Here are today’s top cybersecurity stories for Thursday, August 13, 2026.
White House Authorizes Private Firms to Conduct Offensive Hack-Back Operations Against Cybercriminals
President Trump signed a National Security Presidential Memorandum on August 12 creating the first formal U.S. program allowing vetted private security firms to conduct offensive cyber operations against foreign cyber-enabled transnational criminal organizations. The Department of Justice and Department of Homeland Security will jointly run the program through a new National Coordination Center, and companies must receive written, per-operation approval before acting against a specific target. Firms operating without such approval remain subject to the Computer Fraud and Abuse Act. SecurityWeek | BleepingComputer
Attackers Exploit Adobe Commerce Account Takeover Flaw Within Hours of Patch Release
Adobe patched CVE-2026-71362, a CVSS 9.1 unauthenticated account takeover vulnerability in Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9, as part of its August 2026 security update (APSB26-92). The flaw allows an attacker to switch a customer session into another shopper’s account without credentials or user interaction, exposing private customer data. Security firm Sansec observed exploitation attempts within hours of the patch’s release and is blocking them through its Shield web application firewall. BleepingComputer | Sansec
Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe’s August 2026 security update addressed three maximum-severity vulnerabilities across ColdFusion and Campaign Classic, alongside the Commerce account takeover flaw released the same day. Adobe has not confirmed exploitation of the ColdFusion and Campaign Classic issues but urges administrators to apply patches without delay given the severity ratings. The Hacker News
New NatJack Attack Class Hijacks TCP Sessions and Spoofs DNS Across 32 Products
Researcher Malcolm Stagg disclosed NatJack at Black Hat USA 2026, a new attack class manipulating NAT connection-tracking state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Testing found vulnerable behavior across 32 products and configurations, including routers, firewalls, cloud services, container platforms, and hypervisors, spanning independently developed Windows and Linux implementations. A related flaw in Windows NAT used by Hyper-V is tracked as CVE-2026-56181 with a CVSS score of 8.3. The Hacker News
Jewelbug APT Runs Nation-State Espionage and Cryptocurrency Fraud From a Single Platform
Symantec identified a China-based threat group tracked as Jewelbug, also known as Earth Alux, running espionage campaigns against government and military targets across the Middle East, Southeast Asia, and South Asia alongside a for-profit cryptocurrency theft operation, both administered from a single browser-hijacking control panel named XG-Web. The group’s victim database includes more than 1 million implant check-ins, 580,000 stolen browser cookies, and 2,300 exfiltrated email bodies. Dark Reading
Cloudflare Report Shows DDoS Attacks Above 1 Tbps Surged Fivefold in Q2 2026
Cloudflare’s H1 2026 DDoS Threat Report recorded 805 network-layer DDoS attacks exceeding 1 Tbps in the second quarter, a 519 percent increase over the first quarter, and 935 such attacks for the half-year overall. The report attributes the surge to DNS flood techniques and geopolitical tensions, while noting most network-layer attacks remain under 500 Mbps and end within 10 minutes. Help Net Security
WordPress 7.0.4 Patches Authenticated Remote Code Execution Flaw
WordPress released version 7.0.4, addressing CVE-2026-65640, a CVSS 8.8 vulnerability allowing an authenticated attacker with contributor-level access or higher to execute arbitrary code on affected sites. Site administrators are advised to update immediately given WordPress’s broad footprint across small business and nonprofit websites. SecurityWeek
Wireshark 4.6.8 Fixes 28 Security Bugs, Nine in File Parsers
The Wireshark project released version 4.6.8, resolving 28 bugs with security implications, nine of which affect file parsers used to read captured network traffic. The update addresses crash and denial-of-service conditions triggered by malformed capture files. Users are advised to upgrade before analyzing untrusted packet captures. Wireshark Foundation
WhatsApp Rolls Out On-Device Scam Alert Feature
WhatsApp began rolling out an optional Scam Alert feature using a local, on-device machine learning model to flag messages showing signs of common scam patterns, without sending message content to WhatsApp’s servers. The feature targets impersonation scams, fake job offers, and financial fraud attempts delivered through chat. BleepingComputer
Chrome Extension Banned for Stealing AI Chat Data Returns to Chrome Web Store
A browser extension previously removed from the Chrome Web Store for harvesting user conversations with AI chatbots has reappeared under a new listing and resumed its data-collection activity. Google has not commented publicly on how the extension bypassed store review a second time. SecurityWeek
Stay tuned for today’s in-depth analysis posts.






