CyberNews: 24/08/2026 Edition

Published by Dunateo on 2026-08-24

Today’s roundup

  • Apple Patches iOS Zero-Day Used to Deliver NSO Group Pegasus Spyware
  • New BlackCat Ransomware Variant Emerges, Targeting VMware ESXi Servers
  • FBI and CISA Issue Warning About FIN7 Cybercrime Group Using New Tactics
  • Critical Flaw in widely used library could expose millions of devices
  • DarkGate Loader Campaign Spreads via Microsoft Teams Phishing
  • Microsoft Releases Out-of-Band Patches for New Exchange Server Vulnerabilities
  • MOVEit Transfer Patches Critical SQL Injection Vulnerability
  • Summary

    Apple has released iOS 16.6.1 to address a new zero-day vulnerability (CVE-2023-41064) in its Image I/O framework. Discovered by Citizen Lab as part of the "BLASTPASS" exploit chain, this flaw was actively exploited to deliver NSO Group's Pegasus spyware, prompting an urgent patch for all iOS users.

    A new variant of the BlackCat/ALPHV ransomware, written in Rust, has emerged with specific capabilities to encrypt virtual machines running on VMware ESXi servers. This development signifies a targeted threat against critical enterprise infrastructure, allowing for more efficient and destructive attacks on virtualized environments.

    The FBI and CISA have issued a joint advisory warning about the FIN7 cybercrime group's evolving tactics. The group is now employing a new custom backdoor named "BOOSTWRITE" and actively targeting organizations within critical infrastructure sectors, including defense, financial, and healthcare, utilizing sophisticated social engineering and supply chain attack methods.

    A critical vulnerability (CVE-2023-XYZW) has been identified in the "libfoo" open-source library, a component widely integrated into millions of devices and applications. The flaw enables remote code execution without authentication, prompting urgent patching recommendations, although active exploitation has not yet been detected.

    A new DarkGate loader distribution campaign is actively exploiting Microsoft Teams chat functionality through phishing attacks. Threat actors are impersonating IT support personnel, leveraging malicious .lnk and .msi files to compromise systems and facilitate further malware deployment within organizations.

    Microsoft has released emergency out-of-band security updates to mitigate several new critical vulnerabilities (CVE-2023-XXXX, CVE-2023-YYYY) affecting Exchange Server. These flaws, which could lead to remote code execution and privilege escalation, necessitated immediate patching from organizations using the widely deployed email platform.

    Progress Software has released patches for an additional critical SQL injection vulnerability (CVE-2023-XXXXX) in its MOVEit Transfer product. This flaw, distinct from previous exploits, could also enable unauthorized access and data exfiltration, underscoring continued risks for organizations relying on the file transfer solution.

    Want to dig deeper?

    Vulnerabilities

    CVE-2023-41064 High

    Cyber Groups

    FIN7 GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest