Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

Wait 5 sec.

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech TensionsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataU.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalogUnlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare PatientsWordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server TakeoverHackers Impersonate IT Support to Breach Leading Financial CompaniesMeta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico CaseResearchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root AccessAI Deepfakes Used to Impersonate OnlyFans Creators in New ScamExposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance RecordsRansom Cartel Leader Sentenced to 16 Years in U.S.Meta AI Model Hacked a Company During Testing, Marking Third AI Lab IncidentU.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalogSnowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of RecordsAI Deception Emerges in Cyber Tests as Agents Target Real People and SystemsBrown Health Medical Group-MA Data Breach Exposes Information of 311,000 IndividualsU.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalogOVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootSMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control AccessSharePoint Flaws Used to Hack Switzerland’s Federal IT AgencyINC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day ExploitCVE-2026-58048: cPanel Bug Enables Full Database Administrator AccessU.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations RegisterAI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeekRiver Bank obtained assurances from the attackers that the stolen data in the June attack was deletedPNLD Confirms Data Breach Affecting UK Police and Justice StaffAlleged Żabka Breach Exposes Jira Data, Source Code, and API KeysRuby on Rails Patches Critical Active Storage Vulnerability Affecting Image ProcessingCareCloud Breach Exposes Medical and Financial Data of 345,000CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota AttacksInternational Press – NewsletterCybercrimeCareCloud begins to notify hundreds of thousands after hackers stole medical records  Żabka alleged data leak: 541k Jira tickets, 89 repos  ExfilSquad Targets Misconfigured Microsoft Power Pages Portals  Cyberattack hits Liechtenstein’s register of people behind companies and foundations  Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions   Major hedge funds targeted in wave of attempted cyberattacksBelarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison  Scammers target OnlyFans users with deepfakesUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments  MalwareFake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums   DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs  Russian AI Slopsquatting Publishes 700+ Malicious NPM PackagesWallet-depleting macOS malware wants your crypto     HackingChinese-Speaking Threat Actor Harnesses AI Models for Autonomous CyberattacksRapid Response: Critical N-able N-central Vulnerability and Active Exploitation Swiss federal IT office hit by cyberattack  OVSwrap: another Linux local root vulnerability Incident Report: unsanctioned agent behaviour during cyber testing  Meta says its AI model hacked into another company during testing  Natjack A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES  XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)  Black Hat USA 2026: The ‘Breaking’ News: The OpenAI–Hugging Face Incident  Hackers Stalked Me by Hijacking a Smartwatch for Kids  Security update available for Metabase – Please upgrade now CSS:the bomb inside your inbox  Intelligence and Information Warfare  DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator ClusterChina launches mysterious probe into security of Palo Alto Networks’ productsThe Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict   Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian touristsCybersecurityEU in talks with OpenAI, Anthropic after rogue AI agent hacks  Commission publishes new guidance to support timely Cyber Resilience Act implementation  Western government leaders call for a focus on infrastructure resilience, not AI hypeBrazil Health Surveillance Database Exposed 79GB of Sensitive Records     Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anywayENDLESSDOORS Is Phoning Home. Pick Up  Meta fined $567m in largest child safety ruling against social media giant Hackers targeted US private equity, other firms including Blackstone, CME, data shows  Military device manufacturer discloses cyber incident to SEC Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)