ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

2026-08-20T19:24:03Z2c6c2e7a5e7e1cafe135e96b582fb5696365b806bdbac9104027fa845624cd55
CVE-2026-32475CVE-2026-65400CVE-2026-73570AI-securityDDoSIoTPLCSCADAactive-exploitationandroidauthentication-bypassbanking-malwarebrowser-extensionscloud-securitycommand-injectioncredential-theftcritical-infrastructurecryptocurrency-theftcyber-espionagedata-exfiltrationindustrial-control-systemsinformation-stealermalwarephishingremote-code-executionvulnerability-exploitationwebshellwordpress

What happened

Weekly cybersecurity roundup highlighting active exploitation, critical vulnerabilities, malware campaigns, AI-assisted attacks, supply-chain and cloud risks, industrial-control targeting, and data-exfiltration techniques. Notable incidents include exploited Zimbra command injection, critical Elementor Pro unrestricted upload leading to RCE, NASA AIT-GUI command injection risks, NetScaler authentication bypass, attacks against Siemens PLCs, Android banking malware, malicious browser extensions, and large-scale compromise of Dahua devices.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2c6c2e7a5e7e1cafe135e96b582fb5696365b806bdbac9104027fa845624cd55
Enrichment time
2026-08-20T19:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.