Fake Crypto Extensions, NASA Flaws & AI Attacks on the Power Grid
Thursday, August 20, 2026 · 5-minute read
The U.S. Department of Justice charged 17 Iranians alleged to be members of a hacking-for-hire group called the Mabna Institute. The group is accused of stealing intellectual property from American universities, companies, and government organizations over several years. If the charges stick, this is one of the largest state-linked cyber-theft cases ever prosecuted.
↗ BleepingComputerCERT Polska — Poland's national cyber emergency team — is warning that attackers are actively exploiting a critical flaw in Zimbra Collaboration Suite. The bug lets an attacker run their own code on a vulnerable mail server without needing a password. Organizations still running unpatched Zimbra should treat this as urgent.
↗ BleepingComputerJapanese cloud and data center provider Sakura Internet confirmed hackers got into its sales management system, exposing customer contracts and membership details for up to 1.36 million accounts. Sakura is a major provider of web hosting and cloud services across Asia. If you've ever signed up for a Japanese web service, it's worth checking whether it runs on Sakura infrastructure.
↗ BleepingComputerU.S. cybersecurity agencies, including CISA, are warning that hackers are using AI-generated scripts to attack Siemens S7 Series programmable logic controllers embedded in critical infrastructure. These are the computers that physically control things like water pumps, electrical substations, and factory equipment. The concern is that AI is making it faster and easier for attackers — even less skilled ones — to write working exploit code targeting industrial systems.
An upgraded version of the ToxicPanda malware has ballooned from targeting 16 banking apps to 349 financial institutions across 16 countries. It abuses Android's accessibility services to read everything on your screen — including one-time codes and PINs — and can steal credentials from over 140 banking and crypto apps. A companion malware called GoldDigger is expanding the campaign's reach further.
Elementor Pro is one of the most popular WordPress page-builder plugins, used on millions of websites. This flaw lets anyone — no login required — upload a malicious PHP file to the server through the plugin's form file-upload feature. Once that file is on the server, the attacker can run any command they want on the site. In other words: full takeover, no password needed.
Status: Patch available — update Elementor Pro immediately. If you manage a WordPress site, this is a drop-everything update.
Researchers found a chain of flaws in AIT-GUI, the browser-based console operators use to send commands to NASA and JPL spacecraft and instruments. An unauthenticated attacker — meaning anyone who can reach the software over a network — could issue real commands to the spacecraft's command bus. Researchers put it bluntly: the damage here isn't a defaced webpage, it's misdirected spacecraft commands.
Status: Fixed in AIT-GUI version 2.5.2. Users on version 2.5.1 or earlier should update now. No CVE number has been assigned yet, but the advisory was published August 13.
MLflow is an open-source tool used by AI and data science teams to manage machine learning experiments. CISA added a critical MLflow vulnerability to its Known Exploited Vulnerabilities catalog today, meaning real attackers are already using it in the wild — not just in theory. Federal agencies have been ordered to patch, but any organization running MLflow should treat this as urgent.
Status: CISA has added this to its KEV catalog. Check MLflow's official channels for the latest patch and apply immediately.
A new free service called DecryptAds (decryptads.com), built by security researcher Zach Edwards and colleagues at Infoblox, lets anyone look up which ad companies and data brokers are collecting data from any website or mobile app. It does this by cross-referencing publicly available ads.txt and sellers.json files that websites are required to publish — files that are technically public but nearly impossible for a normal person to read. A quick search for espn.com, for example, reveals 143 ad partners and 19 data brokers, including four linked to Russia, China, or the UAE. The tool also flags ad partners based in countries considered geopolitical risks, and can help trace the source of malicious ads. It's genuinely useful for anyone who cares about privacy — not just security professionals.
↗ Krebs on SecurityIf you use a browser extension to manage a cryptocurrency wallet, today's story is for you. Researchers at Socket discovered 40 malicious Firefox extensions designed to steal crypto wallet secrets — and they were disguised as legitimate, well-known products like OKX, Rabby Wallet, and TronLink. The campaign, which researchers named Offside Wallet Theft Factory, has been running since at least March 2026.
Here's how the scam works. You search for a crypto wallet extension in the Firefox add-ons store. You find what looks like the real thing — correct name, similar logo, professional description. You install it. In the background, the extension waits. When you open your real wallet or type in a seed phrase or private key, the fake extension captures it and sends it to servers controlled by the attackers. Your funds are gone, often within minutes. The 40 confirmed malicious extensions all shared code and infrastructure, suggesting a single organized group behind the campaign. Another 37 extensions showed suspicious behavior but hadn't been confirmed as actively stealing yet.
For regular people, this is a reminder that browser extension stores — even from reputable browsers — are not perfectly policed. A lookalike extension is much harder to spot than a fake website, because it lives inside your browser and has access to everything you type and see. Crypto users are a particularly attractive target because stolen funds are almost impossible to recover.
Mozilla has been notified and is working to remove the extensions. In the meantime: check your installed Firefox extensions right now. If you have any crypto wallet extensions, verify you installed them from the official wallet developer's own website — not just the add-on store search results. And never, ever type your seed phrase into anything other than your physical hardware wallet or the official app you trust completely.