Clear Infosec Threat Intelligence Bulletin – Aug 26th, 2026

Cyber Security News

Grandoreiro Malware Resurfaces With Mexico Campaign

The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder. Read more

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that’s invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information. Read more

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Every time you add an extension or plugin to your browser, there’s a risk that you might be doing more than managing your cryptocurrency wallet, generating pass… Read more

Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc – exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare… Read more

Best Practices

CISOs are struggling to threat-model AI Can 15-minute sessions help?

A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe… Read more

Akira ransomware reboots into Windows Safe Mode to knock EDR offline

Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a comprom… Read more

Attackers target zero-day vulnerability in geospatial data platform GeoServer

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in Geo… Read more

4 gaps slowing AI in enterprise SOCs

Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-… Read more

New Threats and Vulnerabilities

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that’s capable of hijacking Chrom… Read more

14 Trojanized npm Packages Drop RedC2 40 Linux Backdoor With AI-Assisted C2

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealt… Read more

AI-Generated Exploit Scripts Target Siemens S7 PLCs in US Critical Infrastructure

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-… Read more

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 pr… Read more

Patch Management

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security… Read more

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it p… Read more

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in que… Read more

Adobe Patches Three CVSS 100 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully explo… Read more

AI and Security

Code fixers have fired up the AI warp drive Strange new worlds await

It is the best of times, it is the worst of times – especially if your job is keeping systems patched and up to date. Microsoft has gone from 60-90 Windows sec… Read more

Claude Code returns blank thinking blocks but reasoning still costs you

Anthropic’s Claude Code appears to be having trouble displaying summaries of its "thinking," according to several bug reports, while the underlying reasoning t… Read more

Microsofts dueling Copilot apps have combined into a single entity

Microsoft’s consumer Copilot app and Microsoft 365 Copilot are separate no more, with a unified Copilot app beginning its rollout Thursday – minus a few featur… Read more

Grok chat duped into swallowing injected instructions

xAI’s Grok web chat agent is currently vulnerable to a novel form of prompt injection, according to security researchers with Adversa AI. The technique allows … Read more