Skip to main content
news

Entra ID Vulnerability, Zombie Card Attack, AI Exploit Threats – Cybersecurity News [August 17, 2026]

Brad Slavin
Brad Slavin General Manager

Quick Answer

This week’s cybersecurity roundup covers critical vulnerabilities, AI-powered attacks, ransomware, malware, data breaches, exposed AWS keys, and active zero-days. Key incidents include threats targeting Entra ID, industrial systems, VMware, GeoServer, SharePoint, GitLab, and security cameras.

cybersecurity news

It was a packed week in security. Microsoft raced to patch a maximum-severity flaw in its Entra ID identity service, university researchers showed how “dead” Visa cards can be revived for real purchases, and five U.S. federal agencies warned that hackers are now using AI to write attack scripts against industrial control systems. Apple also sent a fresh wave of spyware notifications to iPhone users in over 100 countries, a hardware wallet maker disclosed a breach touching nearly 40,000 customers, and researchers uncovered a sprawling campaign that hijacked more than 14,500 security cameras. Here’s the full rundown.

Microsoft rushes to patch a “perfect 10” flaw in Entra ID

Microsoft disclosed CVE-2026-69836, a maximum-severity (CVSS 10.0) remote code execution flaw in Entra ID, its cloud identity service formerly known as Azure Active Directory. The bug stemmed from the service accepting untrusted data and converting it back into executable code without proper checks the kind of flaw that can let an attacker run code over the network with no special access. Microsoft initially said the flaw had been exploited in the wild, then corrected that after being contacted by reporters, saying it was not actually exploited and that the issue was fully fixed on Microsoft’s end with no action required from customers. (Source: The Hacker News)

“Zombie Card” attack lets researchers revive expired Visa cards

Academic researchers at the University of Massachusetts Amherst demonstrated an attack called Zombie Card that can revive an expired Visa contactless card for real in-store purchases, without ever breaking the card’s underlying cryptography. The trick works by intercepting the tap between the card and the payment terminal and rewriting only the expiration date the terminal sees, exploiting the fact that Visa’s contactless protocol doesn’t tie that field to the same cryptographic signature the issuer checks.

In testing across five U.S. banks, the researchers successfully pushed through transactions ranging from $1 to $500 at real retail and grocery merchants. Mastercard, Amex, and Discover’s competing protocols weren’t vulnerable to the same trick. No CVE has been assigned, and Visa’s security team is reportedly still reproducing the findings. (Source: The Hacker News)

SMTP Email Server 6745

Feds warn hackers are using AI to write exploits against water and power plants

In a rare joint advisory, the NSA, CISA, FBI, Department of Energy, and EPA warned that threat actors are using AI coding assistants to generate exploitation scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) the industrial computers that run pumps, valves, and machinery at water treatment plants, power facilities, and factories. Attackers reportedly scan the internet with tools like Censys and ZoomEye to find exposed, poorly secured PLCs, then use AI to quickly build custom scripts disguised as legitimate monitoring software to gain read/write access. The agencies called it “not a theoretical risk” but an active, ongoing threat, with suspected ties to Iranian operators and activity already reported across multiple U.S. states. (Source: The Hacker News)

Strong SPF and DKIM authentication help prevent attackers from spoofing trusted domains and strengthen email security against phishing threats.

Hardware wallet maker SafePal discloses breach touching ~40,000 customers

Crypto hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of roughly 39,798 customers. Importantly, SafePal said wallet seed phrases, private keys, and financial information were not part of the exposure. The company traced part of the problem to a data-retention job that had silently stopped working since September 2025, letting old order records linger far longer than intended. A threat actor has since advertised a matching dataset on a cybercrime forum. This comes just days after rival hardware wallet maker Trezor disclosed a separate breach affecting nearly 14,000 customers through its shipping provider, ShipMonk. (Sources: The Hacker News and Privacy Guides)

SMTP Email 6742

Researchers uncover “Operation CameraSwarm,” a 14,500-camera hijacking campaign

Security firm Hunt.io detailed a campaign it calls Operation CameraSwarm, which compromised more than 14,530 Dahua security cameras between June and July 2026 using a mix of credential stuffing, two long-known authentication-bypass bugs (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer relay trick that reaches devices hidden behind NAT. The findings came from an exposed 407 MB working directory belonging to the operator, and confirmed compromises were concentrated in Ukraine and Russia. Both underlying flaws remain on CISA’s Known Exploited Vulnerabilities list to this day. (Source: The Hacker News)

Suspected state-linked hackers actively exploiting VMware vCenter flaw

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal flaw in Broadcom’s VMware vCenter server, according to incident response firm QUIRSO. Attackers began exploiting the bug just five days after Broadcom publicly disclosed it, and researchers have since tied 361 victim IP addresses across 47 countries mostly Germany, the U.S., Turkey, Iran, and France to the campaign, which uses an open-source SSH tool to maintain persistent remote access. VMware appliances have long been a favorite target of Chinese state-linked espionage groups. (Source: The Hacker News)

New “Manic” Android malware can exfiltrate data even from offline phones

Researchers at ThreatFabric detailed a new Android threat called Manic that blends banking malware with spyware, targeting 169 banking, crypto, government ID, and messaging apps mostly in Ukraine, Russia, and Europe. Its standout feature is a mesh-relay capability: if the infected phone has no internet connection, Manic can bounce stolen data through a nearby infected device over Wi-Fi Direct or Bluetooth until it reaches a device that can forward it to the attacker’s server meaning disconnecting a phone from the internet doesn’t necessarily stop the data theft. Google says no apps carrying the malware were found on the Play Store. (Source: The Hacker News)

Fake RubyGems and npm packages caught stealing crypto wallets and browser data

A campaign dubbed StubMaker used 16 typosquatted RubyGems packages and dozens of similarly fake npm packages with clumsy misspellings of popular library names to trick developers into installing a Windows infostealer. The malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data, cleverly faking a “clean build” during installation so nothing looks amiss. Researchers say it was one threat actor running parallel typosquatting campaigns across two package ecosystems that shared the same back-end infrastructure. (Source: The Hacker News)

Hosted Email Server 6743

More than 9,300 leaked AWS keys are still live and usable

Cloud security firm Truffle Security reported that more than 9,300 Amazon Web Services access keys exposed publicly between 2022 and 2026 are still valid today. Of those, 526 were full root keys and another 242 carried administrator-level access meaning whoever holds them could read, modify, or delete nearly anything in the affected AWS accounts. Hugging Face was the single largest source of exposed keys, and most of the leaked credentials were years old and had never been rotated, underscoring how “forgotten” secrets in code repositories keep creating risk long after the fact. (Source: BleepingComputer)

Qilin ransomware claims German auto parts maker Motorenmaier

The Qilin ransomware gang added German company Motorenmaier GmbH to its list of victims, threatening to leak stolen data unless the company pays up. It’s just the latest in a steady drumbeat of ransomware disclosures this month, part of a broader pattern security researchers are tracking across manufacturing, healthcare, and critical infrastructure sectors worldwide. (Source: DeXpose Intel Feeds)

Unpatched GeoServer zero-day being actively exploited

Security researchers flagged active exploitation attempts against an unpatched zero-day vulnerability in GeoServer, the widely used open-source geospatial data server, warning that successful exploitation can lead to full remote code execution. Organizations running GeoServer are advised to watch vendor channels closely for a fix and apply available mitigations in the meantime. (Source: The Hacker News)

Attackers piling onto SharePoint authentication bypass flaw

Once proof-of-concept exploit code for a Microsoft SharePoint authentication bypass vulnerability went public, attackers wasted little time putting it to use. It’s a familiar pattern in security: once a working exploit is public, the window between disclosure and real-world attacks shrinks dramatically, making rapid patching critical for any organization running on-premises SharePoint. (Source: The Hacker News)

Spf Permerror 6790

OpenAI pauses frontier reinforcement learning training over safety concerns

OpenAI said it has paused training runs for its most advanced (“frontier”) models using reinforcement learning while it strengthens safeguards meant to catch unsafe model behavior before it ships. The move is part of a broader industry trend of AI labs slowing down releases to tighten internal red-teaming and safety evaluation processes as models grow more capable. (Source: The Hacker News)

White House memo opens door for U.S. firms to hack back at foreign cybercriminals

A newly reported White House memo reportedly clears a path for U.S. companies to take more direct offensive action - including hacking and disrupting infrastructure against foreign cybercrime groups. The move marks a notable shift in how aggressively private industry may be allowed to respond to attacks, a topic likely to draw debate among legal and cybersecurity policy experts in the weeks ahead. (Source: The Hacker News)

Critical GitLab flaw could let attackers wipe public projects

GitLab shipped an out-of-cycle patch for a critical flaw (CVE-2026-19478, CVSS 9.4) in its Community and Enterprise editions that could let an unauthenticated attacker remotely modify or delete public projects and user data via a GraphQL directive. Self-managed GitLab installations need to update manually; GitLab.com and GitLab Dedicated customers were already protected. (Source: The Hacker News)

Brad Slavin
Brad Slavin

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.