Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
International Press – Newsletter
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Unmasking EvilTokens: Getting to the root of device code phishing
Consumer Protection Tuesday: Taking Down Evil Tokens
ShinyHunters hackers say they breached FBI, stole data on bureau employees
How Romanian Crime Rings Are Draining U.S. Welfare Accounts
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts
Exploit.in: inside a Russian hacker forum, 2005 to 2008
Malware
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Malicious npm campaign targets developers integrating Twilio
Graphalgo campaign spreads to Terraform providers and Go Modules
Inside Corp MDM, the Android spyware targeting logistics companies
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Hacking
We got a cybersecurity expert to hack this BYD. It was too easy
UPDATE: Active Exploitation CVE-2026-32996 of Veeam Agent
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
MikroTrick: technical analysis, disclosure process, and the use of LLM agents
Top 10 attacks on Claude Code and what each one actually broke
Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Intelligence and Information Warfare
Water Cyberattack Campaign 2026
Exclusive: US military had close call after using AI for false intelligence report, sources say
Foreign hackers breach two more US water utilities, threaten safety of Colorado residents
Cybersecurity
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
ENISA Threat Landscape 2026 Breadcrumb Home Publications ENISA Threat Landscape 2026
How AI could make it harder for governments to use hacking tools
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
Altman, Amodei Call for Global Cooperation on AI to Boost Safety
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
