FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
2026-08-27T01:24:00Z•60d9c05c144b079dfdc94157fd1805695a52494d8389f6a144ac966f427c98c2
CVE-2026-19912CVE-2026-19913CVE-2026-21962CVE-2026-60004CVE-2026-61979AI securityAPTCISA KEVChina-linkedGiteaIran-linkedKalturaMCPMicrosoft 365Oracle WebLogicRATWordPressactive exploitationadversary-in-the-middlebackdoorcredential theftcritical infrastructurecyber fraudmalwarenpm abusephishing-as-a-serviceransomwaresession hijackingstate-sponsoredsupply-chain
What happened
The feed reports a broad range of cybersecurity developments, including state-sponsored espionage by Chinese and Iranian actors, phishing-as-a-service campaigns targeting Microsoft 365 and Apple users, malware and backdoors, active exploitation of critical vulnerabilities, supply-chain abuse, AI-agent security risks, and law-enforcement disruption operations. Notable vulnerabilities include actively exploited Gitea RCE CVE-2026-60004, Oracle WebLogic/HTTP Server CVE-2026-21962, Kaltura mwEmbed CVE-2026-19912 and CVE-2026-19913, and miniOrange SAML CVE-2026-61979. Overall risk is high due to in
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 60d9c05c144b079dfdc94157fd1805695a52494d8389f6a144ac966f427c98c2
- Enrichment time
- 2026-08-27T01:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.