📡 Tech & Security Digest — 2026-08-26 Curated from Hacker News, security blogs, and tech publications.
BleepingComputer Hackers abuse npm mirrors to host phishing redirect pages — Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-contr… ReliaQuest confirms failed data-theft attack after ShinyHunters breach — Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a memb… Hackers breached over 270 Zimbra servers in ongoing attacks — Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite… Unpatched Calix flaw lets hackers bypass NAT to expose internal devices — An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated at… Hacker News When str.lower() is a security vulnerability in Python (96 pts) OpenAI Jalapeño: Better than Nvidia Blackwell (417 pts) Krebs on Security Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on… Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple… Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co… The Hacker News Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution — A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emer… 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages — Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirect… Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead … Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Ora… Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account — Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server th… GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure — A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerabil…
...