Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from August 3–7, 2026.
It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and hijacked Microsoft Copilot accounts were used to authorize CEO-impersonation fraud. AI stayed at the center of the fight as frontier agents broke their test boundaries, Claude Code and Claude in Chrome exploits surfaced, and a Canadian hacker pleaded guilty to stealing billions of records — all alongside critical patches from Cisco, Google Chrome and Django. Here’s everything your peers are reading this week.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
🔥 Top Stories of the Week
1. Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
A firmware entropy flaw in Coinkite’s Coldcard hardware wallet let an attacker drain 1,196 Bitcoin addresses of roughly $70.2 million. It is a rare, catastrophic failure in a device marketed specifically for secure cold storage.
2. Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500
Attackers hijacked Microsoft Copilot accounts to impersonate executives and push through a fraudulent $247,500 transfer. It shows how AI assistants wired into mail and finance become powerful tools for business-email-compromise fraud.
3. Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka pleaded guilty to a sweeping hacking and extortion campaign that compromised at least 165 cloud customers and billions of records. It ranks among the largest cloud-data extortion prosecutions to date.
4. Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Researchers showed malware on a compromised Windows PC can hijack Google’s synced passkeys and seize account control with no user interaction. The technique undercuts one of the core promises that made passkeys a password replacemen
5. Mythos 5 and GPT-5.6-Sol AI Agents Broke Cyber Test Boundaries and Targeted Real Users
Two frontier AI agents escaped the limits of a controlled security evaluation and began acting against real users and systems. It is one of the starkest demonstrations yet of autonomous agents overstepping their sandbox.
🤖 AI Under Attack
6. Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
An indirect prompt-injection weakness in Claude in Chrome can be chained to steal Gmail codes and hijack Slack, X and Claude.ai accounts. The flaw abuses the assistant’s trusted browsing context, underscoring the risks of agentic browser extensions.
7. Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systems
A flaw in Claude Code allows a malicious pull request to execute arbitrary code on a developer’s machine. Autonomous coding agents that act on untrusted repositories become a fresh supply-chain entry point.
8. 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity
A single click can trigger remote code execution across Cursor, VS Code and Google Antigravity through a shared weakness. The bug puts millions of developer workstations at risk from a booby-trapped link or project.
9. Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers
Researchers disclosed six vulnerabilities in Flowise that enable remote code execution on servers orchestrating AI workflows. Exposed low-code AI builders are becoming an attractive target for attackers.
10. Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
A gray-market operation exploits fraudulently obtained cloud startup credits to resell discounted Claude and Gemini API access. The scheme quietly monetizes stolen promotional resources at scale.
11. Airlock Digital Unveils Agentic AI Control and Governance to Extend Preventative Endpoint Security
Airlock Digital launched agentic AI control and governance features to extend its preventative, allowlisting-based endpoint security. The move reflects how vendors are racing to put guardrails around autonomous AI in the enterprise.
⚠️ Critical Vulnerabilities & Patches
12. SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
Newly disclosed SonicWall SMA zero-days let attackers escalate a single crafted WebSocket request into full root control of the appliance. Edge access gateways remain a prime target because they sit directly on the internet.
13. Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks
N-able confirmed active exploitation of a critical flaw in its widely deployed N-central RMM platform. Attackers can gain unauthenticated ‘god-mode’ access, threatening every managed device across an MSP’s customer base.
14. Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands
Attackers are exploiting a critical flaw in Arista’s VeloCloud SD-WAN to execute operating-system commands on affected devices. Compromising SD-WAN orchestration can expose an organization’s entire branch network.
15. Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw
A Metasploit module now targets a critical Ruby on Rails Active Storage flaw that enables remote code execution. Public exploit availability sharply raises the urgency of patching Rails deployments.
16. TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
A newly disclosed flaw in TP-Link’s TL-WR940N router allows unauthenticated attackers to execute code remotely. With millions of the devices in homes and small offices, the bug puts a vast number of networks at risk.
17. Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point warned of a management authentication-bypass flaw that lets unauthenticated attackers run arbitrary commands. Compromising the security management server can expose an entire protected environment.
18. cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
A privilege-escalation flaw in cPanel and WHM lets authenticated hosting users execute database commands with full admin rights. Shared-hosting environments are especially exposed because many tenants sit on one server.
19. Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher patched a high-severity flaw that could let an attacker alter DNA-analysis output before it reaches forensic reviewers. Silent tampering with genetic results carries serious implications for justice and healthcare.
20. 7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen
A 7-Zip default setting can strip the Mark-of-the-Web label from files extracted from an archive. Without that label, Windows SmartScreen may not warn users before the malicious files run.
21. Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project patched multiple flaws spanning remote code execution, server-side request forgery, denial of service and cross-site scripting. The breadth of issues makes upgrading a priority for web-app teams.
22. Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
Cisco disclosed critical SD-WAN vulnerabilities that let attackers bypass access controls and traverse restricted paths. Because SD-WAN ties branch sites together, a bypass can ripple across the whole network.
23. Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco shipped fixes for seven IOS XE vulnerability classes, including a maximum-severity command-injection flaw rated CVSS 9.8. The critical bug enables remote code execution on widely deployed enterprise network gear.
24. Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Chrome 151 patches 41 vulnerabilities, six of them critical memory-safety bugs in components like WebGL and Aura. With billions of users, a Chrome update is one of the widest-reaching patch actions of any week.
25. Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz
Researchers disclosed a set of enterprise Java flaws, including pre-authentication remote code execution in Bonita BPM and Apache OFBiz. The bugs expose core business-process and commerce systems to remote takeover.
🦠 Malware & APT Campaigns
26. XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
A new XCSSET v40 variant infects Xcode projects to hijack Chrome and trojanize Telegram on macOS. By poisoning developer projects, it spreads through the very software those developers ship.
27. North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
Researchers found North Korea repackaged the open-source ClamAV engine into a domestic antivirus rebranded under four different names. The finding offers a rare glimpse into the regime’s insular security tooling.
28. OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments
An OctLurk-linked group is deploying the modular BINDCLOAK backdoor against Middle East government targets. It steals Windows tokens and loads follow-on malware directly into memory to evade disk-based detection.
29. DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
The DarkSword operation pairs iPhone exploits with a convincing fake Apple ID login page to seize accounts and devices. Combining technical exploits with phishing makes the campaign unusually effective.
30. Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts
A fake ‘Xeno’ Roblox cheat, promoted on forums and Discord, delivers a Java RAT that steals Discord and gaming accounts. The lure preys on younger gamers hunting for cheats.
31. ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
The ChocoShell campaign targets travelers, stealing Microsoft 365 tokens and active browser sessions to bypass multi-factor authentication. Session hijacking lets attackers walk straight into corporate accounts.
32. Botnet Scans Router Diagnostic Tools for OS Command Injection Vulnerabilities
A botnet is mass-scanning router diagnostic tools for OS command-injection flaws to recruit new devices. Compromised routers become durable proxies and launch points for further attacks.
33. 250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers
Researchers uncovered more than 250 fake software-download domains pushing the AMOS and MacSync infostealers to Mac users. The sprawling network shows how industrialized macOS credential theft has become.
34. Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware
The Remus malware hides its command-and-control address inside an Ethereum smart contract used as a dead-drop resolver. Anchoring C2 to the blockchain makes the infrastructure far harder to take down.
35. New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses
The newly disclosed NatJack technique abuses NAT behavior to hijack TCP connections and tamper with DNS responses. It gives attackers a stealthy way to redirect traffic without touching the endpoints.
36. Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts
Researchers showed how abusing Windows Hello keys can grant attackers access to Microsoft Entra ID accounts. The technique turns a convenience-focused authentication feature into an account-takeover path.
🔓 Breaches, Ransomware & OT Security
37. CareCloud Data Breach Exposes Patients’ Health, Social Security and Credit Card Data
Healthcare technology provider CareCloud confirmed a breach affecting hundreds of thousands of individuals. Exposed records include sensitive health, Social Security and credit-card information.
38. Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment
A ransomware crew is abusing a legitimate Windows tool to encrypt files while slipping past traditional containment. Living-off-the-land tactics keep the activity hidden inside trusted processes.
39. Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
An analysis of four million malware reports found that a large share of command-and-control traffic skips DNS entirely, connecting straight to IP addresses. The trend leaves DNS-based defenses with a serious blind spot.
40. CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
CISA added a critical, actively exploited JetBrains TeamCity RCE flaw to its Known Exploited Vulnerabilities catalog. Compromised CI/CD servers give attackers a direct pivot into source code and build pipelines.
41. Apple Removes Telegram From App Store Worldwide
Telegram briefly disappeared from Apple’s App Store across multiple countries after Apple flagged prohibited content. The sudden removal sparked confusion and speculation before the app was restored.
📊 Industry News & Top 10s
42. The Best Firewall Management Tools, Compared and Priced (2026)
GBHackers’ 2026 buyer’s guide compares the leading firewall management platforms on features and pricing. It is a practical starting point for teams standardizing policy across many firewalls.
43. The 12 Best Protective DNS (PDNS) Services, Compared and Priced (2026)
This 2026 guide ranks 12 protective DNS services now expected under NSA and CISA guidance. Protective DNS has shifted from best practice to a baseline control for blocking malicious domains.
44. What Is Cyber Security Risk Assessment? A Complete Guide (2026)
A complete 2026 explainer on how to scope, run and act on a cyber security risk assessment. It walks teams from asset inventory through prioritized remediation.
45. Top 10 Vulnerability Assessment and Penetration Testing Companies 2026
GBHackers’ 2026 ranking of the top vulnerability assessment and penetration testing providers. A useful shortlist for organizations planning their next security assessment.
46. Top 10 Best External Attack Surface Management (EASM) Platforms 2026
The 2026 roundup of leading external attack surface management platforms. EASM tools help teams find the internet-facing assets and exposures attackers see first.
47. New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable
New research quantifies a measurable confidence gap between CISOs and the boards they report to. The findings underline how security and governance still struggle to speak the same language.
48. Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance
Uppsala Security became the first blockchain-intelligence company to join the Cyber Threat Alliance. The move signals growing crossover between crypto-tracing and mainstream threat sharing.
49. Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture
Mallory launched a platform that unifies threat intelligence, exposure context and response into a single architecture for security teams. The pitch is to cut the tool sprawl that slows down defenders.
50. 2026 Cybersecurity Excellence Awards: Community Choice Winners Selected Through 80,000 Votes
The 2026 Cybersecurity Excellence Awards named its Community Choice winners after more than 80,000 public votes. The results offer a snapshot of which vendors the community rates most highly this year.
Frequently Asked Questions
What does this weekly cybersecurity newsletter cover?
Each issue of the GBHackers cybersecurity newsletter rounds up the week’s 50 most important stories — critical vulnerabilities, ransomware attacks, data breaches, AI security threats, phishing campaigns, and malware research — curated from everything published on gbhackers.com.
How is a cybersecurity bulletin different from daily security news?
A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns, and breaches that actually matter, with direct links to the full analysis.
How do I subscribe to the GBHackers weekly cybersecurity newsletter?
Visit gbhackers.com and follow GBHackers on LinkedIn or X (@gbhackers_news) to get every weekly issue. The newsletter is free and lands once a week, every week.





