Information Security News – 08/24/26

Share This Post

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

Article Link: https://www.securityweek.com/threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia/

  • Researchers at Hunt.io uncovered a mass-hacking campaign, dubbed Operation CameraSwarm, that compromised over 14,530 Dahua IP cameras in just 35 days between June 17 and July 22, after gaining access to the threat actor’s own infrastructure.
  • The attacker chained three known Dahua vulnerabilities, including two authentication bypasses that trick cameras into returning a full administrator session without valid credentials, then planted a hidden backdoor account on nearly 1,900 devices. That backdoor is stored separately from the administrator password and survives both password changes and factory resets.
  • Initial scanning covered Russian, Mexican, and Vietnamese IP ranges before narrowing focus specifically to Russian and CIS telecom networks, and some cameras behind firewalls were reached by abusing Dahua’s own cloud relay service using only their serial numbers.
  • Investigators found the campaign’s infrastructure had been built roughly a year in advance and assess with moderate confidence that the toolkit was designed to be handed off to a third party, though the operator’s ultimate motive remains unconfirmed. Organizations running Dahua devices should patch against known CVEs, disable unnecessary cloud relay access, and audit for unauthorized RPC-created accounts that could persist through a factory reset.
  • Additional information: https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised

What does this mean for me?

  • Internet-connected devices such as cameras, smart devices, and other “plug-and-play” technology can become targets if they are not properly secured and updated. If you use smart devices at work or home, keep them updated, change default passwords, and disable features you do not need.

CISA warns of hackers exploiting critical MLflow vulnerability

Article Link: https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/

  • CISA warned federal agencies that hackers are actively exploiting a critical security flaw in MLflow, a widely used open-source tool that companies use to build and manage AI applications, with over 30 million downloads a month.
  • The flaw (CVE-2026-64849) allows an unauthenticated attacker to trick a vulnerable MLflow server into fetching internal data on its behalf, including a cloud provider’s stored security credentials.
  • Attackers began scanning for vulnerable systems within hours of the flaw becoming public, and researchers have confirmed active theft of cloud credentials from unpatched servers exposed to the internet.
  • A patch is available in MLflow version 3.15.0, released three weeks ago. CISA has given federal agencies two weeks to remediate; other organizations running MLflow should patch immediately and check logs for signs of prior compromise.
  • Additional information: Additional Information: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-64849

What does this mean for me?

  • As organizations adopt more AI tools, those systems become attractive targets for attackers. This is a reminder that new technologies carry security risks and should only be used through approved, managed company platforms.

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Article Link: https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html

  • Researchers at UMass Amherst demonstrated an attack, dubbed “Zombie Card,” that lets an expired Visa contactless card make real in-store purchases by rewriting the expiration date the payment terminal reads over NFC, without breaking the card’s underlying cryptography.
  • The attack requires physical possession of (or sustained proximity to) the expired card, plus a relay device positioned between the card and the terminal. It also depends on the account remaining open under the same card number, which is standard when a bank issues a replacement card.
  • The flaw exists because Visa’s payment chip doesn’t cryptographically bind the expiration date the terminal checks to the data verified by the bank, so the two can be made to disagree without invalidating the transaction.
  • According to the research this is only a Visa-specific weakness. Researchers disclosed the findings to Visa and affected banks starting in May 2025; as of publication, no public advisory or fix has been issued. Cardholders are advised to physically destroy expired cards rather than discard them intact, and businesses should treat this as a reminder that card-present fraud risk isn’t limited to stolen numbers.
  • Additional information: https://www.usenix.org/system/files/usenixsecurity26-anwar.pdf

What does this mean for me?

  • Expired payment cards may still have value to criminals. Instead of throwing old cards away intact, cut them up or destroy them before disposal, and regularly review account statements for unauthorized transactions.

Manic: Blend between Banking Malware & Spyware

Article Link: https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware

  • ThreatFabric’s Mobile Threat Intelligence team identified a new Android malware family called Manic, active since February, that blends banking fraud with spyware, monitoring 169 apps across banking, government ID, payments, crypto, messaging, and 2FA categories, with Ukraine as the primary target.
  • Manic has two distinct PIN-theft techniques: one captures taps directly off a banking app’s real keypad while letting the app function normally, and a separate “autoEnterPin” capability works at the Android lock screen to automatically enter a stored credential and unlock the device itself.
  • Its standout feature is a store-and-forward relay: when an infected phone can’t reach the attacker’s server, it encrypts stolen data and relays it through nearby infected devices over Wi-Fi Direct, or Bluetooth hopping up to four devices by default. This means cutting a phone’s internet access does not stop data theft if another infected device is nearby.
  • Users should avoid installing apps from outside official app stores, deny Accessibility permissions to apps that don’t clearly need them, and run regular Play Protect scans to catch known threats.

What does this mean for me?

  • Only download mobile apps from trusted app stores and be cautious when an app requests extensive permissions. If an app asks for access that seems unnecessary for its purpose, do not approve it and consult your IT or security team if the device is used for work.

UT San Antonio Delays Fall Semester After Cyberattack; State Confirms Data Breach

Article Link: https://therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio

  • UT San Antonio detected unauthorized activity against its technology systems over the weekend of August 15-16 and took services offline, including phones and email, just days before the fall semester was set to begin for its 40,000+ students.
  • The disruption forced UTSA to delay the start of classes by five days, from Wednesday, August 19 to Monday, August 24, while the university worked to restore systems and reset passwords campus-wide.
  • UTSA initially said its investigation found no evidence of data being accessed or stolen, but the Texas Cyber Command later confirmed the incident did involve a data breach, working with the university on forensic analysis to determine what was affected. No hacking group has claimed responsibility.
  • Ransomware attacks on higher education institutions rose more than 8% in Q1 2026 compared to the same period last year, and this incident follows the Canvas/ShinyHunters breach that disrupted final exams at schools nationwide this past spring. Experts note that universities’ heavy dependence on centralized tech systems means a single disruption can halt basic operations, not just risk data loss.
  • Additional information: https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/08/20/cyber-threat-delays-start-classes-ut-san

What does this mean for me?

  • Cyberattacks can disrupt daily operations, not just expose data. Having alternate ways to communicate, access important information, and continue critical work during technology outages can help reduce the impact of unexpected disruptions.

Copilot tricked into telling researchers how to hack itself

Article Link: https://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857

  • Varonis Threat Labs discovered a vulnerability, dubbed “CoSnitch,” by repeatedly asking Microsoft Copilot why a blocked attack technique wouldn’t work. Copilot’s own explanations revealed a previously undocumented URL parameter, autorun=1, that could bypass Microsoft’s existing protections and auto-execute a hidden prompt with no user interaction.
  • Combined with Copilot’s chat-input parameter, the flaw let researchers build a single malicious URL that, when clicked, silently ran an attacker’s instructions inside the victim’s own logged-in Copilot session, with no visible warning on screen.
  • Depending on the injected prompt, an attacker could exfiltrate a victim’s connected Gmail, Google Drive, or Calendar data, poison Copilot’s stored memory of past conversations, perform reconnaissance on connected apps and files, or manipulate what Copilot shows the user in future sessions.
  • Varonis reported the flaw to Microsoft in December 2025, and Microsoft issued a fix and assigned a CVE this week, saying customers are already protected and don’t need to take action.
  • Researchers say the underlying issue, AI models failing to separate untrusted data from legitimate instructions, is a systemic risk that extends beyond this one Copilot product into corporate AI deployments generally, since attackers don’t need to break authentication if they can trick the AI into misusing its own authorized access.
  • Additional information: https://www.varonis.com/blog/cosnitch

What does this mean for me?

  • AI tools can make mistakes or be manipulated in ways that expose information or perform unintended actions. Treat AI-generated results with the same level of caution and verification you would apply to information received from any unfamiliar source.

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Article Link: https://www.securityweek.com/contractors-cmmc-confidence-rises-as-ability-to-prove-it-falls-behind/

  • Confidence does not equal compliance readiness. While 96% of defense contractors surveyed by Kiteworks believed their SPRS (Supplier Performance Risk System) self-attestation would withstand scrutiny, only 29% could support that confidence with both a current SPRS submission and a FedRAMP-authorized platform, highlighting a significant gap between perceived and demonstrable compliance.
  • The CMMC Phase 2 suspension did not eliminate risk. Even though third-party assessments were paused, DFARS (Defense Federal Acquisition Regulation Supplement) attestation requirements remain in force. Not surprisingly, 84% of contractors expressed concern about False Claims Act exposure from inaccurate compliance claims, and 92% had involved legal or compliance teams in reviews.
  • Many organizations still misunderstand ongoing obligations. Nearly half of respondents were unaware that Phase 1 self-assessment requirements continued despite the pause in Phase 2 assessments. The findings suggest security leaders should focus on governance, documentation, and regulatory awareness as much as technical controls.
  • Evidence-based security is becoming more important than self-attestation. Both surveys found strong support for independent verification, with 93% of contractors viewing third-party authorization as important for vendor selection. The central message for CISOs and compliance teams is that maintaining auditable evidence, validated controls, and continuous compliance processes will remain critical regardless of future CMMC rule changes.
  • Additional information: https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-cmmc-2-0-dib-readiness.pdf

What does this mean for me?

  • Security is not just about following rules; it is also about being able to demonstrate that those rules are being followed. Completing required training, documenting processes, and following approved procedures helps your organization prove compliance when asked.

Attackers impersonate popular AI brands to spread malware

Article Link: https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/

  • AI brand impersonation is now a significant malware delivery vector. Sophos found that 35 of 38 AI-related incidents involved attackers targeting AI products, brands, or ecosystems, with fake AI software installers accounting for the vast majority of cases. Claude-themed lures were especially prevalent.
  • “InstallFix” campaigns are evolving social engineering tactics. Instead of fake CAPTCHAs, attackers present convincing installation instructions for AI tools and trick users into running malicious commands or installers. Defenders should focus on detecting traditional malware delivery techniques, command execution, and payload behaviors rather than looking for AI-specific indicators.
  • Malicious browser extensions remain a high-risk blind spot. Sophos observed fake AI assistant extensions, including a fraudulent Perplexity extension distributed through the Chrome Web Store, that stole browsing data, hijacked searches, and communicated with attacker-controlled infrastructure. Security teams should strengthen extension governance and monitor browser-based telemetry.
  • AI is helping attackers develop tooling, but humans remain in control. In the clearest example identified, Sophos linked a Rust-based remote access trojan (RAT) to a development workflow involving a Claude coding agent. However, researchers found no evidence that AI was autonomously conducting attacks; instead, threat actors are using AI to accelerate malware development and coding tasks.

What does this mean for me?

  • Cybercriminals are increasingly using popular AI brands as bait to trick users into downloading malware or installing malicious browser extensions. Only download software, plugins, and extensions from trusted sources approved by your organization, and be skeptical of unsolicited “AI tool” recommendations or installation instructions.



Reach out to our incident response team for help

More To Explore

Information Security News – 08/24/26

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia Article Link: https://www.securityweek.com/threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia/ What does this mean for me? CISA warns of hackers exploiting critical

Information Security News – (8/17/26)

Zoom Patches Zero-Click Code Execution Vulnerability Article Link: https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/ What does this mean for me? New Microsoft Defender ‘ShieldBreak’ Zero-Day Grants SYSTEM Privileges Article Link:

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.