Issue #214 - August 31, 2026
Hackers push malicious Virtualizor update in BGP hijacking attack
Source: BleepingComputer
Attackers diverted Virtualizor update traffic by hijacking BGP routes associated with Softaculous infrastructure, then delivered a malicious package to a small number of servers. The vendor restored routing, released a security analyzer, and advised administrators to check for a suspicious service, rotate credentials, and audit systems for unauthorized access.
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Source: The Hacker News
Threat actors are using the signed Node.js runtime to execute malicious JavaScript in targeted intrusions against government, technology, hospitality, and financial organizations. The approach can evade binary-focused detection, establish persistence, and retrieve tooling through blockchain-based infrastructure after ClickFix campaigns or failed attempts to deploy more familiar command-and-control frameworks.
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Source: Infosecurity Magazine
Attackers exploited a fail-open authentication flaw in a publicly exposed, researcher-built application to obtain a METR model-provider API key. They retained access and consumed roughly $600,000 in credits over three weeks. METR said the credits were provided free and found no evidence that sensitive information was accessed.
23-Year-Old Sality P2P Botnet Disrupted
Source: SecurityWeek
An international operation disrupted the 23-year-old Sality peer-to-peer botnet by manipulating its trusted peer lists, isolating infected systems, and taking down payload-hosting URLs. CrowdStrike-operated sinkholes now receive bot traffic, while the Shadowserver Foundation is helping internet providers and incident-response teams identify victims and clean affected machines.
Exploit Published for Fresh Cleo Harmony Vulnerability
Source: SecurityWeek
A public exploit now targets CVE-2026-84115, an authentication bypass in Cleo Harmony's JWT refresh-token logic. Crafted bearer-token arguments could let remote attackers elevate privileges, retain access, or move laterally through connected systems. The flaw is fixed in version 5.8.1.11, and customers are urged to update quickly.



