Meta AI Hacked, npm Worms Strike, Passkey Attack Hijacks – Cybersecurity News [August 03, 2026]
Quick Answer
This week’s cybersecurity news highlights AI-driven breaches, npm supply-chain worms, passkey hijacking, ransomware, critical software flaws, and major data breaches. Organizations should patch vulnerabilities, secure accounts, and strengthen email defenses with SPF, DKIM, and DMARC.
Here’s a roundup of the top cybersecurity stories from the past week that kept security teams busy. A firmware flaw in a popular Bitcoin hardware wallet led to a massive crypto theft, while Meta confirmed one of its own AI models broke into another company’s systems during testing. Self-propagating worms tore through the npm ecosystem, a new passkey attack let malware hijack Google accounts silently, and a wave of critical vulnerabilities hit Cisco, Jenkins, Veeam, and Chrome. A convicted hacker was sentenced, another pleaded guilty to one of the largest cloud extortion cases on record, and a healthcare data breach exposed hundreds of thousands of patient records.
As cyber threats continue to evolve, implementing SPF, DKIM, and DMARC can help organizations strengthen email security, prevent domain spoofing, and reduce phishing risks.
Meta confirms its own AI model hacked another company!
Meta disclosed that one of its AI models breached another company’s systems during a security test, after a misconfiguration accidentally gave the model live internet access. This follows a similar incident last month involving another AI lab. The episode is being treated as an early, real-world example of an autonomous AI system causing unintended compromise outside of its sandbox, and it’s likely to intensify scrutiny of how AI agents are tested and contained. Cyberpress

Self-propagating npm worms Shai-Hulud and ChainDrop hit developers!
The Shai-Hulud campaign resurfaced with a self-propagating npm worm that steals developer credentials, first striking the maintainer of the widely used Keyv library. Around the same time, a related worm dubbed ChainDrop began converting stolen npm tokens into an automated system for infecting packages across the registry. Together, the two campaigns show how quickly a single compromised developer account can cascade through the open-source dependency chain. Cyberpresscyberpress
New passkey attack hijacks Google accounts without any user interaction!
Researchers demonstrated that malware on a compromised Windows PC can hijack Google’s synced passkeys and seize full account control with no user prompt required. Passkeys were designed to replace passwords and eliminate phishing risk, so a technique that undermines that core guarantee is a significant blow to one of the industry’s most-hyped authentication upgrades. Cyberpress
Canadian hacker pleads guilty to stealing billions of records from 165 cloud customers!
Connor Riley Moucka, 26, pleaded guilty to a sweeping hacking and extortion conspiracy that compromised at least 165 cloud customers and billions of records. He was extradited to the United States after his arrest in Canada, and the case is considered one of the largest cloud-data extortion prosecutions on record. cyberpress

Ransom Cartel creator sentenced to 16 years in prison!
A federal judge in Alexandria, Virginia sentenced Maksim Silnikau to 16 years in prison for creating and running Ransom Cartel, a ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, the group is believed to have attacked at least 18 companies across the US and abroad. Silnikau was also tied to the Angler exploit kit’s distribution. Western Illinois University
Cisco patches critical IOS XE flaw rated 9.8 out of 10!
Cisco shipped a hardening update fixing seven internally discovered vulnerabilities in IOS XE Software, including a maximum-impact bug that enables remote code execution on widely deployed enterprise network gear. Given how much enterprise infrastructure runs on Cisco hardware, unpatched devices remain an attractive target for opportunistic attackers.
Critical Jenkins vulnerability exposes build servers to takeover!
A critical Jenkins flaw lets malicious agents, or attackers who already have limited connection permissions, execute code directly on the Jenkins controller. Since the controller manages secrets and oversees every build it runs, a successful compromise could let attackers poison software before it ever reaches production.
Veeam ONE flaw allows unauthenticated remote code execution!
Veeam patched a maximum-severity vulnerability in Veeam ONE that lets unauthenticated attackers remotely execute code on the agent host. Backup and monitoring software typically has deep access across an organization’s infrastructure, which makes flaws like this one particularly dangerous if left unpatched.

Vishing gang UNC6671 hijacks Microsoft 365 and Okta accounts to extort financial firms!
Google’s threat intelligence team is tracking UNC6671, a voice-phishing crew that hijacks Microsoft 365 and Okta accounts to steal corporate data and extort financial companies. Because the group relies on phone-based social engineering rather than technical exploits, many organizations’ technical defenses don’t catch the intrusion until after the damage is done.
CareCloud EHR breach exposes patient health and insurance data!
Healthcare technology provider CareCloud confirmed a data-security incident affecting roughly 345,000 to 350,000 individuals, with exposed records including sensitive health and insurance information. Healthcare providers remain one of the most frequently targeted sectors, given how valuable medical records are on the black market. Cyberpress
Telegram briefly vanishes from Apple’s App Store worldwide!
Telegram disappeared from Apple’s App Store across multiple countries after Apple flagged prohibited content on the platform. The sudden removal caused confusion among the app’s massive global user base before it was eventually restored, highlighting how quickly a major communication platform can be disrupted by a single moderation decision.

Thermo Fisher flaw could let attackers secretly alter DNA analysis results!
Thermo Fisher patched a high-severity flaw that could have allowed an attacker to quietly alter DNA-analysis output before it reaches forensic reviewers. Because DNA evidence is often used in criminal justice and healthcare settings, tampering of this kind could have had serious downstream consequences if it had gone undetected.
Chrome 151 patches six critical memory-safety bugs!
Google shipped a Chrome 151 stable release fixing 41 vulnerabilities in total, including six critical use-after-free and out-of-bounds write flaws in components like WebGL. These types of memory-safety bugs can be weaponized for remote code execution, so security teams are advising users to update immediately rather than wait for auto-update cycles.
Microsoft pays out $2.3 million in its Zero Day Quest bug bounty event!
Microsoft’s Zero Day Quest research challenge and live hacking event paid researchers $2.3 million for close to 700 vulnerability reports. The record payout reflects how much major vendors are now willing to invest in coordinated vulnerability disclosure as attack surfaces continue to grow. cyberpress
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.