CLASSIFIED

CYBER SECURITY • AUGUST 2026

The Monitoring Report

Devops• Linux • Observability

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Læs artiklen →

DAGENS CVE-OVERBLIK – FRA VULNPULS

ProduktCVE'erKritiskHandling
adobe:coldfusionCVE-2026-48276
CVE-2026-48277
+3 flere
1Patch nu (7 dage)
sonicwall:sma6210CVE-2026-15409
1Patch nu (7 dage)
sonicwall:sma6210_firmwareCVE-2026-15409
1Patch nu (7 dage)
sonicwall:sma7210CVE-2026-15409
1Patch nu (7 dage)
sonicwall:sma7210_firmwareCVE-2026-15409
1Patch nu (7 dage)
sonicwall:sma8200vCVE-2026-15409
1Patch nu (7 dage)
adobe:campaignCVE-2026-48286
030 dage
linux:linux_kernelCVE-2026-13782
CVE-2026-48286
030 dage
microsoft:windowsCVE-2026-13782
CVE-2026-48286
030 dage
langflow:langflowCVE-2026-10134
030 dage
apple:macosCVE-2026-13782
030 dage
google:chromeCVE-2026-13782
030 dage
Unknown / see vendorCVE-2026-56413
030 dage

Seneste nyt

The Hacker News

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude

August 5 , 2026
The Hacker News

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes

August 5 , 2026
The Hacker News

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'

August 5 , 2026
The Hacker News

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by

August 5 , 2026
The Hacker News

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim

August 5 , 2026
The Hacker News

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,

August 5 , 2026
The Hacker News

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its

August 5 , 2026
The Hacker News

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896

August 5 , 2026
The Hacker News

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of

August 5 , 2026
The Hacker News

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for

August 5 , 2026