Infosec bits for 2026 week 35
Zoya Vilakazi
| Aug. 28, 2026, 2:57 p.m.
Cybersecurity News:
The cybersecurity blind spot putting South African businesses at risk [Partner, My Broadband]
Android 17 adds ECH support to make web browsing harder to track [Bill Toulas, Bleeping Computer]
Manchester Airports Group breached, millions of customers’ data stolen [Sinisa Markovic, Help Net Security]
OpenAI Agents Coordinated Hugging Face Breach at Scale [Emilia David, Bank Info Security]
Researchers warn about chained SharePoint sequence [David Jones, Cybersecurity Dive]
Vulnerabilities & Patches:
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities [Eduard Kovacs, Security Week]
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access [Swati Khandelwal, The Hacker News]
Recent Citrix NetScaler Vulnerability Exploited in the Wild [Eduard Kovacs, Security Week]
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes [Sinisa Markovic, Help Net Security]
Windows 11 KB5120998 update released with 35 changes and fixes [Sergiu Gatlan, Bleeping Computer]
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions [Ravie Lakshmanan, The Hacker News]
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE [Swati Khandelwal, The Hacker News]
Rasomware & Malware:
Fake OpenAI Codex download tricks macOS users into installing malware [Sinisa Markovic, Help Net Security]
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address [Swati Khandelwal, The Hacker News]