Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

2026-08-06T07:24:01Zee5cfbd0e870509127ac2ae0ab8bb227fbe95028cfdd3fdae89f4f98f6fce821
CVE-2026-18556CVE-2026-18577CVE-2026-58048CVE-2026-59774CVE-2026-64531CVE-2026-9198AI-securityCISA-KEVClickFixGiteaLinux-kernelMFA-bypassOAuthRATSnowflakeactive-exploitationcredential-theftcriticaldata-breachdeveloper-securitydevice-code-phishingmalicious-packagesmalwarenpmphishingprivilege-escalationprompt-injectionremote-code-executionsecrets-exposuresupply-chainvulnerability

What happened

The feed reports widespread active and emerging cyber threats, including critical and actively exploited vulnerabilities, ransomware and malware delivery campaigns, malicious open-source packages and extensions, phishing-as-a-service abusing OAuth device codes, exposed secrets, AI-agent abuse, and major data breaches. Notable issues include unauthenticated critical file reading in Gitea (CVE-2026-59774), actively exploited Langflow, Tomcat, and N-central flaws, Linux Open vSwitch local privilege escalation (CVE-2026-64531), cPanel database-root SQL execution (CVE-2026-58048), and widespreadnpm

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ee5cfbd0e870509127ac2ae0ab8bb227fbe95028cfdd3fdae89f4f98f6fce821
Enrichment time
2026-08-06T07:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.