Dark Caracal Adds New Malware to Cyber Espionage Arsenal
2026-08-27T02:51:35Z•fe194c06163e739431807d2be0f1c4508b024020684c482efd47096f0a04db61
CVE-2026-19478CVE-2026-73570AI-securityAPTAndroid-securityChina-linked-threatsLLM-poisoningNorth-KoreaOT-securityPakistan-linked-threatsagentic-AIbanking-trojanbotnetcloud-securitycredential-theftcyber-espionageindustrial-control-systemsmalwarephishingprompt-injectionransomwaresession-theftsupply-chain-securitythreat-intelligencevulnerability-exploitationzero-click
What happened
Dark Reading coverage from August 17–26, 2026 highlights active cyber-espionage campaigns, modular malware and banking trojans, credential and session theft, ransomware and botnet evolution, exploited enterprise vulnerabilities, supply-chain and insider risks, and emerging threats involving AI agents, LLM poisoning, prompt injection, and insecure sandboxing. Notable items include exploitation of Zimbra CVE-2026-73570 and a critical GitLab zero-click flaw (CVE-2026-19478), along with attacks targeting Android devices, industrial protocols, Microsoft 365 sessions, cloud environments, and vehicle
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- fe194c06163e739431807d2be0f1c4508b024020684c482efd47096f0a04db61
- Enrichment time
- 2026-08-27T02:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.