Washington is hiring pirates to fight cybercrime
This week delivered a striking split-screen on how governments are choosing to fight cybercrime. In the United States, President Trump signed a memorandum on 15 August authorizing private companies to hack back against foreign cybercriminal groups by taking down their servers and even deploying spyware, all subject to government approval. Officials have openly compared the scheme to 18th-century privateering, when states licensed private raiders to attack enemy ships.
Across the Atlantic, the UK took the opposite tack: two members of the notorious Scattered Spider group were jailed for five and a half years each over the 2024 Transport for London attack, in what prosecutors called the largest cyber crime prosecution ever brought before the UK courts. One country is deputizing private pirates while the other is putting the real ones behind bars.
Two young men have been sentenced for launching a cyber attack on Transport for London (TfL) which cost tens of millions of pounds in losses and inconvenienced thousands of customers. Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were identified by the NCA and City of London Police following the infiltration of TfL’s network between 31 August and 3 September 2024.
www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case
The United States will allow private companies to hack foreign cybercriminal groups, a seemingly unprecedented measure that is dividing experts who say it has potential to succeed or spiral out of control. President Donald Trump signed a memorandum on Wednesday that directed the departments of Justice and Homeland Security to allow certain U.S. companies to spy on and attack transnational criminal organizations. The White House justified the approach by citing the damage caused by ransomware, “sextortion” and online fraud, which it said cost Americans more than $20 billion in 2025.
https://www.japantimes.co.jp/news/2026/08/17/world/crime-legal/us-bet-pirates-cybercrime/
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. The incident began on August 16, 2026, at around 21:58 UTC, and is affecting Claude.ai, Claude Code, and Claude Cowork. According to Anthropic’s status page, the company first said it was investigating an issue preventing some users from authenticating to Claude.ai, Claude Code, and Claude Cowork. A few minutes later, Anthropic reported a broader service disruption involving degraded performance on Claude.ai and platform.claude.com.
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-in-major-outage-affecting-multiple-services/
A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials. Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.
https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/
A sophisticated new information-stealing malware dubbed AmnesiaStealer has emerged, targeting macOS users through deceptive ClickFix campaigns to gain interactive, remote control over authenticated web browser sessions. By leveraging a specialized streaming module, the malware allows attackers to hijack active sessions across 16 Chromium-based browsers while bypassing standard security identifiers. This development marks a significant escalation in threat capabilities, moving beyond simple data exfiltration to real-time, operator-driven manipulation of a victim's digital identity.
meterpreter.org/jewelbug-crypto-fraud-espionage-xg-web
WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads. According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights.
https://www.securityweek.com/wordpress-7-0-4-patches-remote-code-execution-vulnerability/
Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables Unauthenticated RCE via PostGIS. A zero-day SQL injection in GeoServer's jsonArrayContains OGC filter function (GHSA-mqjf-5f49-2fjh, CVSS 9.8) lets unauthenticated attackers inject arbitrary SQL against PostGIS-backed layers, escalating to remote code execution via PostgreSQL's COPY TO PROGRAM when the database role has elevated privileges. Disclosed without coordination on 2026-08-12 by researcher q1uf3ng, it was under active internet-wide probing within hours (per WatchTowr) before GeoServer 3.0.1/2.28.5/2.27.6 patched it on 2026-08-14.
https://intel.threadlinqs.com/threat/TL-2026-2035
Trellix Advanced Research Center identified MessiahGPT, a criminal AI-as-a-service model advertised on BreachForums since July 2026 and offered live at messiahgpt[.]de plus a Telegram community, claiming zero ethical constraints (no RLHF, no Constitutional AI layer) to generate ransomware, phishing kits, stealers, crypters, rootkits, exploits/PoC code, fraud content, and more for as little as $8/month in crypto.
https://intel.threadlinqs.com/threat/TL-2026-2036
The Chinese threat group Jewelbug has repurposed a single piece of infrastructure to serve two distinct objectives simultaneously: surveilling government organizations and profiting from cryptocurrency fraud. Symantec researchers determined that a small team managed both operations through a shared system, and the resulting database contained traces of thousands of compromised devices.
https://meterpreter.org/jewelbug-crypto-fraud-espionage-xg-web
Researchers at Palo Alto Networks’ Unit 42 have disclosed three distinct attack paths that allow malware already running on a Windows machine to hijack passkey-protected accounts through Chrome’s Google Password Manager, bypassing the very authentication mechanism designed to replace passwords.
https://pulseofnations.lol/unit-42-exposes-three/
A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline.
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
Researchers at watchTowr published a working exploit for a Citrix NetScaler RCE flaw this week. The bug, CVE-2026-8452, lets an unauthenticated attacker run code as root on the appliance. watchTowr released both the technical write-up and proof-of-concept code publicly. So, the barrier to attack just dropped sharply.
https://securityonline.info/citrix-netscaler-pre-auth-rce-cve-2026-8452
Researchers have identified the HollowGraph malware, which leverages Microsoft 365 calendars and Microsoft Graph APIs as a covert command-and-control (C2) channel. The malware has been attributed to the Cavern framework, a previously documented threat infrastructure. HollowGraph abuses legitimate Microsoft 365 services to evade detection by blending malicious traffic with normal calendar and API activity. No specific dates, victim organizations, or technical indicators (e.g., hashes, CVEs) were disclosed in the report. The primary impact involves stealthy C2 communications, potentially enabling data exfiltration or further compromise.
https://www.cyberhub.blog/article/29330-hollowgraph-malware-abuses-microsoft-365-calendars-and-graph-apis-for-covert-c2-operations
Orange Tsai of the DEVCORE Research Team demonstrated a vulnerability at Pwn2Own that completely bypasses Microsoft Exchange authentication. Coordinated disclosure began on May 21, 2026; the patch arrived on August 11, 2026, after 82 days. The exposure window is closed, but the mechanism remains a wake-up call for anyone managing on-premises mail servers: under certain conditions, a remote attacker can seize all corporate mailboxes without valid credentials.
https://deafnews.it/en/news/cybersecurity/cve-2026-62911-exchange-authentication-bypass-enables-full-mailbox-takeover
Reco is tracking an ongoing campaign we've named the City-Forum Campaign, after a domain tied to the threat actor's IP (more on that below). A single server is pulling records out of Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals, from infrastructure that has been standing since March 2025. In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users, for example ShinyHunters. This actor is different. Except for Aura, the attacker reaches Salesforce Lightning Web Runtime (LWR) sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools. This post covers the indicators, how to hunt them on both platforms, how to close the exposure and a technical dive into exactly how each technique works on the wire.
https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service.According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses, but not payment information or records related to orders. In the email it sent to affected customers, Framework said it was notified of the breach by Metabase, who confirmed that the attackers gained access to Framework’s cloud instance.Framework has rotated credentials for the databases it connected to its Metabase instance and said that it’s yet to find evidence of a wider compromise.
https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/