Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief — August 26, 2026

NVIDIA AI Agent Platform Vulnerable to Drive-By Model Poisoning

A critical vulnerability in NVIDIA's NemoClaw AI agent deployment wrapper (CVE-2026-65105) allows attackers to hijack and persistently poison local AI models through a single malicious website visit. The flaw stems from NemoClaw's default configuration, which binds the underlying Ollama API to 0.0.0.0, exposing it to DNS rebinding attacks. Researchers demonstrated that an attacker-controlled webpage can exploit this misconfiguration to inject malicious instructions, alter model behavior, and maintain persistent access to the AI agent without requiring user interaction beyond visiting the site. The vulnerability highlights emerging attack surfaces as AI agents gain filesystem access and operational autonomy, with security firms warning that autonomous AI systems deployed with overly permissive network configurations create novel exploitation vectors that bypass traditional security boundaries.

Iran-Linked Groups Target U.S. Water Infrastructure and Universities in Coordinated Campaigns

The Department of Justice charged 17 Iranian nationals allegedly affiliated with the Islamic Revolutionary Guard Corps in a multi-year cyber espionage campaign targeting hundreds of U.S. and international universities to exfiltrate research and intellectual property. Separately, Iranian-linked threat groups have been actively exploiting vulnerable programmable logic controllers in attacks against U.S. water treatment facilities, focusing on industrial control systems with known security weaknesses. A separate China-nexus operation dubbed QUICSILVER is targeting Myanmar government personnel and IT sectors using Virtual Hard Disk files disguised as diplomatic event invitations to deliver QUICAgent, a Go-based backdoor that tunnels command-and-control traffic through the QUIC protocol and leverages Cloudflare Workers infrastructure to obscure attacker infrastructure. Additionally, researchers disclosed 24 malicious npm packages abusing unpkg CDN mirrors to redirect developers to ClickFix-style fake CAPTCHA pages for credential theft.


Sources: The Hacker News · Cybersecurity News · Facilities Dive · Campus Reform · Seqrite · The Hacker News

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

What we know about the hacking campaign against US water systems | Facilities Dive

Threat groups with suspected links to Iran have targeted vulnerable programmable logic controllers, the devices used to monitor and control ...

Read more →

Employee benefits platform Paylogix says hackers stole financial and health data

The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.

Read more →

CISA Gives Federal Agencies 72 Hours To Patch Actively Exploited Oracle Bug

CISA issued an urgent directive requiring Federal Civilian Executive Branch agencies to patch CVE-2026-21962, a critical Oracle vulnerability with a C...

Read more →

Iran-linked hackers blamed for taking down U.K. power plant for first time, reports say

The attack happened the same month Iranian-linked hackers are believed to have targeted the water systems of a dozen U.S. states.

Read more →

After Hugging Face Was Attacked By A.I. Agents, It Embarked on a Crusade

Hugging Face, a start-up that was breached by rogue bots from OpenAI, is using the hack to push for openness in A.I. development.

Read more →
Cybersecurity icon

Big Cyber

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

"The client cannot detect or prevent this - the template is a model-level property invisible to API consumers," Oasis Security said. Cybersecurity.

Read more →

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

#1 Trusted Cybersecurity News Platform. Followed by 5.70+ million · The Hacker News Logo... Get the Latest News. Home; Newsletter ...

Read more →

The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera

These incidents mark an important shift in cybersecurity. For years, much of the public conversation around cyberthreats focused on data. People ...

Read more →

A Chinese A.I. Lab May Test the World's Cybersecurity With a Model - The New York Times

Lab May Test the World's Cybersecurity. In July, an unreleased OpenAI model went rogue and demonstrated remarkable hacking abilities. This week, a lab...

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.