π¨ ACTIVE EXPLOITATION
- Infostealers hijack Claude sessions to drain usersβ account usage
Infostealers are hijacking Claude sessions and consuming usersβ account usage.- Claude users on Windows and a small number of Mac accounts are affected.
- Stolen active Claude sessions let attackers access accounts and consume usage.
- Infostealers capture authenticated browser sessions, login cookies, passwords and app credentials.
- Anthropic linked cases to Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer (AMOS).
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
π₯ BREACHES & INCIDENTS
- Rhysida claims 5.79TB data theft from Berlin government systems
Rhysida claims it stole 5.79 TB of data from Berlin government systems.- Berlin state government departments, including mobility, transport, environment and another Senate department, were affected.
- Rhysida claims it took 5.79 TB across about 1.44 million files, including personal data, contracts, personnel records, passwords and government documents.
- The group says the data includes 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs; the claims are unverified.
- Investigators said data was exfiltrated between August 7 and 12; two department networks were shut down on August 14 after the intrusion.
- Rhysida claimed responsibility on its dark-web leak site, demanded payment and threatened to auction the data for 30 bitcoin.
π Coverage: reuters.com Β· π via @metacurity@infosec.exchange
π CVEs & KEV
-
CVE-2026-82654 β CVSS 9.3 β SiYuan before v3.8.1 Stored XSS via block nameSiYuan before v3.8.1 fails to p...
-
CVE-2026-82653 β CVSS 9.3 β SiYuan before v3.8.1 Stored XSS via confirmDialogSiYuan before v3.8.1 contain...
-
CVE-2026-82645 β CVSS 9.2 β AVideo Unauthenticated Stream Credential Disclosure via Forgeable TokenAVideo...
-
CVE-2026-82657 β CVSS 8.7 β Admidio before 5.0.12 Authentication Bypass via RSS feedsAdmidio before 5.0.1...
-
CVE-2026-82655 β CVSS 8.7 β Admidio before 5.0.12 SQL Injection via relation_type_listAdmidio before 5.0....
-
CVE-2026-82644 β CVSS 8.7 β WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-AgentWWBN AVide...
-
CVE-2026-82648 β CVSS 7.1 β WWBN AVideo SSRF Filter Bypass via NAT64 Hex AddressWWBN AVideo contains a se...
-
CVE-2026-82649 β CVSS 7.0 β SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search PathSi...
-
CVE-2026-82652 β CVSS 6.9 β SiYuan before v3.8.1 Information Disclosure via Publish AccessSiYuan before v...
-
CVE-2026-82651 β CVSS 6.9 β SiYuan before v3.8.1 Missing Authorization via /history and /repo/diffSiYuan ...
-
CVE-2026-82643 β CVSS 6.9 β WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.phpWWBN A...
π ADVISORIES
- π Source for 19 Chrome and Edge Extensions Found Stealing Crypto and Browser Data β socket.dev