Issue #212 - August 17, 2026
'Grandoreiro' Malware Resurfaces With Mexico Campaign
Source: Dark Reading
The Grandoreiro banking Trojan has returned in a campaign aimed primarily at Mexican users. Operators disguise malicious archives as invoices, abuse a legitimate file-management application for DLL sideloading, and deploy a heavily protected loader with extensive sandbox, security-tool, and analysis checks before downloading the credential-stealing payload.
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Source: The Hacker News
Researchers demonstrated an encrypted prompt-injection technique that allegedly caused Grok to decrypt hidden instructions and send session details and conversation content to an attacker-controlled server. The reported chain exploited the agent’s code execution and navigation tools without a confirmation step, highlighting the need for provenance controls and strict egress boundaries.
Critical GitLab Flaw Exploited Shortly After Disclosure
Source: SecurityWeek
Attackers began exploiting CVE-2026-19478 roughly two days after its public disclosure. The critical GitLab code-injection flaw allows unauthenticated attackers to modify or delete public projects and user data through a GraphQL directive. Organizations should install fixed releases immediately and inspect web logs for probing or exploitation attempts.
Rogue ransomware affiliate poses as recovery firm to steal payments
Source: BleepingComputer
A suspected ransomware affiliate calling itself Ransom Busters contacted victims before incidents became public and offered decryption and data deletion services. Researchers linked its tools, backdoor credentials, and infrastructure to the original intrusions, suggesting the affiliate was attempting to divert payments from ransomware operations while increasing uncertainty for victims.
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
Source: BleepingComputer
The CameraSwarm campaign compromised more than 14,500 Dahua cameras through brute-force attacks, older vulnerabilities, and recovery codes derived from device serial numbers. Some backdoor accounts survived password changes and factory resets, while cloud relay access reached devices behind NAT. Owners should update firmware, disable unnecessary P2P access, and inspect exposed cameras.



