Security news weekly round-up - 21st August 2026

Security news weekly round-up - 21st August 2026

安全新闻周报 - 2026年8月21日

Cybersecurity is everyone’s business as long as you use the internet in one form or the other. Your job might be to develop the next cutting-edge security tools, raise people’s cybersecurity awareness, and so on. And, in some cases, resolve to physically damage your infrastructure to stop an intrusion or minimize the impact. The list can go on. The point is to do your best wherever you might find yourself. 只要你以某种形式使用互联网,网络安全就与每个人息息相关。你的工作可能是开发下一代尖端安全工具、提高人们的网络安全意识等等。在某些情况下,甚至可能需要通过物理手段破坏基础设施来阻止入侵或将影响降至最低。这样的例子不胜枚举。重点是,无论你身处何处,都要尽你所能。

Windows 11’s strongest security defenses can be bypassed without a screwdriver. The title got me laughing. Still, do not panic. The attack assumes some level of access to the Windows 11 device, and Microsoft shipped mitigations as part of this year—2026—updates back in April. All in all, you should be interested in what happened and how the attack worked. For that, read the excerpt below. Windows 11 最强的安全防御无需螺丝刀即可被绕过。这个标题让我笑了。不过,请不要惊慌。该攻击假设攻击者已经对 Windows 11 设备拥有一定程度的访问权限,且微软已在今年(2026年)4 月的更新中发布了缓解措施。总而言之,你应该关注发生了什么以及攻击是如何运作的。为此,请阅读以下摘录。

…the team demonstrated they could reach into parts of the system Windows is built to keep off-limits, including memory the operating system itself is not supposed to touch. By creating these memory aliases, the researchers showed an attacker could: Turn hundreds of blocklisted drivers with known vulnerabilities back on; Kill antivirus and endpoint detection and response (EDR) software. ……研究团队证明他们可以进入 Windows 系统设计为禁止访问的部分,包括操作系统本身不应触及的内存区域。通过创建这些内存别名,研究人员展示了攻击者可以:重新启用数百个已知存在漏洞的黑名单驱动程序;关闭杀毒软件和端点检测与响应(EDR)软件。

How QR-code phishing can slip past corporate security measures. If you’re comfortable using something every day, don’t rule out that it can’t be turned against you. That’s why you should never let your guard down. This is an example of such a scenario. Scan QR codes out of necessity alone, if it’s in an email, use another medium to check with the sender if they actually sent it, and never stop learning how cyber criminals are innovating ways to steal from you. 二维码钓鱼如何绕过企业安全措施。如果你习惯于每天使用某样东西,不要排除它被用来对付你的可能性。这就是为什么你永远不能掉以轻心。这就是此类场景的一个例子。仅在必要时扫描二维码;如果二维码出现在电子邮件中,请通过其他渠道与发送者核实他们是否真的发送了该邮件,并不断学习网络犯罪分子如何创新手段来窃取你的信息。

From the article: Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security. One important advantage for the attacker is concealment. The destination is encoded in a visual pattern, not displayed as readable text, which hides the malicious URLs behind them. 文章摘录:最重要的是,它们将受害者从相对保护良好的企业环境引导至可能不受管理的移动设备,从而绕过了企业级安全防护。攻击者的一个重要优势是隐蔽性。目标地址被编码在视觉图案中,而不是以可读文本形式显示,这隐藏了其背后的恶意 URL。

T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network. If a keyboard is not available to stop them, take the device offline. From the article: After identifying the breach, T-Mobile’s cybersecurity chief, Jeff Simon, told Bloomberg that he and three others drove to the data center nearby to its Bellevue, Washington headquarters, found the compromised system, pulled out a set of scissors, and snipped the cable connecting the box to the outside world. T-Mobile “剪断电缆”以将中国黑客驱逐出其网络。如果无法通过键盘阻止他们,那就让设备离线。文章摘录:在发现入侵后,T-Mobile 的网络安全主管 Jeff Simon 告诉彭博社,他和另外三人驱车前往位于华盛顿州贝尔维尤总部附近的数据中心,找到了受损系统,掏出一把剪刀,剪断了连接该设备与外部世界的电缆。

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data. One of the key things that aided the success of this attack was outdated software. It was discovered that one of the compromised websites was running a WordPress version from 2021. Here are more details: The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders. This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. StopAndProtect 利用近 2000 个被黑的 WordPress 网站传播恶意软件并窃取数据。促成此次攻击成功的关键因素之一是软件过时。据发现,其中一个受损网站运行的是 2021 年版本的 WordPress。更多细节如下:感染链始于 ClickFix 社会工程学攻击,导致 PowerShell 命令执行,进而部署额外的 .NET 下载器和加载器。随后,这引出了主要组件,包括勒索软件、SMB/USB 蠕虫、锁屏程序、VBS 传播器、聊天工具和凭据窃取程序。

AI is making fraud harder to spot and identity harder to prove. No surprises on this one. From the article: AI makes digital scams easier to create and harder to identify. Criminals can imitate emails, messages, websites, documents, voices and customer support interactions. These scams can appear legitimate enough to persuade people to share information, send money or provide account access. A fraudulent payment or account change may be the final step in a longer chain of deception. AI-generated phishing is a leading concern for businesses, alongside document forgery, automated bot attacks and synthetic identities. 人工智能使欺诈行为更难被发现,身份也更难被证明。这一点并不令人意外。文章摘录:人工智能使数字诈骗更容易制造,也更难识别。犯罪分子可以模仿电子邮件、信息、网站、文档、语音和客户支持互动。这些诈骗看起来非常合法,足以说服人们分享信息、汇款或提供账户访问权限。欺诈性支付或账户更改可能是一个更长欺骗链的最后一步。人工智能生成的钓鱼攻击是企业面临的主要担忧,此外还有文档伪造、自动化机器人攻击和合成身份。

Grok exfiltrates user data when malicious instructions are encrypted. This raises a question: when the engineers were building the guardrails, did they take this into consideration? I mean, think of the following: Adversa can’t be sure what causes Grok to refuse precisely the same plaintext instructions and follow the encrypted ones. The leading theory is that the Grok filtering guardrail inspects text entering and leaving the model, but not the output of its own code execution. 当恶意指令被加密时,Grok 会泄露用户数据。这引发了一个问题:工程师在构建护栏时,是否考虑到了这一点?我的意思是,考虑以下情况:Adversa 无法确定是什么原因导致 Grok 拒绝完全相同的明文指令,却执行了加密指令。目前的主要理论是,Grok 的过滤护栏会检查进入和离开模型的内容,但不会检查其自身代码执行的输出。

Researchers find a loophole that lets expired credit cards make unauthorized payments. On the list of things that should not be possible, this should make the cut. Here is what happened: Credit card accounts don’t expire along with the physical card, so a return still gets refunded even after the purchasing card has expired. That’s what led Muhammad Taqi Raza, assistant professor in the Riccio College of Engineering at UMass Amherst, to ask: “If the card can get a refund, can the card make a payment?” Working with Raja Hasnain Anwar and Gerard DeCunha, Raza found the answer is yes for at least some cards. The researchers describe it as a gap between systems that each assume someone else already checked whether the card should still work. 研究人员发现了一个漏洞,允许过期的信用卡进行未经授权的支付。在“不应该发生的事情”清单中,这绝对榜上有名。事情是这样的:信用卡账户并不会随着实体卡的过期而失效,因此即使在购买卡过期后,退款仍然可以完成。这促使马萨诸塞大学阿默斯特分校 Riccio 工程学院的助理教授 Muhammad Taqi Raza 提出疑问:“如果卡可以退款,那么卡可以进行支付吗?”在与 Raja Hasnain Anwar 和 Gerard DeCunha 的合作下,Raza 发现对于至少部分卡片来说,答案是肯定的。研究人员将其描述为系统之间的鸿沟,每个系统都假设其他人已经检查过该卡是否应该仍然有效。

Credits: Cover photo by Debby Hudson on Unsplash. That’s it for this week, and I’ll see you next time. 鸣谢:封面照片由 Debby Hudson 在 Unsplash 上提供。本周内容就是这些,我们下期再见。