43AA 6E9A 54EE B550 D830 EF7A 36EE 72FB 8AD1 F5CC

Infosec bits for 2026 week 34

Heloise Meyer | Aug. 20, 2026, 10:26 a.m.

Cybersecurity News:

  • Infostealers Harvest 1.7 Billion Credentials in Six Months [Phil Muncaster, Infosecurity Magazine]
  • 5 Key Takeaways from Black Hat USA 2026 [Jake Kramber, Orca Security]
  • Rising Number of Cyberattacks Have AI-Assisted Fingerprints [Mathew J. Schwartz, Bank Info Security]
  • Vulnerabilities & Patches:

  • Hackers exploit macOS Screen Sharing flaw to deploy Monero miner [Bill Toulas, Bleeping Computer]
  • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects [Swati Khandelwal, The Hacker News]
  • 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin [István Márton, Wordfence]
  • WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover [Alessandro Mascellino, Infosecurity Magazine]
  • 943 Patches Rolled Out With Oracle’s August 2026 Security Update [Ionut Arghire, SecurityWeek]
  • CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway [Rapid7, Rapid7]
  • Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code [Ravie Lakshmanan, The Hacker News]
  • Malware:

  • Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies [Ravie Lakshmanan, The Hacker News]
  • New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen [WAQAS, HackRead]
  • MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra [Alessandro Mascellino, Infosecurity Magazine]