View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Latvia's CSDD Confirms Breach Affecting 1.2 Million People

💥 BREACHES & INCIDENTS

  • South Korean startup platform breach exposed encryption key via API
    A South Korean government-backed startup platform exposed data for about 5,000 applicants.
    • Modu-ui Changup supports a nationwide startup audition program overseen by South Korea’s Ministry of SMEs and Startups.
    • Exposed data included email addresses, evaluation comments, and startup idea summaries.
    • The platform’s API returned an encryption key alongside encrypted data.
    • External parties collected the API data through web crawling, including AI-based crawling.
    • Authorities identified 39 South Korean IP addresses that accessed the exposed information.
      📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer

🕵️ RESEARCH & DEEP DIVES

  • Chameleon SEO Poisoning Delivers Cloaked Banking Phishing Pages
    Attackers are poisoning Google and Bing results to steal banking credentials.

    • Major financial institutions and their customers are targeted.
    • Lookalike banking portals capture passwords and hijack active sessions.
    • Attackers use SEO poisoning to rank fraudulent pages for banking searches.
    • Cloaking serves malicious content only to visitors arriving from Google or Bing.
    • Fortra reported a 40% increase in Chameleon attacks in Q2 2026; .ph.com and .gr.com domains were cited.
      📄 Source: fortra.com · 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News
  • 768 Exposed AWS Keys Still Grant Full Corporate Admin Access
    Truffle Security found 768 publicly exposed AWS keys still provide full corporate account control.

    • AWS customers, companies, and cloud-hosted applications are affected.
    • Researchers found 817 company-linked exposed keys, including 526 root keys and 242 AdministratorAccess IAM keys.
    • The keys appeared in Git history, Hugging Face datasets, Docker images, package registries, and CI/CD logs.
    • About 88% of 10,616 re-verified credentials still authenticated on August 10, 2026; the median key age was 1,831 days.
      📄 Source: trufflesecurity.com · 📎 Coverage: bleepingcomputer.com · 👁 via Cyber Security News, cryptika.com (discovered)
  • Latvia’s CSDD Confirms Breach Affecting 1.2 Million People
    Latvia’s CSDD confirmed a breach affecting payment records of 1.2 million people.

    • Latvia’s Road Traffic Safety Directorate and its customers were affected.
    • Payment records of more than 1.2 million people and 200,000 organizations were exposed.
    • The breach affected roughly two-thirds of Latvia’s population.
      📎 Coverage: research.checkpoint.com · 👁 via Check Point Research
  • Attackers Impersonated ReliaQuest Staff to Steal SSO and MFA Access
    Attackers used vishing to obtain one ReliaQuest employee’s SSO session.

    • ReliaQuest employees were targeted in the August 22, 2026, social-engineering attack.
    • Attackers captured one employee’s password, MFA approval, and a view-only identity-dashboard session.
    • The attackers posed as named ReliaQuest security staff during targeted phone calls.
    • They used a lookalike ReliaQuest domain hosting a counterfeit SSO portal behind a CDN.
      📄 Source: reliaquest.com · 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News, cryptika.com (discovered)
  • PavinLoader Used in ClickFix and Fake-Download Malware Campaigns
    PavinLoader is being used in campaigns delivering Amatera Stealer.

    • Users are targeted through ClickFix, fake-software and RenPy campaigns.
    • PavinLoader delivers Amatera Stealer and other malware.
      📎 Coverage: securityboulevard.com · 👁 via securityboulevard.com (discovered)
  • wordlistloader-synkloader-malware-campaign (6) — <https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html|The Hacker News>

🔓 CVEs & KEV

  • CVE-2026-66648 — CVSS 9.8 — WordPress Jawn theme through 1.4.2 - Privilege Escalation vulnerabilityUnauthentic...

  • CVE-2026-32558 — CVSS 9.8 — WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugi...

  • CVE-2026-78365 — CVSS 9.3 — IDOR and missing authorization in Prospero Flow CRM supplier API allows cross...

  • CVE-2026-32551 — CVSS 9.3 — WordPress Woo Essential plugin through 4.3.0 - SQL Injection vulnerabilityUnauthen...

  • CVE-2026-21756 — CVSS 7.2 — HCL Hive is affected by a broken access control vulnerabilityHCL Hive is affe...

📋 ADVISORIES

  • 📄 Source for Kimsuky Uses AI-Generated Chrome Extension to Steal Gmail Datablog.polyswarm.io

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check