Cyber Security Brief — 2026-08-24
Today's brief: UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit (The Hacker News) — Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology…
- ToxicPanda Android malware uses VPN permissions to block Google Play (BleepingComputer) — The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit (The Hacker News) — The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.…
- Hackers infect Android car head units with proxy botnet malware (BleepingComputer) — A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [..…
- Named Pipes Under Attack: Securing Windows Interprocess Communication (BleepingComputer) — Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command au…
Newly published, high-severity CVEs
- CVE-2026-78167 (CVSS 10, CRITICAL) — A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. …
- CVE-2026-78155 (CVSS 9.9, CRITICAL) — privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
- CVE-2026-78169 (CVSS 9.9, CRITICAL) — A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of…
- CVE-2026-5388 (CVSS 9.8, CRITICAL) — justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitiza…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 3 Security Score scans across our customers in the past 7 days.
- medium: 4
- info: 19
- high: 7
- low: 9
Most common issues:
- Cross-origin stylesheet loaded without Subresource Integrity (seen 6x)
- DKIM not detected at common selectors (seen 3x)
- No DMARC record (seen 3x)
- DNSSEC not detected (seen 3x)
- Missing recommended headers (1) (seen 2x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan