Here are today’s top cybersecurity stories for Friday, August 7, 2026.
18-Year-Old Linux SCTP Flaw Enables Root Access and Container Escape
Researchers at Tencent Zhuque Lab disclosed CVE-2026-64564, dubbed SCTPhantom, a use-after-free bug in the Linux kernel’s SCTP Dynamic Address Reconfiguration feature traced back to code introduced in December 2007. The flaw allows an unprivileged local attacker to gain full root and escape container isolation on affected systems including Debian 13, Ubuntu 24.04, Rocky Linux 9, and RHEL 9. Patches are available in stable kernel branches 6.6.148, 6.12.101, 6.18.42, and 7.1.6. The Hacker News
Zapscape KVM Flaw Lets Guest Virtual Machines Escape to the Host
CVE-2026-64561, named Zapscape, is a use-after-free vulnerability in KVM/x86 shadow MMU emulation affecting both Intel and AMD hosts with nested virtualization enabled. A privileged L1 guest exploiting the flaw breaks isolation and executes code on the underlying Linux host with kernel-level root privileges. A proof-of-concept exploit has been published, and the vulnerability affects Linux kernels from 2020 to 2026. The fix was merged on July 21 and followed a five-day coordinated embargo before public disclosure on August 6. The Hacker News
WordPress XSS2Shell: Pre-Auth Login Flaw Chains to PHP Code Execution
WordPress patched CVE-2026-64638 in version 7.0.3, released August 6, addressing a pre-authentication reflected cross-site scripting flaw in the login screen affecting every version of the CMS. Security researchers at pwn.ai demonstrated how the flaw chains into PHP remote code execution on the server when a logged-in administrator interacts with an attacker-controlled page. No active in-the-wild exploitation has been confirmed. Sites using automatic background updates should have received the patch automatically. The Hacker News
GitHub Issue Steals CI Secrets from Claude Code, Gemini CLI, and OpenAI Codex Pipelines
Novee Security presented research at Black Hat USA on August 5 showing how a single GitHub issue opened by an account with no repository privileges executes code on CI runners behind Anthropic’s, Google’s, and OpenAI’s own coding-agent repositories. Two CVEs were issued: CVE-2026-54316, a Hugging Face download-counter exfiltration channel affecting Claude Code from 0.2.54 to 2.1.162, patched in 2.1.163; and CVE-2026-12537 (CVSS 10.0), an OS command injection in the Gemini CLI container launcher via a crafted .gemini/.env file, patched in Gemini CLI 0.39.1. Neither CVE appears in CISA’s Known Exploited Vulnerabilities catalog as of August 7. The Hacker News
Microsoft 365 AitM Campaign Targets Payroll and Finance Email in Canada, US, and Europe
Cybersecurity researchers identified a widespread adversary-in-the-middle phishing campaign, tracked as Storm-2755 by Microsoft, targeting organisations in healthcare, education, manufacturing, government, and professional services across the United States, Canada, and Europe. Attackers route phishing links through a six-stage redirect chain using Google Meet, Google Ads infrastructure, and Amazon S3 to evade reputation-based filters, then harvest Microsoft 365 session tokens to access payroll and finance-related email. Residential proxies disguise malicious sign-ins, and compromised sessions are maintained at approximately eight-hour intervals. The Hacker News
Greatness PhaaS Adds Device Code Phishing to Its M365 Attack Toolkit
The Greatness phishing-as-a-service platform, sold for $289 per month via Telegram, has expanded its capabilities to include device code phishing alongside its existing adversary-in-the-middle and OAuth consent abuse modules, all from a single operator panel. The platform targets Microsoft 365 users in Canada, the United States, the United Kingdom, Australia, and South Africa. Defenders are advised to block device code authentication flows via Conditional Access Policies and migrate users to phishing-resistant MFA methods. BleepingComputer
UNC6671 Rebrands BlackFile Extortion Operation as Redact — and Three Other Brands
Google Threat Intelligence Group linked vishing extortion group UNC6671 to the rebrand of BlackFile into four simultaneous extortion brands: Redact, Pink, Falcon, and Helix. The group claimed an exiled affiliate hijacked the original BlackFile brand in May 2026 to sow confusion among threat intelligence analysts. UNC6671 received over $10 million in Bitcoin ransoms between January and May and continues targeting enterprise cloud environments through helpdesk impersonation calls routing victims through adversary-in-the-middle portals to steal credentials and MFA tokens. Google Threat Intelligence
Switzerland’s Federal IT Agency Confirms 200 Accounts Compromised in SharePoint Breach
Switzerland’s Federal Office for Information Technology, Systems and Telecommunication (FOITT) disclosed attackers exploited Microsoft SharePoint vulnerabilities to compromise approximately 200 accounts across its systems. The intrusion was detected on July 28, with credential theft confirmed on July 31. The agency believes the attackers leveraged CVE-2026-56164 or CVE-2026-50522, both addressed in Microsoft’s July Patch Tuesday updates. FOITT states no confidential data or sensitive personal information was stored on the affected platform. BleepingComputer
Beacon CRM Breach Exposes Data of 1,500 UK Charities
Beacon, a CRM platform widely used by UK charities, notified approximately 1,500 customer organisations: an unauthorized third party accessed its systems on July 29 using compromised credentials and likely downloaded database backups. Data affected includes supporter and donor names, addresses, email addresses, phone numbers, dates of birth, and donation records, with healthcare and victim support charities among those impacted. Beacon has reset all user passwords and advises customers to treat all stored data as potentially exfiltrated. The Register
Stay tuned for today’s in-depth analysis posts.






