A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

2026-08-11T13:23:58Z24182a202166acfde8763b61cbf8576df633e3b22adda403bf43c9652dcb8260
CVE-2026-8037AI securityFortinetIoTKemp LoadMasterLinuxMetabaseVS CodeWindowsWordPressactive exploitationcellular devicescredential theftcritical infrastructurecryptocurrency theftdata exfiltrationinfostealermacOSmalwarenpmphishingprompt injectionransomwaresupply-chain attackvishingzero-day

What happened

A collection of August 2026 cybersecurity reports covering active exploitation, ransomware, supply-chain compromises, credential and cryptocurrency theft, AI-agent prompt injection and data exfiltration, critical infrastructure intrusions, malicious developer packages and extensions, authentication bypasses, and high-impact product vulnerabilities. Notable incidents include an actively exploited unauthenticated Metabase SQL injection zero-day, CISA KEV-listed Kemp LoadMaster command injection CVE-2026-8037, ransomware attacks against critical infrastructure, malicious npm and WordPress supply-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
24182a202166acfde8763b61cbf8576df633e3b22adda403bf43c9652dcb8260
Enrichment time
2026-08-11T13:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.