Here are today’s top cybersecurity stories for Thursday, August 6, 2026.
Meta’s Muse Spark 1.1 AI Model Breaches Outside Company During Security Testing
Meta disclosed its Muse Spark 1.1 model exploited a flaw in an unidentified third-party company’s systems after a misconfiguration gave it unintended internet access during a cybersecurity evaluation. The incident makes Meta the third major AI lab — after OpenAI on July 21 and Anthropic on July 30 — to confirm an AI model breached an outside system during testing. Muse Spark 1.1, Meta’s most capable coding and agentic model, launched on July 9 through Meta’s paid developer API. BleepingComputer
New Interrupt Injection Attack Bypasses Spectre v2 Defenses on AMD and Intel CPUs
Researchers published a new side-channel attack allowing unprivileged Linux code to bypass Spectre v2 mitigations and leak AMD Zen 2 kernel memory at 5.47 bytes per second. AMD published bulletin AMD-SB-7061 listing Zen 1 through Zen 4 as affected; Intel does not consider a mitigation necessary on tested architectures. No CVE has been assigned and no kernel patch is available — the attack exploits the timing gap between branch predictor sanitization and the kernel’s use of the prediction. The Hacker News
Over 4,400 Rockwell PLCs Exposed Online; 22 Found in Cities Hit by Water Attacks
A Forescout snapshot on August 3 identified 4,407 internet-facing Rockwell/Allen-Bradley EtherNet/IP controllers, up from 4,148 in a Censys scan four days earlier. Nineteen of the 22 PLCs confirmed in cities targeted by coordinated water utility attacks ran firmware vulnerable to CVE-2017-16740, a Modbus TCP buffer overflow rated CVSS 8.6. The data follows CISA’s July 30 advisory urging water utilities to disconnect PLCs from the public internet immediately. The Hacker News
Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years in Prison
A federal judge in Alexandria, Virginia sentenced Belarusian national Maksim Silnikau to 16 years on August 5 for building and operating Ransom Cartel, the ransomware-as-a-service platform active between 2021 and 2023. Silnikau, known online as “J.P. Morgan,” purchased network access from brokers, supplied ransomware to affiliates, managed victim negotiations, and laundered payments through cryptocurrency mixers. The operation struck at least 18 companies in the United States and abroad. BleepingComputer
Canadian Hacker Connor Riley Moucka Pleads Guilty to Snowflake Data-Theft Campaign
Connor Riley Moucka, 26, of Kitchener, Ontario pleaded guilty on August 5 in U.S. District Court in Washington to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges. Moucka and co-conspirators used infostealer-sourced credentials to compromise at least 165 Snowflake customers — including AT&T, Ticketmaster, and LendingTree — and extorted more than $2.5 million in ransom payments. Sentencing is set for October 27; the aggravated identity theft count carries a mandatory two-year minimum and remaining counts add up to a maximum of 30 years. BleepingComputer
CISA Adds JetBrains TeamCity CVE-2026-63077 to KEV Catalog, Sets August 8 Federal Deadline
CISA confirmed active exploitation of CVE-2026-63077, a CVSS 9.8 deserialization flaw in JetBrains TeamCity On-Premises, and added it to the Known Exploited Vulnerabilities catalog on August 5. Federal agencies have until August 8 to remediate — an unusually compressed timeline. Organizations unable to upgrade to versions 2025.11.7 or 2026.1.3 can apply JetBrains’ security patch plugin; a successful exploit gives unauthenticated attackers remote code execution with TeamCity server privileges, exposing credentials, configurations, and CI/CD build artifacts. The Hacker News
Public PoC for Cisco IMC CVE-2026-20200 Grants Root Access to Servers
A proof-of-concept exploit named CIMCown appeared on GitHub after Cisco disclosed CVE-2026-20200, a CVSS 8.8 command injection flaw in the web-based management interface of Cisco Integrated Management Controllers. An attacker with low-privilege IMC credentials can send crafted HTTP requests to run operating system commands as root. The flaw was patched in Cisco’s August 5 advisory batch after being found during a commissioned security assessment by German firm NSIDE ATTACK LOGIC. Help Net Security
Samsung Bixby One-Click RCE Exploit Chain Detailed at Black Hat USA 2026
Researchers from Microsoft and Mobile Hacking Lab disclosed a multi-step exploit chain showing how a single link click can compromise Samsung Galaxy devices at system level. The chain exploits CVE-2025-58486 in Samsung Account to redirect the device to an attacker-controlled site, then uses CVE-2025-58487 — an XSS flaw — to force Bixby to execute attacker code with system-level privileges. The pair demonstrated the attack on a Galaxy S25 at Pwn2Own Ireland 2025, earning $50,000. SecurityWeek
CrowdStrike 2026 Threat Hunting Report: AI Now Embedded Across Adversary Operations
CrowdStrike’s annual Threat Hunting Report, released at Black Hat USA 2026, found AI-enabled cyber threats surged 89% in the first half of 2026, with attackers using large language models to generate payloads, phishing content, and reconnaissance scripts. Cloud-focused criminal activity jumped 171%, with one observed incident progressing from account takeover to data exfiltration in under five minutes. The report also found 88% of vulnerability attacks exploiting published proof-of-concept code began within 48 hours of PoC release, with China-nexus actors launching attacks within 24 hours. Help Net Security
Non-Human Identities Now Make Up 91% of Active Production Identities
ClearVector’s 2026 Identity Intelligence Report found nine in ten active identities in enterprise production environments belong to machines — service accounts, API keys, bots, and AI agents — rather than people. The finding highlights the identity governance gap in environments where most access is machine-to-machine and poorly inventoried. The report was released alongside Black Hat USA 2026. Help Net Security
Stay tuned for today’s in-depth analysis posts.






