CyberNews: 13/08/2026 Edition
Today’s roundup
Summary
China-linked hackers reportedly launched the first fully autonomous, AI-driven hacking operation against a government target, likely Taiwan. Multiple AI agents mapped systems, found vulnerabilities, and adapted tactics, compromising government accounts, stealing personnel records, and targeting critical infrastructure.
Critical vulnerabilities in a key browser extension supporting Belgium's national electronic ID (eID) system could allow Remote Code Execution (RCE). This threatens citizen accounts and highlights systemic security issues with browser extensions in national authentication frameworks.
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento e-commerce platforms is under active exploitation, enabling attackers to hijack customer accounts. Businesses using these platforms face a significant threat.
A critical SharePoint authentication bypass (CVE-2026-55040, CVSS 9.1) is actively exploited following a public PoC release. Attackers can forge JWT tokens to impersonate any SharePoint user or administrator, potentially gaining access to sensitive data and Microsoft 365 infrastructure.
A new APT group, "Jewelbug," has been identified conducting both state-sponsored cyber espionage and financially motivated cryptocurrency theft from a single web panel, indicating a dual-purpose operational strategy.
The Colombian Justice Ministry experienced a ransomware attack just days before a presidential transition. This incident underscores the continued targeting of critical government infrastructure in Latin America.
The "City-Forum" data theft campaign is ongoing, using custom tools to steal information exposed to anonymous users via Salesforce Experience Cloud and ServiceNow customer portals. This affects various sectors by exfiltrating sensitive data.
A new Android NFC relay malware, WindRelay, is collaborating with the SpyNote remote administration tool (RAT) to steal live credit card data. This enables attackers to facilitate fraudulent loans and conduct real-time financial theft.
Over 737 fake VPN and proxy extensions on the Chrome Web Store, mainly targeting Russian-speaking users, have been identified. These extensions route user traffic through a proxy infrastructure, enabling browser data interception.
Hundreds of allegations reveal U.S. Customs and Border Protection (CBP) workers misused internal government databases to spy on romantic interests and track colleagues. This highlights serious insider threats and privacy violations within federal agencies.
Want to dig deeper?
Vulnerabilities
| CVE-2026-55040 | High |
| CVE-2026-71362 | Critical |