Issue #213 - August 24, 2026
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Source: The Hacker News
Researchers demonstrated GPUThor, a Rowhammer technique that produced multi-bit errors on several NVIDIA Ampere workstation GPUs and bypassed the protection expected from ECC. With unprivileged CUDA execution, the team achieved denial of service and host privilege escalation. Defenders should limit untrusted GPU workloads, avoid cross-tenant sharing, and monitor ECC errors.
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
Source: BleepingComputer
CVE-2026-75501 exposes a MiniUPnPd control endpoint on affected Calix GS7 XGS residential routers without authentication. Remote attackers can create persistent port-forwarding rules that bypass NAT and expose internal cameras, storage, administration interfaces, or IoT devices. No patch was available; users were advised to disable UPnP or contact their ISP.
Russian Hackers Phish EU Officials Over Messaging Apps
Source: Dark Reading
European officials are facing spear-phishing campaigns delivered through Signal and WhatsApp, where attackers impersonate support services, demand PINs, or trick targets into linking hostile devices through QR codes. The shift moves social engineering beyond monitored email channels and highlights the need for approved government messaging platforms, device controls, and user verification procedures.
Cyberattack Causes Global Disruption at Boston Scientific
Source: SecurityWeek
Boston Scientific disclosed a cybersecurity incident affecting IT systems and causing a global network outage. The disruption limited access to business applications, including systems used to process and ship customer orders. The medical-device company said its investigation was continuing and that the incident’s operational, financial, and possible data-breach impacts remained unknown.
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
Source: SecurityWeek
U.S. authorities seized domains supporting QScan and QTRouter, platforms tied to the China-linked QTFY group. The infrastructure scanned for vulnerable IoT devices, built an obfuscation botnet, and supported attacks against military, government, telecom, higher-education, and other critical targets. Hard-coded domain seizures reportedly rendered both services inoperable.



