CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) catalog, signaling active attacks against the self-hosted Gitea Git platform. The weakness is a code injection issue, meaning successful exploitation can lead directly to remote compromise and follow-on access. Organizations running Gitea should treat this as an urgent patching event and verify instances are updated and not reachable by the internet if not required.
Source: Help Net Security
US disrupts China-linked infrastructure (QScan and QTRouter) used to compromise critical systems
The FBI and DOJ announced the disruption of China-linked hacking platforms QScan and QTRouter, which were used to hide intrusions and target US critical infrastructure and other sectors. The action highlights a continued pattern where threat actors rely on infrastructure to support reconnaissance, persistence, and operational routing across victims. Defenders should review for related indicators and focus on hardening detection for unusual scanning and infrastructure “relay” behavior.
Source: The Record
Over 100 water systems targeted in July; CISA urges utilities to find exposed PLCs before attackers do
CISA reported that attackers targeted more than 100 internet-exposed water and wastewater systems during July, prompting a guidance push centered on reducing exposure. The core message is operational: utilities must locate and secure internet-facing PLCs and associated pathways before they become a convenient entry point for threat actors. Given the potential real-world impact, incident response planning should include industrial control system (ICS) containment assumptions, not just IT recovery steps.
Source: SecurityWeek
“GhostJacking”: attackers turn poisoned logs/blocked events into production DNS hijacks via AI agents
Research described an emerging class of AI agent compromise where prompt-injection doesn’t arrive via a direct malicious prompt, but through data the agent is expected to inspect—such as blocked payloads, alert/event records, or error logs. Because agents can both interpret and execute, an attacker can sometimes transform “defender artifacts” into instructions that lead to high-impact changes like rerouting DNS. The practical takeaway is governance: enforce authorization outside the model, split “read/observe” from “execute/change,” and require human approval for actions with meaningful blast radius.
Source: VentureBeat
Mobile phishing and recruitment scams keep targeting accounts—and increasingly rely on “browser-in-the-browser” tactics
Researchers documented recruitment scams that impersonate HR or recruiters to steal high-value corporate credentials, including campaigns that use browser-in-the-browser (BitB) approaches. These workflows can make targets believe they’re interacting with a legitimate sign-in page while attackers capture authentication material or complete takeover steps. Organizations should tighten identity defenses with phishing-resistant controls (where feasible), monitor for unusual session behaviors, and train employees to treat credential-entry flows from unexpected recruiting communications as high risk.
Source: Help Net Security
WhatsApp rolls out stronger account protections: passkeys growth plus improved verification and caller context
Meta says WhatsApp now has more than one billion users using passkeys, alongside enhancements to two-step verification and improved information around calls from unknown numbers. While these changes are consumer-focused, the security impact is meaningful: passkeys reduce exposure to password-based compromise and can lower the success rate of social engineering that relies on credential theft. Enterprises supporting employee account security should still treat account-level takeovers as a viable initial intrusion path and reinforce secure device and session management.
Source: Help Net Security
Chrome 152 patches 300+ vulnerabilities—reinforcing the need for rapid browser update hygiene
Google’s latest Chrome update fixes more than 300 security vulnerabilities, including issues that malicious websites could potentially exploit immediately upon visit. Even when drive-by exploitation is difficult at scale, browsers remain a high-leverage target because they sit at the center of user activity and web execution paths. Organizations should ensure endpoint management enforces timely browser updates and prioritize auditing for machines that lag behind.
Source: Malwarebytes
You May Also Be Interested In... Chrome 152 Patches Over 300 Vulnerabilities
Who Has Admin Rights in your Entra ID Directory?
The Future of AI-Driven Security Depends on Complete Data