This daily cybersecurity summary highlights critical updates and new threats impacting organizations. A significant update on the LiteLLM supply chain attack reveals the use of the 'SANDCLOCK Stealer' malware, which exfiltrated 153GB of secrets from over 2,400 corporate domains. The attack chain involved compromising a vulnerability scanner's CI/CD pipeline to steal publishing tokens for LiteLLM, leading to malicious versions being distributed. Another update details APT exploitation of a critical VMware vCenter RCE flaw (CVE-2026-59310), with attackers establishing persistence via cron jobs and reverse SSH tunnels. Defenders should monitor for suspicious cron job modifications and SSH command patterns.
New threats include a critical RCE vulnerability (CVE-2026-65640) in WordPress affecting author-level users, patched in version 7.0.4. This flaw allows code execution through specially crafted image uploads when the Imagick PHP extension and Ghostscript are used. Intel and AMD have released patches for over 80 vulnerabilities in their August updates, addressing privilege escalation and denial-of-service flaws. Cisco Talos has uncovered 'JWR,' a sophisticated phishing-as-a-service framework enabling live, operator-driven attacks that can steal credentials, 2FA codes, and sensitive documents. Phantom Stealer and Umbral Stealer are new information-stealing malware families targeting Windows systems, employing techniques like steganography (PNG files) and targeting browser credentials, cryptocurrency wallets, and session data. CISA has warned of a persistent XSS vulnerability (CVE-2026-34491) in Johnson Controls Metasys ICS, potentially leading to session hijacking. Fortinet has patched a critical authentication bypass flaw (CVE-2026-26035) in FortiWeb WAF. Finally, over 700 fake Chrome VPN extensions have been found funneling user traffic through a single proxy, posing risks of man-in-the-middle attacks and credential theft. Organizations are urged to review and apply relevant patches and audit their systems and extensions.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.