ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
2026-08-20T19:24:03Z•2c6c2e7a5e7e1cafe135e96b582fb5696365b806bdbac9104027fa845624cd55
CVE-2026-32475CVE-2026-65400CVE-2026-73570AI-securityDDoSIoTPLCSCADAactive-exploitationandroidauthentication-bypassbanking-malwarebrowser-extensionscloud-securitycommand-injectioncredential-theftcritical-infrastructurecryptocurrency-theftcyber-espionagedata-exfiltrationindustrial-control-systemsinformation-stealermalwarephishingremote-code-executionvulnerability-exploitationwebshellwordpress
What happened
Weekly cybersecurity roundup highlighting active exploitation, critical vulnerabilities, malware campaigns, AI-assisted attacks, supply-chain and cloud risks, industrial-control targeting, and data-exfiltration techniques. Notable incidents include exploited Zimbra command injection, critical Elementor Pro unrestricted upload leading to RCE, NASA AIT-GUI command injection risks, NetScaler authentication bypass, attacks against Siemens PLCs, Android banking malware, malicious browser extensions, and large-scale compromise of Dahua devices.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2c6c2e7a5e7e1cafe135e96b582fb5696365b806bdbac9104027fa845624cd55
- Enrichment time
- 2026-08-20T19:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.