Infosec bits for 2026 week 34
Heloise Meyer
| Aug. 20, 2026, 10:26 a.m.
Cybersecurity News:
Infostealers Harvest 1.7 Billion Credentials in Six Months [Phil Muncaster, Infosecurity Magazine]
5 Key Takeaways from Black Hat USA 2026 [Jake Kramber, Orca Security]
Rising Number of Cyberattacks Have AI-Assisted Fingerprints [Mathew J. Schwartz, Bank Info Security]
Vulnerabilities & Patches:
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner [Bill Toulas, Bleeping Computer]
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects [Swati Khandelwal, The Hacker News]
600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin [István Márton, Wordfence]
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover [Alessandro Mascellino, Infosecurity Magazine]
943 Patches Rolled Out With Oracle’s August 2026 Security Update [Ionut Arghire, SecurityWeek]
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway [Rapid7, Rapid7]
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code [Ravie Lakshmanan, The Hacker News]
Malware:
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies [Ravie Lakshmanan, The Hacker News]
New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen [WAQAS, HackRead]
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra [Alessandro Mascellino, Infosecurity Magazine]