Breaking News – Cyber Threats – 2026-08-31 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-08-31 08:00 PDT
- Chinese Fire Ant hackers turn Cisco routers into spying platforms
BleepingComputer • 2026-08-31 07:52 • www.bleepingcomputer.com
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. […]
https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/ - File servers are here to stay. Here’s how to manage them securely
BleepingComputer • 2026-08-31 07:00 • www.bleepingcomputer.com
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. […]
https://www.bleepingcomputer.com/news/security/file-servers-are-here-to-stay-heres-how-to-manage-them-securely/ - ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The Hacker News • 2026-08-31 06:50 • thehackernews.com
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html - Berlin confirms data theft after Rhysida ransomware attack claims
BleepingComputer • 2026-08-31 06:30 • www.bleepingcomputer.com
Berlin’s city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. […]
https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/ - ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The Hacker News • 2026-08-31 05:14 • thehackernews.com
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html - Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
The Hacker News • 2026-08-31 04:47 • thehackernews.com
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its
https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html - Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
The Hacker News • 2026-08-31 04:31 • thehackernews.com
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.AI has moved from the browser tab to the
https://thehackernews.com/2026/08/securing-claude-code-new-compliance-api.html - Hiding Prompt Injection in Legal Filing
Schneier on Security • 2026-08-31 04:03 • www.schneier.comSomeone hid AI instructions into a legal filing.
Alternate link.
https://www.schneier.com/blog/archives/2026/08/hiding-prompt-injection-in-legal-filing.html
- Microsoft says Windows 11 KB5120998 update resets mouse settings
BleepingComputer • 2026-08-31 03:23 • www.bleepingcomputer.com
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. […]
https://www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/ - ValleyRAT masquerading as adware
Securelist • 2026-08-31 03:00 • securelist.com
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
https://securelist.com/valleyrat-backdoor-adware/121175/ - Nigerians extradited to US for sextortion, deaths of two teens
BleepingComputer • 2026-08-31 02:22 • www.bleepingcomputer.com
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. […]
https://www.bleepingcomputer.com/news/security/nigerians-charged-US-over-sextortion-deaths-of-us-teens/ - China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
The Hacker News • 2026-08-31 02:04 • thehackernews.com
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor
https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.