Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    August 6, 2026

    InfoSec News Nuggets – 08/06/2026

    August 6, 2026

    The OSINT Newsletter – Issue #117

    August 6, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets – 08/06/2026
    News

    InfoSec News Nuggets – 08/06/2026

    adminBy adminAugust 6, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

    CISA added CVE-2026-63077, a critical unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog after confirming active exploitation, giving federal agencies just three days to patch under Binding Operational Directive 26-04. The deserialization vulnerability, rated CVSS 9.8, lets an attacker with mere HTTP or HTTPS access to a TeamCity server bypass authentication entirely via the agent polling protocol and execute arbitrary OS commands with the privileges of the server process — no credentials or user interaction required. Because TeamCity sits at the center of many organizations’ build and release pipelines, a compromise can expose source code, signing material, deployment credentials, and stored secrets, creating serious downstream supply-chain risk; Censys identified roughly 4,500 internet-facing TeamCity instances shortly after disclosure, and administrators running on-premises versions should update to 2025.11.7 or 2026.1.3 immediately.


    Critical Paperclip Bugs Expose AI Agent Trust Failures

    Researchers at Oasis disclosed critical vulnerabilities in Paperclip, an open-source control plane used to orchestrate teams of AI agents, including a maximum-severity flaw (CVE-2026-41679, CVSS 10.0) that let an unauthenticated attacker self-register an account, approve their own CLI authorization request without a separate administrator check, and use the resulting board-level access to import a malicious AI agent configured to execute arbitrary commands on the host server. A second flaw allowed an attacker who convinced a user to visit a malicious webpage to achieve remote code execution on that user’s own machine while Paperclip ran locally in its default mode, and a third exposed sensitive agent configuration data and control-plane details through API routes missing standard access checks. Paperclip patched all three issues in version 2026.416.0, but Rapid7 has since published a working Metasploit module for the primary flaw, and organizations running Paperclip should upgrade immediately and treat any internet-exposed instance as a priority.


    From Open Lures to Cloaked Gates: How a macOS ClickFix Campaign Learned to Hide

    Microsoft Threat Intelligence detailed the evolution of a macOS-focused ClickFix campaign spanning more than 250 algorithmically named “download” domains that now fingerprint visitors before deciding whether to serve a malware lure, hiding the malicious page from crawlers, sandboxes, and non-Mac visitors while presenting qualifying targets with a convincing fake “Download for macOS” page complete with a forged verified-publisher badge. Victims who copy and run the obfuscated Terminal command are ultimately infected with MacSync or Atomic Stealer (AMOS), both established macOS infostealers designed to harvest credentials, browser data, cryptocurrency wallets, and sensitive files while bypassing macOS’s notarization and quarantine protections. Because the malicious page only reveals itself to filtered, qualified traffic, Microsoft recommends defenders hunt for the underlying fingerprinting infrastructure and shared staging domains rather than chasing the constantly rotating front-end URLs.


    Bank of America Impersonators Weaponize ScreenConnect, Then Make It Hard to Remove

    Huntress uncovered an active phishing campaign impersonating Bank of America that pushes Windows users toward a fake “Account Guard” download which actually installs the ScreenConnect remote access tool, disguised as a legitimate “Windows Security” service, with layered permission changes that block the victim from viewing or uninstalling it through normal tools like services.msc or Get-Service. Mac users hitting the same campaign are instead directed to a credential-harvesting page requesting banking login details along with full personal and financial information, including government ID and Social Security numbers. Huntress assesses the campaign as a broad, untargeted blast rather than a spear-phishing operation aimed at specific victims, having caught the initial email in one of its own honeytrap accounts, and has published full indicators of compromise to help defenders detect the unauthorized installations this campaign leaves behind.


    Critical Cisco SD-WAN Vulnerabilities Enable Access Control Bypass and Path Traversal

    Cisco disclosed several critical vulnerabilities in Catalyst SD-WAN Software carrying maximum CVSS scores of 9.9, including CVE-2026-20303 (improper input validation enabling path traversal) and CVE-2026-20304 (improper access control), affecting all deployment types regardless of configuration — on-premises, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud, and even government FedRAMP environments. Cisco says the flaws were found internally through security testing supported by frontier AI models, and while it has no evidence of active exploitation, no workarounds are available, meaning affected organizations must upgrade rather than apply a temporary mitigation. Given SD-WAN’s central role in enterprise network routing and the maximum-severity ratings involved, organizations running Cisco Catalyst SD-WAN on unsupported or outdated releases should prioritize migration to a fixed version, particularly anywhere administrative interfaces are reachable from shared networks.

    The post InfoSec News Nuggets – 08/06/2026 appeared first on AboutDFIR – The Definitive Compendium Project.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe OSINT Newsletter – Issue #117
    Next Article Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
    admin
    • Website

    Related Posts

    News

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    August 6, 2026
    News

    The OSINT Newsletter – Issue #117

    August 6, 2026
    News

    Cities Are Ditching Flock, Immediately Replacing It With Axon License Plate Readers

    August 6, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    August 6, 2026

    InfoSec News Nuggets – 08/06/2026

    August 6, 2026

    The OSINT Newsletter – Issue #117

    August 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.