Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

Wait 5 sec.

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VotePhilippine Nuclear and Naval Targets Hit by Suspected Chinese OperatorLove Electric Breach: 877,000 Driver Records Offered for $600Trump Targets Foreign Technology in New U.S. Power Grid Security OrderU.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalogRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic OrganizationsPaperCut Zero-Day Under Active Attack: Emergency Patch ReleasedU.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogCyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three AirportsDark Caracal Deploys New Go Malware With Ethereum-Based C2 FallbackAustralian Police Charge Two Over TeamPCP Credential TheftMeta to Pay Up to $18B Over Teen Social Media UseCISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers DoOpenAI banned Russian ChatGPT accounts backing covert influence operationCISA Red Team Fully Compromised Two Critical Infrastructure OrgsFBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical InfrastructureU.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog88 ID Verification Breaches Show the Cost of Collecting Identity DataWhatsApp Adds Stronger Security as Passkeys Hit 1 BillionOperation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global ScamsNorway ’s Digital Government Infrastructure Hit by a new DDoS AttackWhen the Algorithm Fires You: Uber Faces €825M FineTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableU.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalogFake Minecraft Sites Are Still Spreading WeedHack After C2 TakedownCybercriminals Turn GTA VI Leaks Into Malware BaitSlovakia Warns of Cyber Risks in Road Speed CamerasTikTok Settles U.S. Child Privacy Case for $400 MillioniAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password ResetUK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water AttacksZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionInternational Press – NewsletterCybercrimeiAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets     Fake GTA VI ISO circulates on the internet a few days after leak, internet sleuths claim 113GB download is padded malware        Taiwan charges 9 over illegal AI server exports to China, including Nvidia and Super Micro staff  Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly58 arrests in global effort to dismantle West African organized crime groupsExposing AnonyMousKIT: AI-Powered PhaaS Supply Chain       RTM Locker interview: a ransomware actor on the RaaS market Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate  Love Electric driver data for sale: NI, licence numbers Ransomware group says it stole Berlin data, offers it for auction  Malware FTP Banners: The New Dead Drop Resolver Delivering Novel RATsThe State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution     19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads  SLEEPWALKER: A Passive Backdoor With Its Own Command Language  HackingOne slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin  A Tale of Two SOCs: Insights From Two Red Team Assessments  Three UK airports hit by cyber-attack with data of 8.7m customers accessed   New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root AccessPaperCut Releases Emergency Patch for Exploited Zero-DayPhilippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities   The Hugging Face incident and the road aheadPower Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration      Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in TestsUniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range  PaperCut Actively Exploited: A Pre-Auth RCE Chain  Intelligence and Information Warfare  Iranian hackers shut down UK power plant  Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor    Digdir stabilizes solutions after cyberattack  Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical InfrastructureThe infrastructure quartermaster: inside a China-nexus state enablement model     Disrupting a new covert influence campaign from Russia Tortoiseshell: New Toolset and Operational Infrastructure ExposedTreasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-DayDark Caracal Reloaded: New Malware, Same Hunting Grounds  Cambodia-focused cluster uses multistage infection chain with localized luresBlueDelta Targets Defense and Diplomacy with HOOKEDGECybersecurityWarning about the risks of road meters  One billion people are now protected with passkeys on WhatsApp, plus more account security featuresAn ID Check Breach Timeline: 2011–2026 Internet Exposure Reduction Guidance Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction  DECLARING A NATIONAL EMERGENCY TO SECURE THE UNITED STATES BULK-POWER SYSTEM  Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)