums   

DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs  

Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

Wallet-depleting macOS malware wants your crypto     

Hacking

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation 

Swiss federal IT office hit by cyberattack  

OVSwrap: another Linux local root vulnerability 

Incident Report: unsanctioned agent behaviour during cyber testing  

Meta says its AI model hacked into another company during testing  

Natjack A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES  

XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)  

Black Hat USA 2026: The ‘Breaking’ News: The OpenAI–Hugging Face Incident  

Hackers Stalked Me by Hijacking a Smartwatch for Kids  

Security update available for Metabase – Please upgrade now 

CSS:the bomb inside your inbox  

Intelligence and Information Warfare  

DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster

China launches mysterious probe into security of Palo Alto Networks’ products

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict  

Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists

Cybersecurity

EU in talks with OpenAI, Anthropic after rogue AI agent hacks  

Commission publishes new guidance to support timely Cyber Resilience Act implementation  

Western government leaders call for a focus on infrastructure resilience, not AI hype

Brazil Health Surveillance Database Exposed 79GB of Sensitive Records     

Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway

ENDLESSDOORS Is Phoning Home. Pick Up  

Meta fined $567m in largest child safety ruling against social media giant 

Hackers targeted US private equity, other firms including Blackstone, CME, data shows  

Military device manufacturer discloses cyber incident to SEC 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)