💥 BREACHES & INCIDENTS
- South Korean startup platform breach exposed encryption key via API
A South Korean government-backed startup platform exposed data for about 5,000 applicants.- Modu-ui Changup supports a nationwide startup audition program overseen by South Korea’s Ministry of SMEs and Startups.
- Exposed data included email addresses, evaluation comments, and startup idea summaries.
- The platform’s API returned an encryption key alongside encrypted data.
- External parties collected the API data through web crawling, including AI-based crawling.
- Authorities identified 39 South Korean IP addresses that accessed the exposed information.
📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer
🕵️ RESEARCH & DEEP DIVES
-
Chameleon SEO Poisoning Delivers Cloaked Banking Phishing Pages
Attackers are poisoning Google and Bing results to steal banking credentials.- Major financial institutions and their customers are targeted.
- Lookalike banking portals capture passwords and hijack active sessions.
- Attackers use SEO poisoning to rank fraudulent pages for banking searches.
- Cloaking serves malicious content only to visitors arriving from Google or Bing.
- Fortra reported a 40% increase in Chameleon attacks in Q2 2026; .ph.com and .gr.com domains were cited.
📄 Source: fortra.com · 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News
-
768 Exposed AWS Keys Still Grant Full Corporate Admin Access
Truffle Security found 768 publicly exposed AWS keys still provide full corporate account control.- AWS customers, companies, and cloud-hosted applications are affected.
- Researchers found 817 company-linked exposed keys, including 526 root keys and 242 AdministratorAccess IAM keys.
- The keys appeared in Git history, Hugging Face datasets, Docker images, package registries, and CI/CD logs.
- About 88% of 10,616 re-verified credentials still authenticated on August 10, 2026; the median key age was 1,831 days.
📄 Source: trufflesecurity.com · 📎 Coverage: bleepingcomputer.com · 👁 via Cyber Security News, cryptika.com (discovered)
-
Latvia’s CSDD Confirms Breach Affecting 1.2 Million People
Latvia’s CSDD confirmed a breach affecting payment records of 1.2 million people.- Latvia’s Road Traffic Safety Directorate and its customers were affected.
- Payment records of more than 1.2 million people and 200,000 organizations were exposed.
- The breach affected roughly two-thirds of Latvia’s population.
📎 Coverage: research.checkpoint.com · 👁 via Check Point Research
-
Attackers Impersonated ReliaQuest Staff to Steal SSO and MFA Access
Attackers used vishing to obtain one ReliaQuest employee’s SSO session.- ReliaQuest employees were targeted in the August 22, 2026, social-engineering attack.
- Attackers captured one employee’s password, MFA approval, and a view-only identity-dashboard session.
- The attackers posed as named ReliaQuest security staff during targeted phone calls.
- They used a lookalike ReliaQuest domain hosting a counterfeit SSO portal behind a CDN.
📄 Source: reliaquest.com · 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News, cryptika.com (discovered)
-
PavinLoader Used in ClickFix and Fake-Download Malware Campaigns
PavinLoader is being used in campaigns delivering Amatera Stealer.- Users are targeted through ClickFix, fake-software and RenPy campaigns.
- PavinLoader delivers Amatera Stealer and other malware.
📎 Coverage: securityboulevard.com · 👁 via securityboulevard.com (discovered)
-
wordlistloader-synkloader-malware-campaign (6) — <https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html|The Hacker News>
🔓 CVEs & KEV
-
CVE-2026-66648 — CVSS 9.8 — WordPress Jawn theme through 1.4.2 - Privilege Escalation vulnerabilityUnauthentic...
-
CVE-2026-32558 — CVSS 9.8 — WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugi...
-
CVE-2026-78365 — CVSS 9.3 — IDOR and missing authorization in Prospero Flow CRM supplier API allows cross...
-
CVE-2026-32551 — CVSS 9.3 — WordPress Woo Essential plugin through 4.3.0 - SQL Injection vulnerabilityUnauthen...
-
CVE-2026-21756 — CVSS 7.2 — HCL Hive is affected by a broken access control vulnerabilityHCL Hive is affe...
📋 ADVISORIES
- 📄 Source for Kimsuky Uses AI-Generated Chrome Extension to Steal Gmail Data — blog.polyswarm.io