Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A critical zero-day SQL injection vulnerability in GeoServer (now assigned GHSA-mqjf-5f49-2fjh, CVSS 9.8) was publicly disclosed on August 12, 2026, by researcher @q1uf3ng. The flaw resides in the `jsonArrayContains` function within the PostGIS DataStore implementation and allows unauthenticated SQL injection.
This week’s ThreatsDay Bulletin covers a wide range of cybersecurity developments, including an advanced data theft campaign targeting Salesforce and ServiceNow guest access, a data breach at shipping provider ShipMonk affecting Trezor customers, and a critical vulnerability in Cursor’s CLI that allowed untrusted repository code execution. Emerging threats like the GhostJacking AI agent hijacking and the scale of vishing operations via Okta’s Work Panel are detailed, alongside new defensive features from Meta, Signal, and Tracebit that aim to protect users and systems through on-device analysis, automatic key verification, and innovative use of prompt injections.
The Jewelbug hacker group is simultaneously conducting espionage operations targeting government and military webmail while engaging in cryptocurrency fraud schemes. This dual-purpose approach blurs the line between state-sponsored espionage and financially motivated cybercrime.
Cisco Talos discovered a previously undocumented real-time phishing framework called JWR, likely a variant of the Outsider phishing-as-a-service platform. It uses open WebSocket connections to let attackers monitor keystrokes live and steer victims through fake checkout flows, enabling theft of payment data, 2FA codes, and device fingerprints.
Microsoft released security patches for a Windows zero-day vulnerability named LegacyHive, which was disclosed after the July 2026 Patch Tuesday cycle. The flaw was actively exploited in the wild, prompting an urgent out-of-band update to protect affected systems.
Following Anthropic's introduction of text watermarking for Claude, numerous unverified 'watermark remover' tools have appeared online, including a popular open source project. None of these tools can prove their claims because Anthropic has not yet released a detection mechanism.