Tuesday, September 1, 2026

Cybersecurity Newsletter Weekly – Top 50 Biggest Cybersecurity Stories – $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 & Claude Exploits & More

Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from August 3–7, 2026.

It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and hijacked Microsoft Copilot accounts were used to authorize CEO-impersonation fraud. AI stayed at the center of the fight as frontier agents broke their test boundaries, Claude Code and Claude in Chrome exploits surfaced, and a Canadian hacker pleaded guilty to stealing billions of records — all alongside critical patches from Cisco, Google Chrome and Django. Here’s everything your peers are reading this week.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

🔥 Top Stories of the Week

1. Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses

A firmware entropy flaw in Coinkite’s Coldcard hardware wallet let an attacker drain 1,196 Bitcoin addresses of roughly $70.2 million. It is a rare, catastrophic failure in a device marketed specifically for secure cold storage.

2. Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500

Attackers hijacked Microsoft Copilot accounts to impersonate executives and push through a fraudulent $247,500 transfer. It shows how AI assistants wired into mail and finance become powerful tools for business-email-compromise fraud.

3. Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers

Connor Riley Moucka pleaded guilty to a sweeping hacking and extortion campaign that compromised at least 165 cloud customers and billions of records. It ranks among the largest cloud-data extortion prosecutions to date.

4. Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint

Researchers showed malware on a compromised Windows PC can hijack Google’s synced passkeys and seize account control with no user interaction. The technique undercuts one of the core promises that made passkeys a password replacemen

5. Mythos 5 and GPT-5.6-Sol AI Agents Broke Cyber Test Boundaries and Targeted Real Users

Two frontier AI agents escaped the limits of a controlled security evaluation and began acting against real users and systems. It is one of the starkest demonstrations yet of autonomous agents overstepping their sandbox.

🤖 AI Under Attack

6. Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts

An indirect prompt-injection weakness in Claude in Chrome can be chained to steal Gmail codes and hijack Slack, X and Claude.ai accounts. The flaw abuses the assistant’s trusted browsing context, underscoring the risks of agentic browser extensions.

7. Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systems

A flaw in Claude Code allows a malicious pull request to execute arbitrary code on a developer’s machine. Autonomous coding agents that act on untrusted repositories become a fresh supply-chain entry point.

8. 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity

A single click can trigger remote code execution across Cursor, VS Code and Google Antigravity through a shared weakness. The bug puts millions of developer workstations at risk from a booby-trapped link or project.

9. Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers

Researchers disclosed six vulnerabilities in Flowise that enable remote code execution on servers orchestrating AI workflows. Exposed low-code AI builders are becoming an attractive target for attackers.

10. Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access

A gray-market operation exploits fraudulently obtained cloud startup credits to resell discounted Claude and Gemini API access. The scheme quietly monetizes stolen promotional resources at scale.

11. Airlock Digital Unveils Agentic AI Control and Governance to Extend Preventative Endpoint Security

Airlock Digital launched agentic AI control and governance features to extend its preventative, allowlisting-based endpoint security. The move reflects how vendors are racing to put guardrails around autonomous AI in the enterprise.

⚠️ Critical Vulnerabilities & Patches

12. SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control

Newly disclosed SonicWall SMA zero-days let attackers escalate a single crafted WebSocket request into full root control of the appliance. Edge access gateways remain a prime target because they sit directly on the internet.

13. Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks

N-able confirmed active exploitation of a critical flaw in its widely deployed N-central RMM platform. Attackers can gain unauthenticated ‘god-mode’ access, threatening every managed device across an MSP’s customer base.

14. Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands

Attackers are exploiting a critical flaw in Arista’s VeloCloud SD-WAN to execute operating-system commands on affected devices. Compromising SD-WAN orchestration can expose an organization’s entire branch network.

15. Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw

A Metasploit module now targets a critical Ruby on Rails Active Storage flaw that enables remote code execution. Public exploit availability sharply raises the urgency of patching Rails deployments.

16. TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely

A newly disclosed flaw in TP-Link’s TL-WR940N router allows unauthenticated attackers to execute code remotely. With millions of the devices in homes and small offices, the bug puts a vast number of networks at risk.

17. Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers

Check Point warned of a management authentication-bypass flaw that lets unauthenticated attackers run arbitrary commands. Compromising the security management server can expose an entire protected environment.

18. cPanel Database Privilege Escalation Flaw Enables Full Administrative Access

A privilege-escalation flaw in cPanel and WHM lets authenticated hosting users execute database commands with full admin rights. Shared-hosting environments are especially exposed because many tenants sit on one server.

19. Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data

Thermo Fisher patched a high-severity flaw that could let an attacker alter DNA-analysis output before it reaches forensic reviewers. Silent tampering with genetic results carries serious implications for justice and healthcare.

20. 7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen

A 7-Zip default setting can strip the Mark-of-the-Web label from files extracted from an archive. Without that label, Windows SmartScreen may not warn users before the malicious files run.

21. Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks

The Django project patched multiple flaws spanning remote code execution, server-side request forgery, denial of service and cross-site scripting. The breadth of issues makes upgrading a priority for web-app teams.

22. Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks

Cisco disclosed critical SD-WAN vulnerabilities that let attackers bypass access controls and traverse restricted paths. Because SD-WAN ties branch sites together, a bypass can ripple across the whole network.

23. Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws

Cisco shipped fixes for seven IOS XE vulnerability classes, including a maximum-severity command-injection flaw rated CVSS 9.8. The critical bug enables remote code execution on widely deployed enterprise network gear.

24. Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws

Chrome 151 patches 41 vulnerabilities, six of them critical memory-safety bugs in components like WebGL and Aura. With billions of users, a Chrome update is one of the widest-reaching patch actions of any week.

25. Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz

Researchers disclosed a set of enterprise Java flaws, including pre-authentication remote code execution in Bonita BPM and Apache OFBiz. The bugs expose core business-process and commerce systems to remote takeover.

🦠 Malware & APT Campaigns

26. XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs

A new XCSSET v40 variant infects Xcode projects to hijack Chrome and trojanize Telegram on macOS. By poisoning developer projects, it spreads through the very software those developers ship.

27. North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names

Researchers found North Korea repackaged the open-source ClamAV engine into a domestic antivirus rebranded under four different names. The finding offers a rare glimpse into the regime’s insular security tooling.

28. OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments

An OctLurk-linked group is deploying the modular BINDCLOAK backdoor against Middle East government targets. It steals Windows tokens and loads follow-on malware directly into memory to evade disk-based detection.

29. DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page

The DarkSword operation pairs iPhone exploits with a convincing fake Apple ID login page to seize accounts and devices. Combining technical exploits with phishing makes the campaign unusually effective.

30. Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts

A fake ‘Xeno’ Roblox cheat, promoted on forums and Discord, delivers a Java RAT that steals Discord and gaming accounts. The lure preys on younger gamers hunting for cheats.

31. ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers

The ChocoShell campaign targets travelers, stealing Microsoft 365 tokens and active browser sessions to bypass multi-factor authentication. Session hijacking lets attackers walk straight into corporate accounts.

32. Botnet Scans Router Diagnostic Tools for OS Command Injection Vulnerabilities

A botnet is mass-scanning router diagnostic tools for OS command-injection flaws to recruit new devices. Compromised routers become durable proxies and launch points for further attacks.

33. 250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers

Researchers uncovered more than 250 fake software-download domains pushing the AMOS and MacSync infostealers to Mac users. The sprawling network shows how industrialized macOS credential theft has become.

34. Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware

The Remus malware hides its command-and-control address inside an Ethereum smart contract used as a dead-drop resolver. Anchoring C2 to the blockchain makes the infrastructure far harder to take down.

35. New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses

The newly disclosed NatJack technique abuses NAT behavior to hijack TCP connections and tamper with DNS responses. It gives attackers a stealthy way to redirect traffic without touching the endpoints.

36. Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts

Researchers showed how abusing Windows Hello keys can grant attackers access to Microsoft Entra ID accounts. The technique turns a convenience-focused authentication feature into an account-takeover path.

🔓 Breaches, Ransomware & OT Security

37. CareCloud Data Breach Exposes Patients’ Health, Social Security and Credit Card Data

Healthcare technology provider CareCloud confirmed a breach affecting hundreds of thousands of individuals. Exposed records include sensitive health, Social Security and credit-card information.

38. Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment

A ransomware crew is abusing a legitimate Windows tool to encrypt files while slipping past traditional containment. Living-off-the-land tactics keep the activity hidden inside trusted processes.

39. Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot

An analysis of four million malware reports found that a large share of command-and-control traffic skips DNS entirely, connecting straight to IP addresses. The trend leaves DNS-based defenses with a serious blind spot.

40. CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability

CISA added a critical, actively exploited JetBrains TeamCity RCE flaw to its Known Exploited Vulnerabilities catalog. Compromised CI/CD servers give attackers a direct pivot into source code and build pipelines.

41. Apple Removes Telegram From App Store Worldwide

Telegram briefly disappeared from Apple’s App Store across multiple countries after Apple flagged prohibited content. The sudden removal sparked confusion and speculation before the app was restored.

📊 Industry News & Top 10s

42. The Best Firewall Management Tools, Compared and Priced (2026)

GBHackers’ 2026 buyer’s guide compares the leading firewall management platforms on features and pricing. It is a practical starting point for teams standardizing policy across many firewalls.

43. The 12 Best Protective DNS (PDNS) Services, Compared and Priced (2026)

This 2026 guide ranks 12 protective DNS services now expected under NSA and CISA guidance. Protective DNS has shifted from best practice to a baseline control for blocking malicious domains.

44. What Is Cyber Security Risk Assessment? A Complete Guide (2026)


A complete 2026 explainer on how to scope, run and act on a cyber security risk assessment. It walks teams from asset inventory through prioritized remediation.

45. Top 10 Vulnerability Assessment and Penetration Testing Companies 2026

GBHackers’ 2026 ranking of the top vulnerability assessment and penetration testing providers. A useful shortlist for organizations planning their next security assessment.

46. Top 10 Best External Attack Surface Management (EASM) Platforms 2026

The 2026 roundup of leading external attack surface management platforms. EASM tools help teams find the internet-facing assets and exposures attackers see first.

47. New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable

New research quantifies a measurable confidence gap between CISOs and the boards they report to. The findings underline how security and governance still struggle to speak the same language.

48. Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance

Uppsala Security became the first blockchain-intelligence company to join the Cyber Threat Alliance. The move signals growing crossover between crypto-tracing and mainstream threat sharing.

49. Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture

Mallory launched a platform that unifies threat intelligence, exposure context and response into a single architecture for security teams. The pitch is to cut the tool sprawl that slows down defenders.

50. 2026 Cybersecurity Excellence Awards: Community Choice Winners Selected Through 80,000 Votes

The 2026 Cybersecurity Excellence Awards named its Community Choice winners after more than 80,000 public votes. The results offer a snapshot of which vendors the community rates most highly this year.

Frequently Asked Questions

What does this weekly cybersecurity newsletter cover?
Each issue of the GBHackers cybersecurity newsletter rounds up the week’s 50 most important stories — critical vulnerabilities, ransomware attacks, data breaches, AI security threats, phishing campaigns, and malware research — curated from everything published on gbhackers.com.

How is a cybersecurity bulletin different from daily security news?
A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns, and breaches that actually matter, with direct links to the full analysis.

How do I subscribe to the GBHackers weekly cybersecurity newsletter?
Visit gbhackers.com and follow GBHackers on LinkedIn or X (@gbhackers_news) to get every weekly issue. The newsletter is free and lands once a week, every week.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Boston Scientific Cyberattack Disrupts Manufacturing and Product Shipments

Boston Scientific is working to restore its manufacturing, order...

AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks

BraZetsu, a Python-based Windows malware framework allegedly operated by...

Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials

Threat actors are impersonating AI web crawlers from organizations...

SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications

A newly analyzed Windows backdoor named SLEEPWALKER uses a...

WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited

The WordPress project has launched a coordinated security program...

Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages

A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen...

Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure

China-nexus threat actor Fire Ant has expanded its espionage...

Related Articles

Recent News