CyberNews: 13/08/2026 Edition

Published by Dunateo on 2026-08-13

Today’s roundup

  • China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
  • Belgium's eID Authentication Opens Citizen Accounts to RCE
  • Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
  • SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
  • 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
  • Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
  • "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
  • Android malware combo takes out loans and relays victims' credit cards
  • 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
  • CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
  • Summary

    China-linked hackers reportedly launched the first fully autonomous, AI-driven hacking operation against a government target, likely Taiwan. Multiple AI agents mapped systems, found vulnerabilities, and adapted tactics, compromising government accounts, stealing personnel records, and targeting critical infrastructure.

    Critical vulnerabilities in a key browser extension supporting Belgium's national electronic ID (eID) system could allow Remote Code Execution (RCE). This threatens citizen accounts and highlights systemic security issues with browser extensions in national authentication frameworks.

    A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento e-commerce platforms is under active exploitation, enabling attackers to hijack customer accounts. Businesses using these platforms face a significant threat.

    A critical SharePoint authentication bypass (CVE-2026-55040, CVSS 9.1) is actively exploited following a public PoC release. Attackers can forge JWT tokens to impersonate any SharePoint user or administrator, potentially gaining access to sensitive data and Microsoft 365 infrastructure.

    A new APT group, "Jewelbug," has been identified conducting both state-sponsored cyber espionage and financially motivated cryptocurrency theft from a single web panel, indicating a dual-purpose operational strategy.

    The Colombian Justice Ministry experienced a ransomware attack just days before a presidential transition. This incident underscores the continued targeting of critical government infrastructure in Latin America.

    The "City-Forum" data theft campaign is ongoing, using custom tools to steal information exposed to anonymous users via Salesforce Experience Cloud and ServiceNow customer portals. This affects various sectors by exfiltrating sensitive data.

    A new Android NFC relay malware, WindRelay, is collaborating with the SpyNote remote administration tool (RAT) to steal live credit card data. This enables attackers to facilitate fraudulent loans and conduct real-time financial theft.

    Over 737 fake VPN and proxy extensions on the Chrome Web Store, mainly targeting Russian-speaking users, have been identified. These extensions route user traffic through a proxy infrastructure, enabling browser data interception.

    Hundreds of allegations reveal U.S. Customs and Border Protection (CBP) workers misused internal government databases to spy on romantic interests and track colleagues. This highlights serious insider threats and privacy violations within federal agencies.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-55040 High
    CVE-2026-71362 Critical