Cybersecurity threats this week highlight a surge in social engineering, legacy credential exploitation, and the weaponization of routine productivity tools to bypass traditional enterprise security defenses.
Key Points
- Cloudflare introduced the Private Access Control Token (PACT) protocol to help browsers verify human users without relying on invasive tracking or traditional captchas.
- A critical unauthenticated remote code execution flaw (CVE-2026-50160) in the Hoppscotch API platform allowed attackers to gain full server control via mass assignment vulnerabilities.
- Research from Spur Intelligence found that over 34% of apps on LG and Samsung smart TVs contain proxyware that can relay third-party traffic through home networks.
- Two members of the Scattered Spider criminal collective were convicted for a 2024 cyberattack on Transport for London that resulted in $38.2 million in losses.
- Threat actors are increasingly using Microsoft 365 collaboration features, such as shared group mailboxes and calendar invites, to conduct sophisticated phishing campaigns.
- Censys identified 8,500 global REDCap research servers, which have been targeted by the China-nexus group UNC6508 to exfiltrate sensitive clinical and military data.