Top stories.
- Citrix urges immediate patching of two newly disclosed vulnerabilities.
- Supply chain attack compromises popular Rust library.
- US states sue Meta over claims that it deliberately addicts young users.
- Medusa ransomware affiliates have breached hundreds of critical infrastructure entities.
- General Electric, Philips, and Shell investigate alleged breaches.
- Latvian road traffic agency data breach affects two-thirds of the country's population./
Citrix urges immediate patching of two newly disclosed vulnerabilities.
Citrix is urging customers to immediately patch two vulnerabilities affecting NetScaler Gateway and ADC devices. One of the flaws (CVE-2026-19490) is a critical authentication bypass bug, while the other (CVE-2026-19489) is a high-severity memory overflow vulnerability. Citrix stated, "The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds."
While Citrix hasn't disclosed whether the flaws are being actively exploited, BleepingComputer notes that the company generally issues such urgent bulletins when it believes exploitation is imminent.
Supply chain attack compromises popular Rust library.
Threat actors inserted malicious code into two popular Rust crates after compromising a maintainer's account, BleepingComputer reports. The attackers poisoned arrayref, which has 244 million downloads, and append-only-vec, which has 4 million downloads. According to Aikido Security, "The attacker added a malicious dependency on a package called proc-macro1, which downloads a remote payload during the build and executes it on the developer's machine. Because the dependency runs at build time, simply compiling a project that pulls in either crate is enough to trigger the infection, with no need to call any of the crate's actual functionality."
Wiz notes that the campaign shows "significant overlap" with previous supply chain attacks that have been attributed to North Korean APTs.
US states sue Meta over claims that it deliberately addicts young users.
California, Colorado, Kentucky, and New Jersey are suing Meta for $200 billion, alleging that the company intentionally designed Facebook and Instagram to be addictive for children, the New York Times reports. The trial began this past week in the US District Court for the Northern District of California, and is expected to last six to eight weeks. Meta will argue that it was truthful to consumers and put safeguards in place to protect children.
The trial is the first bellwether in a series of Federal cases against the company, following several smaller losses by Meta this year involving personal injury cases and consumer protection violations. $200 billion would be the largest penalty in history for a tech company, amounting to nearly fourteen percent of the company's entire stock value.
Medusa ransomware affiliates have breached hundreds of critical infrastructure entities.
The US Cybersecurity and Infrastructure Security Agency (CISA) warns that Medusa ransomware-as-a-service affiliates have breached more than 500 entities in critical infrastructure sectors, including the medical, education, legal, insurance, technology, and manufacturing industries. In a joint advisory issued alongside the FBI and the US Department of Health and Human Services (HHS), the agency said Medusa actors "operate opportunistically by targeting victims with unpatched software rather than focusing on specific organizations or sectors," and "leverage vulnerability announcements, such as the February 2026 publication of BeyondTrust vulnerability (CVE-2026-1731), to identify CVEs to exploit."
Officials urge organizations to prioritize patching vulnerabilities, segment networks to limit lateral movement, require phishing-resistant multifactor authentication, and restrict remote access from untrusted sources.
General Electric, Philips, and Shell investigate alleged breaches.
General Electric, Philips, and Shell are each investigating claims of data theft by the Clop ransomware gang, BleepingComputer reports. Clop claims to have stolen project plans, photos of facilities, engineering drawings, diagrams, blueprints, software backups, and more. Phillips told Reuters, "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data. This has no impact on customer environments." A GE spokesperson said the company is "working to assess the potential issue," and Shell told BleepingComputer, "We are working with our security teams and relevant experts to investigate."
Clop listed the companies along with 40 other alleged victims that were likely breached via a critical remote code execution flaw (CVE-2026-12569) affecting Internet-exposed PTC Windchill and PTC FlexPLM instances. The flaw was patched in June, and the US Cybersecurity and Infrastructure Security Agency (CISA) said at the time that ransomware gangs were exploiting the vulnerability.
Latvian road traffic agency data breach affects two-thirds of the country's population.
Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a data breach affecting around two-thirds of the country's population, the Record reports. The cyberattack, which occurred over the weekend of August 8th, exposed information belonging to more than 1.2 million people and 200,000 businesses, dating back to 2008. Officials said the attackers gained access to systems containing personal or company identification numbers, vehicle license plate numbers, payment amounts and dates, and addresses associated with vehicle registrations.
The CSDD's supervisory board stepped down this week after parliament and Latvia's president called for their resignations. President Edgars Rinkevics said the attack posed "a significant threat to national security."