Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
| Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions |
| Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data |
| U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog |
| Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients |
| WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover |
| Hackers Impersonate IT Support to Breach Leading Financial Companies |
| Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case |
| Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access |
| AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam |
| Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records |
| Ransom Cartel Leader Sentenced to 16 Years in U.S. |
| Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident |
| U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog |
| Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records |
| AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems |
| Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals |
| U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog |
| OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root |
| SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access |
| SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency |
| INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit |
| CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access |
| U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog |
| 31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register |
| AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek |
| River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted |
| PNLD Confirms Data Breach Affecting UK Police and Justice Staff |
| Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys |
| Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing |
| CareCloud Breach Exposes Medical and Financial Data of 345,000 |
| CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks |
International Press – Newsletter
CareCloud begins to notify hundreds of thousands after hackers stole medical records
Żabka alleged data leak: 541k Jira tickets, 89 repos
ExfilSquad Targets Misconfigured Microsoft Power Pages Portals
Cyberattack hits Liechtenstein’s register of people behind companies and foundations
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
Major hedge funds targeted in wave of attempted cyberattacks
Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison
Scammers target OnlyFans users with deepfakes
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Malware
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
Wallet-depleting macOS malware wants your crypto
Hacking
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation
Swiss federal IT office hit by cyberattack
OVSwrap: another Linux local root vulnerability
Incident Report: unsanctioned agent behaviour during cyber testing
Meta says its AI model hacked into another company during testing
Natjack A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES
XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)
Black Hat USA 2026: The ‘Breaking’ News: The OpenAI–Hugging Face Incident
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security update available for Metabase – Please upgrade now
CSS:the bomb inside your inbox
Intelligence and Information Warfare
DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster
China launches mysterious probe into security of Palo Alto Networks’ products
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists
Cybersecurity
EU in talks with OpenAI, Anthropic after rogue AI agent hacks
Commission publishes new guidance to support timely Cyber Resilience Act implementation
Western government leaders call for a focus on infrastructure resilience, not AI hype
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
ENDLESSDOORS Is Phoning Home. Pick Up
Meta fined $567m in largest child safety ruling against social media giant
Hackers targeted US private equity, other firms including Blackstone, CME, data shows
Military device manufacturer discloses cyber incident to SEC
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, newsletter)

