Fire Ant Hackers Hijack Cisco Routers to Spy on Networks
Routers rarely get attention. They sit in racks, push traffic, and run untouched for years at a time. That quiet reliability is exactly what Fire Ant hackers learned to exploit, because a compromised router watches everything and raises no alarm. Investigators recently unpicked a Chinese espionage operation that turned Cisco networking gear into long-term surveillance equipment. The group has moved

Claude Session Hijacking: Malware Drains Paid AI Accounts
Anthropic has started emailing Claude users with an unwelcome message. Malware sitting on their own computers stole active login sessions. Attackers then used those sessions to sign in and drain the usage that victims had paid for. This wave of Claude session hijacking did not begin with a flaw in the AI platform, because it began on the victim's own

Carhartt Data Breach Exposes 12.9 Million Accounts
Millions of people who once ordered a jacket or a pair of work pants now have a security problem on their hands. The Carhartt data breach has pushed personal details from more than 12.9 million customer accounts onto a dark web leak site, and the exposed records go well beyond email addresses. Names, phone numbers, and home addresses sit in

Zimbra Server Attacks Hit 274 Systems as Patching Lags
Hundreds of email servers around the world now sit under attacker control. A scan on August 22 found 274 compromised Zimbra instances, and the Zimbra server attacks behind that figure have not slowed down. A patch for the underlying flaw arrived back in July. Yet thousands of systems still run vulnerable code, so the window for exploitation stays wide open.

Operation Jackal IV: 58 Arrests in Global Fraud Takedown
Police forces in 22 countries have closed one of the biggest fraud investigations of the past year. Operation Jackal IV ran from November 2025 through June 2026, and it ended with 58 arrests. Investigators also identified 263 more suspects tied to cybercrime networks run by West African organized crime groups. INTERPOL coordinated the work, and the results open a rare

MoYu Proxy Botnet Hijacks Android Car Head Units
A car's touchscreen looks harmless. It plays music, shows maps, and handles the climate controls. But researchers have now found malware that turns those screens into infrastructure for online crime. They traced the campaign to MoYu, a threat group that runs a proxy botnet built from hijacked consumer devices. This time the target was the Android head unit sitting in

ToxicPanda Android Malware Blocks Google Play Via VPN
A banking trojan aimed at Android phones has returned with a much sharper set of tools. The ToxicPanda Android malware now asks victims to approve a VPN connection, then uses that access to cut the phone off from Google Play. Once that link goes dark, the device loses the checks that would normally catch a threat like this. Security scans,

Claude AI Watermarking: How Anthropic Will Tag Its Text
Anthropic has revealed how it plans to mark the text Claude produces, and the method avoids the usual tricks. Claude AI watermarking runs during generation rather than after it, so nothing attaches to the finished response. The technique draws on Google DeepMind's SynthID-Text research, and it leaves a statistical trail instead of a visible one. This matters because machine-written text

Evooo1Bot Botnet Hijacks Routers to Relay Criminal Traffic
A new strain of Linux malware has been turning routers into relay points for criminal traffic. Researchers call the threat Evooo1Bot. The Evooo1Bot botnet has been active since at least July. It hunts for internet-facing gateway devices. Then it turns each one into a SOCKS5 proxy node. The owner keeps browsing as normal. Meanwhile, someone else's traffic leaves the same

Trezor Data Breach Exposes Nearly 14,000 Crypto Customers
Crypto owners buy hardware wallets so their private keys never touch the internet. That logic still holds. Yet the Trezor data breach exposed personal details for nearly 14,000 customers. Attackers never came close to the devices themselves. Instead, they walked in through a shipping company. The hardware wallet maker confirmed the incident on August 13, 2026, after its logistics partner
