Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — August 26, 2026
NVIDIA AI Agent Platform Vulnerable to Drive-By Model Poisoning
A critical vulnerability in NVIDIA's NemoClaw AI agent deployment wrapper (CVE-2026-65105) allows attackers to hijack and persistently poison local AI models through a single malicious website visit. The flaw stems from NemoClaw's default configuration, which binds the underlying Ollama API to 0.0.0.0, exposing it to DNS rebinding attacks. Researchers demonstrated that an attacker-controlled webpage can exploit this misconfiguration to inject malicious instructions, alter model behavior, and maintain persistent access to the AI agent without requiring user interaction beyond visiting the site. The vulnerability highlights emerging attack surfaces as AI agents gain filesystem access and operational autonomy, with security firms warning that autonomous AI systems deployed with overly permissive network configurations create novel exploitation vectors that bypass traditional security boundaries.
Iran-Linked Groups Target U.S. Water Infrastructure and Universities in Coordinated Campaigns
The Department of Justice charged 17 Iranian nationals allegedly affiliated with the Islamic Revolutionary Guard Corps in a multi-year cyber espionage campaign targeting hundreds of U.S. and international universities to exfiltrate research and intellectual property. Separately, Iranian-linked threat groups have been actively exploiting vulnerable programmable logic controllers in attacks against U.S. water treatment facilities, focusing on industrial control systems with known security weaknesses. A separate China-nexus operation dubbed QUICSILVER is targeting Myanmar government personnel and IT sectors using Virtual Hard Disk files disguised as diplomatic event invitations to deliver QUICAgent, a Go-based backdoor that tunnels command-and-control traffic through the QUIC protocol and leverages Cloudflare Workers infrastructure to obscure attacker infrastructure. Additionally, researchers disclosed 24 malicious npm packages abusing unpkg CDN mirrors to redirect developers to ClickFix-style fake CAPTCHA pages for credential theft.
Sources: The Hacker News · Cybersecurity News · Facilities Dive · Campus Reform · Seqrite · The Hacker News
Around the Web
Last Updated: N/A

Hacks + Heists
What we know about the hacking campaign against US water systems | Facilities Dive
Threat groups with suspected links to Iran have targeted vulnerable programmable logic controllers, the devices used to monitor and control ...
Read more →Employee benefits platform Paylogix says hackers stole financial and health data
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
Read more →CISA Gives Federal Agencies 72 Hours To Patch Actively Exploited Oracle Bug
CISA issued an urgent directive requiring Federal Civilian Executive Branch agencies to patch CVE-2026-21962, a critical Oracle vulnerability with a C...
Read more →Iran-linked hackers blamed for taking down U.K. power plant for first time, reports say
The attack happened the same month Iranian-linked hackers are believed to have targeted the water systems of a dozen U.S. states.
Read more →After Hugging Face Was Attacked By A.I. Agents, It Embarked on a Crusade
Hugging Face, a start-up that was breached by rogue bots from OpenAI, is using the hack to push for openness in A.I. development.
Read more →
Big Cyber
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
"The client cannot detect or prevent this - the template is a model-level property invisible to API consumers," Oasis Security said. Cybersecurity.
Read more →U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
#1 Trusted Cybersecurity News Platform. Followed by 5.70+ million · The Hacker News Logo... Get the Latest News. Home; Newsletter ...
Read more →The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera
These incidents mark an important shift in cybersecurity. For years, much of the public conversation around cyberthreats focused on data. People ...
Read more →A Chinese A.I. Lab May Test the World's Cybersecurity With a Model - The New York Times
Lab May Test the World's Cybersecurity. In July, an unreleased OpenAI model went rogue and demonstrated remarkable hacking abilities. This week, a lab...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.