Dark Caracal Adds New Malware to Cyber Espionage Arsenal

2026-08-27T02:51:35Zfe194c06163e739431807d2be0f1c4508b024020684c482efd47096f0a04db61
CVE-2026-19478CVE-2026-73570AI-securityAPTAndroid-securityChina-linked-threatsLLM-poisoningNorth-KoreaOT-securityPakistan-linked-threatsagentic-AIbanking-trojanbotnetcloud-securitycredential-theftcyber-espionageindustrial-control-systemsmalwarephishingprompt-injectionransomwaresession-theftsupply-chain-securitythreat-intelligencevulnerability-exploitationzero-click

What happened

Dark Reading coverage from August 17–26, 2026 highlights active cyber-espionage campaigns, modular malware and banking trojans, credential and session theft, ransomware and botnet evolution, exploited enterprise vulnerabilities, supply-chain and insider risks, and emerging threats involving AI agents, LLM poisoning, prompt injection, and insecure sandboxing. Notable items include exploitation of Zimbra CVE-2026-73570 and a critical GitLab zero-click flaw (CVE-2026-19478), along with attacks targeting Android devices, industrial protocols, Microsoft 365 sessions, cloud environments, and vehicle

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
fe194c06163e739431807d2be0f1c4508b024020684c482efd47096f0a04db61
Enrichment time
2026-08-27T02:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.