ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 590 by Pierluigi Paganini

infoIndustryimportance 10
AI summary · glm-5.3-flash

Weekly Security Affairs newsletter roundup aggregating top cybercrime, malware, APT and AI security stories including ExfilSquad, Kimwolf v7 and Kimsuky AI use.

This is the Round 590 weekly newsletter from Security Affairs, linking to the week's major stories rather than reporting a single incident. Headlines include ExfilSquad extortion, a 7.3M chess.com record leak, Kimwolf botnet v7, SharePoint exploitation after a public PoC, Kimsuky integrating AI, and China-linked autonomous-style attacks. It is a digest and promotional item with no standalone technical details.

  • Aggregates the week's Security Affairs stories across cybercrime, malware, APTs and AI security.
  • Includes Kimi K3 failing UK AI Safety Institute benchmarks and an Australian autonomous AI attack story.
Full article477 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

International Press – Newsletter

Cybercrime

ExfilSquad Targets New Victims, Shares Data via Torrents  

Israeli population registry for sale, but the data is old  

Before Fraud Transacts  

ExfilSquad Targets New Victims, Shares Data via Torrents

Fake CAPTCHA, Real Business: Traffic Distribution for Hire  

7.3M chess.com records leaked, and the data is real

Drop Something? Don’t Worry, Someone Caught it      

Malware

ShieldBreak – August 2026 disclosure  

Kimwolf v7: An Evolution of the Kimwolf Botnet 

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers  

Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme  

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection  

Hacking

Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations  

AI assistant hacks gym website in first known Australian autonomous cyber attack  

Zoomsday

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

It’s a pre-auth, stupid!  

A root remote command execution on macOS with M5 in 2026?

Intelligence and Information Warfare  

Follow-Up Analysis of the 29 December 2025 Energy Sector Incident    

New Jersey, Alabama Join States Targeted in Water Cyberattacks 

Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM  

China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack  

State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit  

Social engineering performed by UAC-0145: compromising in the employment process 

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side  

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure 

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved  

Cybersecurity

How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta

Responding to the next frontier of critical cyber capabilities      

Facebook is paying controversial creators to produce rage-bait content  

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC  

The August 2026 Security Update Review 

Cyberattack on logistics giant CEVA delivers customer data into the wrong hands

About Apple threat notifications and protecting against mercenary spyware

If Apple sends you a push notification alerting you to a spyware attack, take it seriously 

AI isn’t changing how companies work. It’s changing what a company is 

Swarms of OpenAI systems set up their own chatrooms to discuss and carry out hacks, company reveals 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197288/breaking-news/security-affairs-newsletter-round-590-by-pierluigi-paganini-international-edition.html