Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 26, 2026

CISA listed CVE-2026-60004 in its KEV catalog after confirming in-the-wild exploitation of Gitea's diffpatch endpoint, where an attacker with repository write access—trivially obtained via default open registration—plants a malicious Git hook to execute arbitrary shell commands as the Gitea OS user; the vulnerability spans all versions from 1.17 and is fixed in 1.27.1, and one documented hit showed a dropper that cleared LD_PRELOAD, killed competing high-CPU processes, and pulled an architecture-specific miner payload over HTTPS. SOCRadar separately detailed AnonyMousKIT, a credit-metered PhaaS platform active since early 2024 that deploys AI voice agents to call owners of stolen Apple devices and harvest their passcode, Apple ID, and live 2FA code to bypass Activation Lock; 200 recovered calls ran from August 2025 to May 2026 (179 to Brazilian numbers), and the researchers recommend moving high-value Apple IDs to hardware security keys to neutralize the real-time 2FA interception the platform targets.

Compiled by the Slugnet Editorial System. Published Aug 26, 2026, 8:34 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

    What happened

    CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, though the agency did not disclose whether this action resulted from the specific reported attack or other evidence of exploitation. The vulnerability allows attackers with repository write access to execute arbitrary shell commands via the diffpatch endpoint, a risk amplified by Gitea’s default open registration setting. A reported incident involved an unknown threat actor using this flaw to deploy a cryptocurrency-miner-like dropper on a compromised instance.

    Why it ranks #1

    CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, though the agency did not disclose whether this action resulted from the specific reported attack or other evidence of exploitation.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Federal agencies must patch the flaw by August 28, 2026, prioritizing updates based on a risk-based approach.

    Impact
    moderate
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    LACMA data breach last year exposed social security and medical data

    What happened

    LACMA disclosed that a network intrusion detected in July 2025 resulted in the exposure of customer and employee data, including government-issued identification numbers and medical records. LACMA confirmed the network compromise in August 2025, with the first investigation results available in late February 2026, and the museum has since notified law enforcement and sent personalized breach notifications to impacted individuals.

    Why it ranks #2

    LACMA confirmed a July 2025 network intrusion exposed customer and employee government-issued identification numbers and medical records, with personalized breach notifications sent to impacted individuals.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

    What happened

    SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents to call owners of stolen Apple devices and extract device passcodes, Apple ID credentials, and live two-factor authentication codes. SOCRadar's report documents that the AnonyMousKIT platform requested device passcodes, Apple ID credentials, and 2FA codes from victims between August 31, 2025, and May 30, 2026, but does not confirm that the service was active since early 2024, that the credentials were successfully used to bypass Activation Lock, or that criminals accessed iCloud backups or resold the hardware.

    Why it ranks #3

    SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents to call owners of stolen Apple devices and extract device passcodes, Apple ID credentials, and live two-factor authentication codes.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    Hackers abuse npm mirrors to host phishing redirect pages

    What happened

    Threat actors are abusing the npm registry and its mirrors, such as UNPKG, to host malicious HTML pages that impersonate Cloudflare CAPTCHAs. These pages execute obfuscated JavaScript to redirect users to attacker-controlled domains, leveraging the trusted status of the mirror infrastructure to bypass security controls.

    Why it ranks #4

    Threat actors are abusing the npm registry and its mirrors, such as UNPKG, to host malicious HTML pages that impersonate Cloudflare CAPTCHAs.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    What happened

    The U.S. Department of the Treasury sanctioned five individuals linked to the Mabna Institute, alleging they breached and exfiltrated data from U.S. critical infrastructure entities, including energy, defense, and healthcare organizations, since late 2023. The action, part of Operation Economic Outcast, also targets a broader network of Iranian cyber actors and financial enablers, with the Treasury citing the group's dual motivation of state-directed espionage and personal financial gain.

    Why it ranks #5

    The U.S. Department of the Treasury sanctioned five individuals linked to the Mabna Institute, alleging they breached and exfiltrated data from U.S. critical infrastructure entities, including energy, defense, and healthcare organizations, since late 2023.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Massive DDoS attack disrupts Norway’s government digital services

    What happened

    A large-scale DDoS attack disrupted Norway’s shared government digital infrastructure, affecting services such as ID-porten and eSignering. The Norwegian Digitalization Agency confirmed that many systems have stabilized but noted this is the third such incident targeting the agency in recent months.

    Why it ranks #6

    A large-scale DDoS attack disrupted Norway’s shared government digital infrastructure, affecting services such as ID-porten and eSignering, with the Norwegian Digitalization Agency confirming that many systems have stabilized but noting this is the third such incident targeting the agency in recent months.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    BleepingComputer

    From Fake Workers to Account Recovery: The Growing Identity Verification Risk

    What happened

    The U.S. Department of State and allied nations issued a joint alert warning that North Korean IT workers are impersonating foreign nationals to secure employment by falsifying identity documents. This tactic, which also involves social engineering to exploit service desk account recovery processes, was linked to the 2025 M&S ransomware breach.

    Why it ranks #7

    The U.S. State Department and allies issued a joint alert warning that North Korean IT workers are falsifying identity documents to secure employment and exploit service desk account recovery processes.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

    What happened

    INTERPOL announced that Operation Jackal IV, an eight-month investigation spanning 22 countries, resulted in 58 arrests and the identification of 263 suspects linked to West African organized crime groups. INTERPOL identified 196 individuals in a crime-as-a-service network believed to have provided support to West African organized crime groups, while a separate Romanian investment scam resulted in an estimated €143 million in stolen and laundered funds.

    Why it ranks #8

    INTERPOL announced that Operation Jackal IV, an eight-month investigation spanning 22 countries, resulted in 58 arrests and the identification of 263 suspects linked to West African organized crime groups.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    critical
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

    What happened

    Independent researcher Dominik Reichel documented SLEEPWALKER, a Windows backdoor that side-loads into the ESET Management Agent and remains dormant until a specific network packet triggers its execution. The implant uses a custom 23-instruction bytecode language to move data and execute code in memory across six transports, including TCP, UDP, and VMware's VMCI. Reichel published host indicators and a YARA rule for detection, noting that the sample's origin and deployment status remain unconfirmed.

    Why it ranks #9

    Independent researcher Dominik Reichel documented SLEEPWALKER, a Windows backdoor that side-loads into the ESET Management Agent and remains dormant until a specific network packet triggers its execution.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

    What happened

    SOCRadar identified AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents to contact owners of stolen Apple devices and extract passcodes and two-factor authentication codes. SOCRadar reports that AnonyMousKIT, active since early 2024, uses retrieved passcodes to disable Activation Lock and access iCloud backups, enabling the resale of stolen iPhones.

    Why it ranks #10

    SOCRadar identified AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that uses AI voice agents to contact owners of stolen Apple devices and extract passcodes and two-factor authentication codes to disable Activation Lock and access iCloud backups.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email