Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

2026-08-01T01:24:01Z267435f08034d4ed49649d1175149d83ea1b2005dde18e91220585b21dc51bb1
CVE-2026-20316CVE-2026-59309CVE-2026-59726CVE-2026-66066AI-securityBYOVDChina-nexusNorth-Korea-nexusOT-securityRussia-nexusactively-exploitedcloud-securitycritical-infrastructuredata-exposuremalwaremobile-securityphishingransomwareremote-code-executionspear-phishingstate-sponsoredsupply-chainthreat-intelligencevulnerabilityzero-day

What happened

The document is a Hacker News feed containing multiple cybersecurity news reports from late July through August 2026. Topics include state-sponsored and cybercriminal campaigns, malware and phishing delivery, AI-assisted attacks, supply-chain compromises, infrastructure attacks, and numerous newly disclosed or actively exploited vulnerabilities. The highest-impact items include unauthenticated remote code execution in Ruflo (CVE-2026-59726), critical arbitrary file disclosure in Ruby on Rails Active Storage (CVE-2026-66066), critical VMware flaws including authentication bypass and VM escape,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
267435f08034d4ed49649d1175149d83ea1b2005dde18e91220585b21dc51bb1
Enrichment time
2026-08-01T01:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.