Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.
Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.
Researchers at Truffle Security reported that after four years of collecting leaked Amazon Web Services keys, they found 768 that still grant full control over a company's cloud account, with a median age of about five years. The keys were exposed in places like public code and configuration and were never rotated, so they remain live long after the people who created them have likely forgotten them. A single valid key with broad permissions can let an attacker read data, spin up resources, and move through a cloud environment. The finding is a reminder that leaked long-lived credentials remain one of the most durable and overlooked paths into cloud accounts.
US Bank said that data-theft claims made by the LockBit ransomware group stem from a fourth-party incident that happened outside its own environment, at a contractor working for one of its third-party vendors. The bank stated there is no evidence its own systems, networks, or data repositories were compromised, while LockBit set a deadline to leak the data unless paid. The "fourth-party" framing is the notable part: exposure reached the bank's customers through a vendor's vendor, two steps removed from its own controls. It follows earlier third-party incidents affecting US Bank customer data and underscores how far organizations' real attack surface extends beyond their direct suppliers.
Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.
Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.
Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.
Researchers disclosed a critical flaw in Elementor Pro, the widely used WordPress page builder, that lets an unauthenticated visitor upload a PHP file through a public form and run code on the server. Tracked as CVE-2026-32475 and scored 9.0, it is a desynchronization bug in the Forms module's file-upload field: the code that validates an upload and the code that saves it disagree about how to handle an empty file entry. By sending a crafted upload with an empty first part followed by a PHP payload, an attacker slips the file past validation into a public directory. It affects versions up to 4.2.1 and is fixed in 4.2.2.
Attackers briefly poisoned arrayref, a foundational Rust crate with about 245 million downloads that sits underneath widely used graphics and blockchain libraries, along with two sibling crates from the same maintainer account. The crate code itself was clean; each added a dependency on a typosquat of a popular package whose build script ran during compilation, pulling and executing an infostealer that grabbed host data and browser credentials. Because the malicious code lived in a build script, simply compiling a project that resolved the crate ran it, with nothing from the library needing to be called. The bad versions were pulled within about ninety minutes, but any build during that window was exposed.
Researchers at Socket found 40 malicious Firefox extensions, part of a wider set of 77, that impersonate cryptocurrency wallets like OKX, Rabby, and TronLink to steal users' funds. Dubbed the Offside Wallet Theft Factory and active since March, the campaign uses lookalike names with subtle character swaps, cloned wallet code, and reused extension identities. Some variants capture recovery phrases as a user sets up or imports a wallet; others copy the wallet's keyring before it is encrypted locally, so on-device encryption offers no protection. Stolen data goes out through Cloudflare Workers, attacker databases, and hardcoded servers. Removing an extension after theft does not secure the wallet, so victims must move funds.