CyberNews: 11/08/2026 Edition
Today’s roundup
Summary
Cisco has issued a warning regarding two high-severity vulnerabilities affecting its Secure Endpoint Connector, specifically impacting the ClamAV scanning process. These flaws, which have public exploits available, could allow threat actors to trigger denial-of-service (DoS) attacks.
Researchers have uncovered a method to achieve a full SYSTEM takeover on fully updated Windows 11 machines by abusing Windows Plug and Play functionality. This involves tricking the system into fetching signed vendor software for an emulated USB device and executing privileged installation components.
A novel attack vector has been identified where malicious tool servers can manipulate AI coding assistants. By splitting harmful instructions into routine-looking fragments and placing them in channels the assistant already uses, attackers can exfiltrate sensitive data such as SSH keys, environment secrets, source code, and customer data.
U.S. and South Korean cybersecurity agencies have jointly warned about active Gunra ransomware attacks targeting critical infrastructure sectors globally, including healthcare, financial services, and government. The threat actors are exploiting vulnerabilities in Fortinet and Schneider Electric products to breach networks.
A supply chain compromise has impacted BdThemes, a WordPress plugin vendor. Threat actors modified a remote JSON feed to create unauthorized administrative accounts on websites using their premium web-design tools, prompting WordPress to temporarily disable plugin downloads.
Microsoft has disclosed that the financially motivated, China-linked threat actor Storm-1175 is now deploying a new ransomware strain named StormEncryptor. This marks a shift from their previous use of Medusa ransomware and is believed to be facilitated through an N-central flaw.
Attacks targeting water systems are expanding across a dozen U.S. states. These incidents leverage vulnerabilities in ill-secured, internet-exposed Programmable Logic Controllers (PLCs), with Iran suspected of involvement.
A maximum-severity SQL zero-day vulnerability in Metabase, an open-source business intelligence platform, is being actively exploited. The flaw, which currently lacks a CVE identifier, grants remote administrator access to the platform and could affect its downstream users.
Sophisticated iPhone exploit chains, known as Coruna and DarkSword, previously associated primarily with nation-state actors, are now spreading globally to organized cybercrime groups. This broadens the threat landscape for iOS users.
A detailed report from CERT Poland describes a 2025 cyberattack on a small Polish combined heat and power plant. Attackers leveraged a private Access Point Name (APN) via a compromised Fortinet device to pivot from IT to OT networks, disrupting steam turbines and water treatment systems.
Want to dig deeper?
Cyber Groups
| Play |