Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Tuesday, August 25, 2026

Here are today’s top cybersecurity stories for Tuesday, August 25, 2026.

CISA Compares Defensive Outcomes From Two Parallel Red Team Assessments
CISA published advisory AA26-237A, comparing two organizations subjected to closely matched red team tradecraft, with sharply different detection results. In one engagement, the red team gained a foothold on several workstations, escalated privileges across the domain, and moved laterally into sensitive business systems and cloud resources without triggering an alert. The advisory sets out the specific detection gaps behind the outcome and recommends logging, segmentation, and monitoring changes for security teams. CISA

Mirage2FA Phishing Kit Hits Thousands of Microsoft 365 Accounts
Researchers tracked a surge in Mirage2FA, a commercial phishing-as-a-service kit operated by a group known as LinX Coders since September 2024, targeting Microsoft 365 login flows. The kit sits between a victim and the real Microsoft sign-in page, stealing passwords and active session cookies to bypass multi-factor authentication entirely. Of roughly 9,400 targeted addresses tracked, close to half ended in a successful compromise, with United States organizations accounting for the largest share of victims. The Hacker News

Researchers Find Thousands of Leaked AWS Keys Still Active Years Later
Truffle Security uncovered more than 64,000 exposed AWS key pairs across GitHub repositories, Hugging Face datasets, Docker images, and CI logs, with roughly 9,300 confirmed still valid as of early August. Hundreds of the working keys belong to identified companies, including 242 tied to accounts with full administrator access. Researchers found the vast majority of the exposed keys were never rotated after initial exposure, leaving the access open indefinitely. BleepingComputer

40 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Funds
Security firm Socket identified a network of 77 Firefox extensions tied to cryptocurrency theft, with 40 confirmed malicious and posing as wallet tools from OKX, Rabby Wallet, TronLink, and other Web3 brands. Roughly half present a convincing wallet interface asking users to import an existing wallet, harvesting whatever recovery phrase gets entered, while others quietly forward stored wallet data to remote servers. Mozilla signing records show activity dating back to March, with a peak in late July. The Hacker News

New ShieldBreak Exploit Claims to Bypass Patched Microsoft Defender Flaw
The threat actor behind the Nightmare Eclipse leaks published a proof-of-concept exploit dubbed ShieldBreak, claiming to grant SYSTEM-level access on machines running a patched version of Microsoft Defender. Microsoft assigned the underlying issue CVE-2026-69414, rated 7.8 on the CVSS scale, and researchers are still confirming the extent of the bypass. The release adds to a pattern of Defender privilege-escalation disclosures from the same group throughout 2026. SecurityWeek | The Hacker News

Apple Patches iCloud Private Relay Flaw Exposing Users’ Real IP Addresses
Apple fixed a flaw in iCloud Private Relay allowing certain WebKit proxy configurations to leak a user’s real IP address despite the privacy feature staying active. The bypass undermined the core promise of Private Relay, which hides browsing traffic and location from network operators and websites. Apple confirmed a patch addresses the issue, with no evidence of exploitation reported before the fix. The Hacker News

Flaw in NVIDIA NemoClaw Lets a Web Page Poison Locally Running AI Models
Researchers disclosed a vulnerability in NVIDIA’s NemoClaw framework allowing a malicious web page to tamper with AI models running locally on a user’s machine, altering model behavior without the user’s knowledge. NVIDIA has not confirmed exploitation in the wild as of this writing. The disclosure adds to a growing list of security gaps found in tooling supporting locally deployed AI models. The Hacker News

WhatsApp Adds Multiple Passkeys and Stronger Two-Step Verification
WhatsApp rolled out account security updates allowing users to register more than one passkey, useful for people running the app across both iOS and Android devices, alongside a strengthened two-step verification flow and added caller context features. The changes give users more flexible recovery options if a single device is lost or replaced. SecurityWeek

SANS Researchers Flag Hostname-Based Scans Targeting Cloud Metadata Services
The SANS Internet Storm Center documented scanning activity using hostnames instead of raw IP addresses to reach the cloud metadata service at 169.254.169.254, an address commonly targeted in server-side request forgery attacks. Because most software accepts a hostname anywhere it accepts an IP address, the technique gives attackers a way around defenses filtering only on IP address. Security teams should extend SSRF protections to cover hostname-based requests. SANS Internet Storm Center

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.