๐จ ACTIVE EXPLOITATION
- TA488 Exploited Outlook Web Access 0-Day XSS Flaw to Compromise Mailboxes
CVE-2026-42897
TA488 exploited a zero-day Outlook Web Access XSS flaw to run malicious code in victim browsers.- Targets: Government, telecom, finance, hospitality, aerospace sectors in US and Europe
- Vulnerability: CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access on-premises Exchange
- Attack: Malicious emails without attachments or links trigger JavaScript payload when opened in webmail
- Payload: OWAReaper implant runs in browser, steals mailbox data, alters folder permissions for persistence
- Command & Control: Uses GitHub commits, email commands, HTTPS image traffic, and DNS tunneling for data exfiltration
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
- UK Department for Education hacked, 607K records of officials leaked in 2026 breach
The UK Department for Education suffered a data breach exposing 607,000 records.- Applies to UK Department for Education staff and officials, including head teachers and senior leaders
- Exposed data includes names, job titles, email addresses, and phone numbers
- Attack exploited the DfE help desk and Turing Scheme portals via social engineering
- Incident occurred July 26, 2026, disclosed July 29, 2026, linked to hacker group ExfilSquad
- Part of wider UK government cyberattacks; data risks targeted phishing and impersonation
๐ Coverage: paperweight.email ยท ๐ via r/cybersecurity
๐ต๏ธ RESEARCH & DEEP DIVES
-
OS Command Injection Vulnerability Found in OCPP Agent Before Version 1.9.1
CVE-2026-44098
An unauthenticated remote attacker can perform OS command injection in OCPP Agent.- Applies to OCPP Agent versions before 1.9.1
- Vulnerability allows OS command injection via the charge_box_id parameter
- Attack requires remote access to OCPP backend with firewall bypass
- Execution occurs as limited user charx-oa, potentially disrupting charging operations
- CVE ID: CVE-2026-44098, CVSS 8.6/8.8, CWE-78 OS Command Injection
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps
Attackers use fake N26 support calls to install Copybara RAT on Android devices.- Targets Android users of N26 banking app via voice phishing calls impersonating support
- Victims are tricked into visiting fake login pages and installing malicious APKs outside app stores
- Malware Copybara abuses Android Accessibility permissions to remotely control banking apps
- Copybara can capture screens, record audio/video, log keys, and intercept messages and calls
- Attackers communicate via MQTT channels hosted on hard-coded command-and-control servers
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Claude Opus 5 AI Agent Accidentally Wipes Entire Production Database in Minutes
Claude Opus 5 AI agent accidentally wiped a production database during a personal project.- Applies to developers using Anthropic's Claude Opus 5 AI in Ultracode mode
- Vulnerability: AI executed a Prisma migration command targeting a live Supabase production database
- Attack vector: AI connected directly with broad access to production DB and ran schema-altering commands autonomously
- Impact: All 22 tables wiped, including key datasets like tools, users, reviews, and comparison entries
- Cause: Misconfigured --shadow-database-url pointed to production, triggering full schema reset from outdated migrations
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
-
Google Chrome 151 Fixes 370 Vulnerabilities Including 80 Critical and High-Severity Bugs
Google released Chrome 151 to patch 370 vulnerabilities including critical use-after-free bugs.- Applies to Google Chrome versions 151.0.7922.71/.72 on Windows, macOS, and Linux
- Fixes 370 vulnerabilities including 7 critical bugs and 71 high-severity defects
- Critical bugs include use-after-free issues in Compositing, Views, Skia, Ozone, and validation flaws in Dawn and ANGLE
- Over 30 vulnerabilities affect ANGLE, Chrome's WebGL graphics backend
- Google discovered 349 issues and credited external researchers for 21, paying $58,500 in bounties
๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Node.js July 2026 Update Fixes 11 Vulnerabilities Including HTTP/2 and Permission Bypass
Node.js released security updates fixing 11 vulnerabilities across active branches.- Applies to Node.js versions 22.x, 24.x, and 26.x (v22.23.2, v24.18.1, v26.5.1)
- Fixes 11 vulnerabilities including HTTP/2 memory limit bypass and heap use-after-free
- Addresses permission model flaw allowing filesystem access outside allowlist
- Patches HTTPS mTLS identity reuse and hostname verification bypass issues
- Resolves crashes from oversized DNS responses, SQLite, Zlib, and HTTP request smuggling
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ CVEs & KEV
- Other: 19 CVEs (worst 9.8)