InfoSec News 20260826
Publicada em: 26/08/2026
TOP NEWS
Massive DDoS attack disrupts Norway’s government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector.
The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta.
Link
TLP1: Green
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.
Both organizations were fully compromised at the domain level, and in both, the red team also reached sensitive business systems (SBSs) and cloud resources.
Link
TLP1: Green
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.
"The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said.
Link
TLP1: Green
Cybersecurity State: Surveillance, Cyberwarfare, Cybercriminality and Hacktivism
Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups.
The "Operation Jackal IV" international joint action targeted West African criminal networks between November 2025 and June 2026.
Link
TLP1: Green
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide.
Link
TLP1: Green
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.
The technique was previously spotted in July by security researcher inf0stache, who found a 'china_airlines' npm package that used a fake Cloudflare verification page to redirect visitors to a malicious domain, and was also reported by IntelFusions.
Link
TLP1: Green
Breaches: Data Breaches and Hacks
Hospital operator Nutex Health says data stolen in cyberattack
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.
The organization has disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC), noting that the stolen data includes details that may be private or confidential.
Link
TLP1: Green
Vulnerabilities: Vulnerability Advisories, Zero-Days, Patches and Exploits
Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are actively exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Like cloud-hosted GitHub or GitLab SaaS (Software as a Service) platforms, Gitea provides a full suite of DevOps tools, but it is designed to be used as a self-hosted software development platform.
Link
TLP1: Green
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.
The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform.
Link
TLP1: Green
Incident Response: Infrastructure, Training, SIEM and Incident Handling
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation.
Link
TLP1: Green
Technical Articles: Forensics, Reverse Engineering, Malware, Phishing, Pentesting, Software Security and Cryptography
WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification.
While the instant messaging service already allowed users to add passkeys for secure logins via fingerprint, Face ID, or screen lock code, it now lets them create separate ones for each platform.
Link
TLP1: Green
1Traffic Light Protocol (TLP) [1] for information sharing:
- Red: Not for disclosure, restricted to participants only.
- Amber: Limited disclosure, restricted to participants organizations.
- Green: Limited disclosure, restricted to the community.
[1]https://www.first.org/tlp