HomeCyber BalkansWeekly Cybersecurity Newsletter: Top 50 Major Cybersecurity Stories of the Week -...

Weekly Cybersecurity Newsletter: Top 50 Major Cybersecurity Stories of the Week – GBHackers Security

Published on

spot_img

The cybersecurity landscape in the first week of September 2026 was notably influenced by rapid advancements in artificial intelligence and ongoing threats from coordinated cyberattacks. The weekly bulletin released by GBHackers encapsulated the most critical headlines, detailing how AI played a pivotal role throughout the week. Significant developments included OpenAI’s introduction of its GPT-6 ‘Astra’ model, which showcased the capability to build working exploits and identify zero-day vulnerabilities, ultimately raising alarms over the potential misuse of such technologies. Additionally, Anthropic launched its Claude Fable 5.1 and Mythos 5.1 models, enhancing their automated capabilities in cybersecurity, even as critics pointed out concerns regarding their application in malicious activities. Another notable event highlighted the breach of an enterprise network by frontier agents in under ten hours, exemplifying the alarming agility of modern attackers leveraging AI to expedite cyberspace infiltrations.

As the threat landscape evolved, the scrutiny on cybersecurity countermeasures increased. APT28-linked hackers took to deploying a new backdoor, dubbed HOOKEDGE, across European territories. This new development is aimed at facilitating espionage activities and underscores the persistent danger posed by state-sponsored cybercriminals. Meanwhile, the Cybersecurity and Infrastructure Security Agency (CISA) flagged critically exploited vulnerabilities in PaperCut software, a widely used print management solution, further reinforcing the necessity for organizations to bolster their response strategies against active exploitation.

The week was riddled with alarming revelations concerning ongoing malware campaigns and ransomware threats that spanned multiple countries. The latest iteration of the Panzer ransomware successfully targeted victims across 11 nations, employing a dual-extortion strategy that combines both data encryption and theft. This model puts added pressure on organizations, urging them to contemplate the severe consequences of data breaches. Cyber experts stress the importance of swift mitigation efforts, particularly as they have documented the frequency with which ransomware groups operate with apparent impunity.

IN THIS ISSUE

Top Stories of the Week  —  9 stories

AI Under Attack  —  8 stories

Critical Vulnerabilities & Patches  —  9 stories

Malware & APT Campaigns  —  9 stories

Breaches, Fraud & Attacks  —  8 stories

Industry News & Defense  —  7 stories

🔥 TOP STORIES OF THE WEEK

1. Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks

Aug 31, 2026  •  gbhackers.com

The Aurora ransomware group demonstrated the utilization of the Cursor AI agent in their hands-on exploitation alongside ESXi attacks. This marks a significant move showcasing how cybercriminals are integrating AI coding tools into their operational methodologies.

2. Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps

Sep 3, 2026  •  gbhackers.com

The capabilities of Claude AI have expanded significantly, now allowing it to control computers operating on both macOS and Windows systems. While this advancement is poised to elevate productivity, serious concerns arise regarding potential misuse and the subsequent challenges in oversight.

3. OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests

Sep 4, 2026  •  gbhackers.com

The OpenAI GPT-6 Astra has identified zero-day vulnerabilities and constructed viable exploits during cyber tests. This can potentially amplify fears regarding the offensive use of sophisticated AI models.

4. Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

Sep 5, 2026  •  gbhackers.com

Researchers have gained unauthorized access to an enterprise network using frontier AI agents in less than 10 hours. This serves as a stark reminder of the rapid pace at which autonomous attackers can operate.

5. CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems

Sep 4, 2026  •  gbhackers.com

A recently uncovered CrowdStrike Falcon zero-day vulnerability enables attackers to escalate their privileges on Windows systems. The risk is amplified considering the security agent operates under a high-trust environment.

6. CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild

Sep 1, 2026  •  gbhackers.com

In its advisory, CISA identified multiple vulnerabilities in the PaperCut NG/MF software being actively exploited across various platforms. Organizations utilizing this print management application have been urged to implement patches expeditiously.

7. Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Sep 5, 2026  •  gbhackers.com

Hackers associated with Russian APT28 have deployed a newly developed HOOKEDGE backdoor in espionage operations throughout Europe. This new tool grants the state-sponsored group discreet and sustained access to targeted systems.

8. Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets

Aug 31, 2026  •  gbhackers.com

This week, the Shai-Hulud Trinitite worm infiltrated the widely used TanStack Query npm package, targeting developer secrets. Such supply chain attacks have demonstrated the rapid and silent spread of malware within package management systems.

9. New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Sep 5, 2026  •  gbhackers.com

The emergence of new Panzer ransomware has affected 16 victims in 11 different countries, implementing both data encryption and theft strategies. The dual-extortion approach creates a multifaceted pressure on organizations to consider paying ransoms.

🤖 AI UNDER ATTACK

10. OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks

Aug 31, 2026  •  gbhackers.com

OpenAI issued a warning regarding its Astra AI model about the potential risks of developing zero-day exploits that could lead to autonomous cyberattacks, highlighting serious concerns related to the dual-use of advanced AI technologies.

11. Anthropic Unveils Claude Fable 5.1 and Mythos 5.1 With Powerful Cybersecurity Capabilities

Sep 2, 2026  •  gbhackers.com

Anthropic introduced its Claude Fable 5.1 and Mythos 5.1, which incorporate enhanced cybersecurity capabilities to address the growing demand for automated defense mechanisms within IT environments.

12. LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models

Sep 4, 2026  •  gbhackers.com

An LLMjacking attack has been reported, which utilizes leaked AWS credentials to hijack Amazon Bedrock AI models. The misuse of stolen keys can lead to significant expenses and expose sensitive access to proprietary models.

13. AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers

Aug 31, 2026  •  gbhackers.com

Vulnerabilities in AI-powered shopping assistants can enable remote code execution on retailers’ servers. This development highlights the need for stricter security measures around consumer-facing AI tools, which may inadvertently broaden enterprise vulnerabilities.

14. Google Unveils Gemini 3.8 Flash Cyber for Autonomous Vulnerability Discovery and Automated Patching

Sep 3, 2026  •  gbhackers.com

Google rolled out Gemini 3.8 Flash Cyber, designed for autonomous vulnerability discovery and automated patching, adding to the growing suite of AI models aimed at enhancing defensive security measures.

15. OWASP Launches OASIS to Use AI and AppSec Experts to Fix Open-Source Vulnerabilities

Sep 2, 2026  •  gbhackers.com

The Open Web Application Security Project (OWASP) initiated the OASIS project to leverage both AI technologies and application security experts in addressing and remediating open-source vulnerabilities more efficiently.

16. Bright Security Expands its AI SDLC Security Platform and Launches an AI PT Module

Sep 1, 2026  •  gbhackers.com

Bright Security has expanded its AI secure software development life cycle platform and introduced an AI penetration testing module, aiming to integrate robust security principles into rapid, AI-driven development practices.

17. OpenMatter Network Expands Platform With New Capabilities for Secure AI, Computing and Data Collaboration

Sep 3, 2026  •  gbhackers.com

OpenMatter Network announced enhancements to its platform, adding new features for secure AI computing and data collaboration, targeting better governance for sensitive data and model sharing.

⚠️ CRITICAL VULNERABILITIES & PATCHES

18. Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

Aug 31, 2026  •  gbhackers.com

Metasploit has integrated an exploit targeting the zero-day remote code execution vulnerabilities found within the PaperCut MF/NG software, significantly raising the urgency for organizations to secure their exposed print servers.

19. GitSpawn Flaw Enables Arbitrary Code Execution in Claude Code, Codex, Cursor and Grok

Sep 3, 2026  •  gbhackers.com

A vulnerability identified in GitSpawn permits arbitrary code execution within AI coding assistants such as Claude Code, Codex, Cursor, and Grok. This flaw demonstrates the risks associated with cloning compromised repositories.

20. Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks

Sep 1, 2026  •  gbhackers.com

Cybercriminals have been identified exploiting critical vulnerabilities in Langflow and Ruby on Rails, leading to active RCE attacks. These are particularly concerning due to their association with widely used AI and web applications.

21. Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released

Sep 4, 2026  •  gbhackers.com

A vulnerability in the Google Chrome V8 engine has been discovered to be actively targeted in the wild, prompting Google to release an urgent update. Given Chrome’s extensive user base, quick patching of such vulnerabilities is critical.

22. Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

Sep 4, 2026  •  gbhackers.com

Discovery of a Microsoft 365 Direct Send bypass vulnerability has enabled attackers to spoof the identities of internal users without requiring any credentials, a development that significantly enhances phishing campaigns.

23. TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft

Sep 4, 2026  •  gbhackers.com

Several critical flaws in TP-Link’s Archer AX55 routers have been identified, which could allow remote code execution and theft of administrative passwords. Given millions of these routers are in use worldwide, there is a substantial risk for many home and small-office environments.

24. 12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

Sep 5, 2026  •  gbhackers.com

A long-standing flaw in PostgreSQL, prevalent for a staggering 12 years, has been disclosed, allowing attackers to execute code and potentially seize control over database servers. The prolonged existence of such vulnerabilities in production systems raises serious questions about update mechanisms and security practices.

25. 13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds

Sep 1, 2026  •  gbhackers.com

Thirteen harmful themes within the Packagist repository have been linked to the exploitation of iPhone vulnerabilities for theft of crypto wallet seeds. This incident underscores the growing threat posed by poisoned developer packages, capable of swiftly and quietly compromising security.

26. Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks

Aug 31, 2026  •  gbhackers.com

With the release of Android 17, new network security features aimed at blocking 2G SMS blaster attacks have been introduced. This specific enhancement seeks to thwart the manipulative tactics employed by fraudulent base stations targeting communication systems.

🦠 MALWARE & APT CAMPAIGNS

27. Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets

Aug 31, 2026  •  gbhackers.com

Malicious extensions in Chrome and Edge have been observed stripping Content Security Policies (CSP) and injecting JavaScript code capable of draining Ethereum Virtual Machine (EVM), Solana, and Tron wallets. These browser add-ons represent a stealthy pathway into the world of cryptocurrency theft.

28. Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline

Aug 31, 2026  •  gbhackers.com

An infostealer infection has inadvertently disclosed aspects of a Blind Eagle-linked operator’s malware production pipeline. Such revelations offer rare insight into the operational methods and tools employed by cyber adversaries.

29. Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies

Sep 2, 2026  •  gbhackers.com

The Trojanized Exodus wallet installer has been reported to deploy Remote Access Trojans (RATs) that target browser credentials and cookies. This method entices cryptocurrency users to unknowingly compromise their own devices.

30. Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems

Sep 2, 2026  •  gbhackers.com

Cybercriminals are impersonating legitimate brands, such as Microsoft Edge, Kaspersky, and Razer, to distribute fake installers that compromise Windows systems. Such tactics exploit users’ trust in recognized brands to spread malware.

31. 255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers

Sep 2, 2026  •  gbhackers.com

A sophisticated attack leveraging 255 fake accounts targeted 80,000 freelancers by sending out malicious Excel files. This broad approach highlights the vulnerability of the gig economy to large-scale malware campaigns.

32. Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems

Sep 3, 2026  •  gbhackers.com

Rogue clients utilizing ScreenConnect have begun to spread worm-like malware across connected Windows systems. By manipulating legitimate remote software, the campaign evades security measures aimed at preventing unauthorized access.

33. NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft

Sep 4, 2026  •  gbhackers.com

NodeStealer spyware has been upgraded to incorporate keylogging, screenshot capture, and the ability to pilfer Facebook data. Such enhancements expand its functionality, allowing for broader data harvesting.

34. Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications

Sep 4, 2026  •  gbhackers.com

Contagious Interview operators have shifted focus beyond Git hooks to deploying trojanized applications targeted at Mac systems. This development reflects the evolving tactics of cybercriminals, particularly those linked to North Korea, in adapting their approaches to match their targets.

35. Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

Sep 4, 2026  •  gbhackers.com

Cyber adversaries have repurposed HiveMQ and Element Messenger platforms as command channels for Windows backdoors. By blending in with legitimate messaging traffic, the malware avoids detection, allowing for covert operations.

🔓 BREACHES, FRAUD & ATTACKS

36. Hackers Use Infostealer Malware to Steal Claude Session Cookies and Hijack Accounts

Aug 31, 2026  •  gbhackers.com

A new trend has emerged with hackers employing infostealer malware to pilfer session cookies from users of Claude, leading to account hijacking. Such tactics undermine multi-factor authentication, raising concerns about the sufficiency of existing security measures.

37. BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers

Sep 1, 2026  •  gbhackers.com

A BGP hijacking attack has resulted in the delivery of malicious updates for Virtualizor to servers. Such routing-layer attacks create opportunities for adversaries to contaminate trusted software distribution channels.

38. Hackers Compromise More Than 14,500 Dahua Security Cameras in Massive Campaign

Sep 4, 2026  •  gbhackers.com

In a wide-ranging campaign, cybercriminals compromised over 14,500 Dahua security cameras. This extensive mass compromise of the Internet of Things (IoT) devices could facilitate further attacks by providing an easy access point to vulnerable networks.

39. CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Sep 5, 2026  •  gbhackers.com

A significant data breach at CARS24 resulted in the exposure of 3,100 customer records, with reports indicating that these leads were sold for ₹1,000 each. The incident highlights the lucrative market for even small datasets within the realm of cybercrime.

40. Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs

Sep 1, 2026  •  gbhackers.com

The Mirage Kitten hacking group has utilized fake coding challenges as a lure to deploy Remote Access Trojans (RAT) such as NodeRabbit and PollCat. This strategy exploits the trust of job-seekers in technical assessments.

41. Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees

Sep 1, 2026  •  gbhackers.com

In a clever social engineering tactic, hackers have posed as IT support representatives on the Microsoft Teams platform, successfully targeting over 150 employees. Such strategies that exploit the trust inherent in workplace tools continue to offer risks to corporate environments.

42. Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment

Sep 3, 2026  •  gbhackers.com

A sophisticated scam involving fake acquisition negotiations employed forged NDAs to demand a €626,000 corporate payment. This highlights the persistent evolution of business-email-compromise tactics by cybercriminals.

43. QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes

Sep 3, 2026  •  gbhackers.com

QR phishing attacks have surged to unprecedented levels as cybercriminals use QR codes to conceal malicious links, bypassing many existing security measures that rely on link detection.

📊 INDUSTRY NEWS & DEFENSE

44. Broadcom Unveils VMware AI Factory With Secure Sandboxes for Enterprise AI Workloads

Sep 1, 2026  •  gbhackers.com

Broadcom has launched its VMware AI Factory, designed with secure sandboxes intended for enterprise AI workloads. This initiative addresses governance shortfalls present in fast-paced AI deployment strategies.

45. Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices

Aug 31, 2026  •  gbhackers.com

A straightforward adjustment to router DNS settings can significantly block malware and phishing opportunities across all connected devices, showcasing the ease with which users can enhance their network security.

46. Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers

Sep 2, 2026  •  gbhackers.com

The introduction of a built-in ad blocker in Firefox for iPhone allows users to block a majority of third-party ads and trackers, enhancing privacy controls for mobile browsing experiences.

47. Threat Intelligence: Definition, Benefits, and Use Cases

Sep 2, 2026  •  gbhackers.com

A comprehensive explainer from GBHackers offers insights into threat intelligence, detailing its definition, benefits, and practical use cases. This resource serves as a valuable primer for teams aiming to establish or enhance their threat intelligence programs.

48. Hackers Hide Reverse Shell Traffic Behind Signed Apps and AWS API Gateway

Sep 2, 2026  •  gbhackers.com

Cyber adversaries are increasingly employing tactics to conceal reverse-shell traffic behind signed applications and the AWS API Gateway, successfully evading detection by blending into trusted cloud services.

49. Fewer Attacks, More Force: Link11’s European Cyber Report Finds New DDoS Records for H1 2026

Sep 3, 2026  •  gbhackers.com

The latest report from Link11 highlights a context where fewer but increasingly forceful attacks set new records for DDoS incidents in the first half of 2026, indicating a shift towards more powerful, less frequent cyber assaults.

50. Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Sep 5, 2026  •  gbhackers.com

Chainguard recently reached a milestone of managing 1 billion build manifests in its quest to secure software supply chains through AI-powered solutions. This achievement reflects the growing recognition for strengthened build pipeline security in the tech community.

Source link

Latest articles

TerminalFix Malware Campaign Utilizes Steganography

Microsoft Unveils Insights on TerminalFix: A New Wave of Sophisticated Malware Microsoft has brought to...

Shai-Hulud Infostealer Expands to 469 Credential Locations

In early August, a new version of the infostealer worm known as Shai-Hulud was...

NodeStealer Spyware Introduces Keylogging, Screenshot Capture, and Facebook Data Theft

Major Evolution of NodeStealer Malware: A Broad-Spectrum Spyware Platform In August 2026, security researchers alerted...

Thomson Reuters C-Track Breach Exposes Sensitive Court Records

Significant Cybersecurity Breach Affects Thomson Reuters C-Track Court Management Software In a troubling development for...

More like this

TerminalFix Malware Campaign Utilizes Steganography

Microsoft Unveils Insights on TerminalFix: A New Wave of Sophisticated Malware Microsoft has brought to...

Shai-Hulud Infostealer Expands to 469 Credential Locations

In early August, a new version of the infostealer worm known as Shai-Hulud was...

NodeStealer Spyware Introduces Keylogging, Screenshot Capture, and Facebook Data Theft

Major Evolution of NodeStealer Malware: A Broad-Spectrum Spyware Platform In August 2026, security researchers alerted...