SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111

2026-08-24T02:51:39Zaeda53ba26849ee0fe6bb76cd93f4cf3659ecf7d8eb9b5b20ef289ef86f179ec
CVE-2026-73570AI-securityAndroid-malwareBADBOXCISA-KEVCiscoICSIran-linked-threat-actorToxicPandaZimbraactively-exploitedbanking-malwarebotnetcritical-vulnerabilitycyber-threat-intelligencedata-exfiltrationinfostealermalwarepayment-securitypower-gridprompt-injectionransomwarespace-systemsunauthenticated-command-executionwater-infrastructure

What happened

Security Affairs roundup covering major malware, cyberattack, vulnerability, and security research developments. Notable items include Iran-linked disruption of a UK power plant and attacks on U.S. water infrastructure; ToxicPanda 2.0 targeting Android banking applications; BADBOX-related malware compromising Android vehicle head units; a critical unauthenticated command-execution flaw in NASA/JPL AIT-GUI; the actively exploited Zimbra flaw CVE-2026-73570; cryptographic prompt/context injection affecting Grok chat confidentiality; payment-card expiry validation weaknesses; and multiple maximum

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
aeda53ba26849ee0fe6bb76cd93f4cf3659ecf7d8eb9b5b20ef289ef86f179ec
Enrichment time
2026-08-24T02:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.