Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
2026-08-20T01:23:59Z•9772aa5814fbd32811325cb23203fe3bf9b2c94e328ac2ed9531bd3f2f638fa6
CVE-2026-15748CVE-2026-19478CVE-2026-65400AI securityC2Cloudflare WorkersDNS tunnelingDahuaGitHub ActionsGitLabIoTJWT leakageMLflowRATRaySharePointSpectreTeamsWordPressactive exploitationcloud securitycredential theftdata breachespionageinformation stealermacOS malwaresupply chainzero-day
What happened
The feed reports active exploitation of critical vulnerabilities, cloud and AI infrastructure risks, malware campaigns, espionage activity, credential theft, supply-chain abuse, and data exposure incidents. Notable threats include Spectre-based JWT leakage in co-located Cloudflare Workers, exploitation of MLflow, Ray, GitLab, Forminator, and enterprise platforms, large-scale Dahua compromise, macOS information stealers, WordPress-based malware distribution, and state-linked RAT campaigns.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 9772aa5814fbd32811325cb23203fe3bf9b2c94e328ac2ed9531bd3f2f638fa6
- Enrichment time
- 2026-08-20T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.