Exploits and vulnerabilities in Q2 2026
2026-08-26T20:51:46Z•3d982e4757b59c94056930b466ec10c11f284d730eb0d2a4fa66c2d423ade694
APTAiTMAnatsaAndroid-malwareArmored-LikhoCoolClientDNS-C2Google-Apps-Script-C2Head-MareHoneyMyteMFA-bypassPhantomCorePhantomGraphStill-ToolkitTrueConfcloud-phishingcredential-theftcyber-espionageeducation-sectorexploitskernel-rootkitmalwareproxy-botnetvulnerabilities
What happened
Kaspersky Securelist reporting from August 2026 covering Q2 vulnerability and exploit trends, malware and APT campaigns, kernel-level rootkits, Android proxy botnets, exploitation of unpatched TrueConf servers, cloud-hosted adversary-in-the-middle phishing that bypasses MFA, DNS and Google Apps Script command-and-control, and threats targeting educational institutions. The collection describes active exploitation, espionage, credential theft, evasion, and backdoor delivery across Windows, Android, cloud, IoT, and collaboration platforms.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 3d982e4757b59c94056930b466ec10c11f284d730eb0d2a4fa66c2d423ade694
- Enrichment time
- 2026-08-26T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.