CyberNews: 03/08/2026 Edition

Published by Dunateo on 2026-08-03

Today’s roundup

  • N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
  • CareCloud Breach Exposes Medical and Financial Data of 345,000
  • Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
  • Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
  • PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
  • Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
  • HollowFrame Loader Uses Fake Python DLL to Evade Defender
  • Google Chrome may soon block New Tab hijacker extensions by default
  • Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
  • Summary

    N-able has confirmed that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management (RMM) platform. This allowed attackers to gain remote administrative access to N-central servers and subsequently reach customer systems managed through these servers. The initial patch released on August 2 (build 2026.3.1.7) proved incomplete, necessitating further action.

    Healthcare technology company CareCloud disclosed a data breach affecting approximately 345,000 individuals. Attackers accessed one of CareCloud's AWS environments between March 10 and March 16, 2026, and claimed to have exfiltrated medical and financial data. Compromised information may include names, home addresses, Social Security numbers, government IDs, bank account details, payment card numbers, and health information. Notifications to affected individuals are ongoing following California's data breach rules.

    An unknown Chinese threat actor is targeting Apple iOS devices using a publicly leaked version of the DarkSword exploit kit. Censys observed the actor operating over 100 web properties, many being fake Amazon Web Services (AWS) sign-in pages, which also hosted the exploit toolkit to deploy GHOSTBLADE on iOS.

    Three high-severity security flaws have been discovered in Hugging Face's Diffusers library. These vulnerabilities could allow specially crafted model repositories to execute arbitrary code on machines loading them, posing a significant risk to the artificial intelligence (AI) supply chain by bypassing the trust_remote_code safeguard.

    The Police National Legal Database (PNLD) in the UK has confirmed a data compromise that exposed police, government, and customer contact information, which was subsequently published on the dark web. The breach, identified on July 26, included names, organizations, and work email addresses of police officers, staff, criminal justice professionals, government partners, and customers.

    Thermo Fisher Scientific has patched a flaw (CVE-2026-17583) in its Applied Biosystems human identification software. This vulnerability could permit nearly undetectable alterations to .fsa and .hid DNA data files if laboratory controls are bypassed before analysis software loads them. The patch was released on July 31.

    A new HollowFrame loader has been observed to evade Microsoft Defender by hiding Go code within a fake Python DLL. This technique involved pre-staging Defender exclusions to facilitate the stealthy deployment and operation of the malware.

    Google is developing a new security feature for Chrome that will default block policy-installed extensions from hijacking the New Tab page or altering the default search engine. This aims to counter common browser hijacker tactics and enhance user security.

    Korea's largest telecommunications company, KT, has been fined $38 million (USD) for a year-long data breach linked to the compromise of femtocell devices. The fine follows an incident where a security lapse exposed user data.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-18577 Critical

    IP Address Details

    22.3.1.7 0/91