Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

2026-08-20T01:23:59Z9772aa5814fbd32811325cb23203fe3bf9b2c94e328ac2ed9531bd3f2f638fa6
CVE-2026-15748CVE-2026-19478CVE-2026-65400AI securityC2Cloudflare WorkersDNS tunnelingDahuaGitHub ActionsGitLabIoTJWT leakageMLflowRATRaySharePointSpectreTeamsWordPressactive exploitationcloud securitycredential theftdata breachespionageinformation stealermacOS malwaresupply chainzero-day

What happened

The feed reports active exploitation of critical vulnerabilities, cloud and AI infrastructure risks, malware campaigns, espionage activity, credential theft, supply-chain abuse, and data exposure incidents. Notable threats include Spectre-based JWT leakage in co-located Cloudflare Workers, exploitation of MLflow, Ray, GitLab, Forminator, and enterprise platforms, large-scale Dahua compromise, macOS information stealers, WordPress-based malware distribution, and state-linked RAT campaigns.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9772aa5814fbd32811325cb23203fe3bf9b2c94e328ac2ed9531bd3f2f638fa6
Enrichment time
2026-08-20T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.