# This Week in Cybersecurity: Week 34

> Week 34: 14,500 hijacked Dahua cameras, a Rust crate with 245M downloads poisoned, WhatsApp device-linking abuse, and a CVSS 10.0 that needed nobody at all.

By Marcus · August 23, 2026 · 10 min read · Weekly

Source: https://bluwarden.com/blog/this-week-in-cybersecurity-2026-w34

---

Week 34's clearest lesson came from a Rust package with 245 million downloads. Someone slipped a malicious build script into it, and simply *compiling* a project that depended on it was enough to run the payload. Nothing in your own code had to call anything. It was live for 86 minutes.

Closer to home, researchers documented 14,530 Dahua security cameras taken over between June and July, concentrated in Ukraine and Russia. Nearly 2,000 of them fell to authentication-bypass flaws with patches available since 2021 - a five-year-old fix that nobody applied, on devices that watch people's doors.

This roundup covers **Monday 17 to Sunday 23 August**. What needs your attention first, then the week's biggest stories whether or not you're exposed - each with an honest line on who actually is - then things worth knowing about.

---

## What to act on

### Check which devices are linked to your WhatsApp

Three suspected Russian clusters are running a campaign that [abuses Google OAuth and WhatsApp's device-linking feature](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html). The WhatsApp technique is the one worth understanding: a phishing page asks for your phone number, the attacker triggers a genuine device-link request, and you are shown a **real** QR code and linking code from WhatsApp itself. Approve it and their device is attached to your account.

The OAuth variant works similarly. You click "Continue with Google", authenticate on Google's actual page, and get redirected to attacker infrastructure running a script that lifts the authentication token out of the URL.

Neither exploits a vulnerability. Both abuse features working exactly as designed, which is why there is nothing for Google or Meta to patch and why the usual "look for the fake login page" advice fails - the login page is real.

**What to do:** in WhatsApp, open Settings, Linked Devices, and log out anything you do not recognise. Do it now and periodically after. The rule to internalise: a legitimate service will never walk you through linking a device or reading back a code during a conversation it initiated. That is the same structural tell behind most [smishing](/blog/smishing-anatomy-phone-protection) - the request itself is the giveaway.

**Honest scope:** the observed targeting is academia, aerospace and defence, governments and think tanks across Europe, the US, Ukraine and Armenia. If you are not in that set you are unlikely to be a target today, but the technique is cheap and will be copied.

### 14,530 Dahua cameras were taken over, and 2,000 fell to a 2021 patch

Between 17 June and 22 July, an operation researchers call CameraSwarm [compromised over 14,530 Dahua cameras and NVRs](https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html), heavily concentrated in Ukraine and Russia. Three routes in: credential attacks from 12,324 unique IPs, authentication bypasses via **CVE-2021-33044** and **CVE-2021-33045** on 1,923 devices, and abuse of the serial-number P2P relay to reach 283 cameras sitting behind NAT. Researchers assess with moderate confidence that part of the toolkit was built to hand camera access to a third party.

The P2P detail is the one people miss. "It's behind my router, it's fine" stops being true when the vendor ships a relay service whose entire purpose is punching through NAT for you.

**What to do:** update the firmware from Dahua's site, turn off P2P if you do not use it, replace default and reused credentials, and put cameras on their own network segment away from laptops and phones. Fixes for those two CVEs have existed for five years, which is the whole argument of our piece on [the EU Cyber Resilience Act](/blog/cyber-resilience-act-what-changes) - published support periods only help if somebody installs what gets published.

### Rust developers: check your Cargo cache

Three crates were poisoned on 20 August, including **arrayref 0.3.10** - 245.4 million downloads all-time, 53.9 million in the preceding 90 days, and 403 other crates depending on it. Also hit: `internment 0.8.7` and `append-only-vec 0.1.9`.

The mechanism deserves attention. The compromised versions [added a dependency on `proc-macro1`](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html), a typosquat of the real `proc-macro2`, and the malicious code lived in that dependency's *build script*. Building a project that resolved it was enough to execute the payload - "nothing from the crates themselves had to be called." The stage-two implant read Chrome, Brave and Edge login databases straight out of SQLite, established persistence, and accepted remote commands.

They were pulled within 86 to 107 minutes and there is no evidence of successful exploitation. But a 90-minute window on a dependency that popular is a lot of CI runs.

**What to do:** search `~/.cargo/registry/cache` for the pulled versions and pin `arrayref` at 0.3.9 or earlier. If you find them, treat browser credentials on that machine as compromised and rotate.

---

## The week's biggest

### A CVSS 10.0 in Entra ID that required nothing from anyone

**CVE-2026-69836** is a deserialization flaw in Microsoft Entra ID scored 10.0, allowing an unauthorised attacker to execute code over a network. It was [initially flagged as exploited in the wild](https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html), and Microsoft later corrected that: it was not. Microsoft fixed it service-side, and "there are no additional actions customers need to take."

Worth pausing on, because this is what a 10.0 looks like when the system works. Maximum severity, cloud-hosted, patched centrally, corrected disclosure. It generated a great deal of alarm and required nothing of anybody.

**Who's exposed:** organisations using Entra ID, in theory. Nobody, in practice. There is no action item here and we are not inventing one.

### GitLab exploited within days, and the window keeps shrinking

**CVE-2026-19478** (CVSS 9.4) lets unauthenticated attackers modify or delete public GitLab projects, delete repositories outright, forge merge records and ban maintainers. watchTowr [reproduced it within minutes of disclosure and then observed live exploitation against its honeypots](https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html) within days. Patched in 19.2.4, 19.1.6, 19.0.8 and 18.11.11.

Their framing is the part to remember: "AI-enabled attackers are able to compress the time from disclosure to exploitation." [Last week](/blog/this-week-in-cybersecurity-2026-w33) GeoServer was attacked within hours of its patch. This week it was GitLab. That is now the baseline assumption, not the alarming exception.

**Who's exposed:** internet-facing self-managed GitLab instances. GitLab.com users are not the target here, and if your code lives on GitHub this is somebody else's morning.

### Cisco shipped five 10.0s in one release

Cisco patched [nine flaws across Crosswork and Secure Workload, five of them scored CVSS 10.0](https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html). No exploitation reported at release.

**Who's exposed:** network operators running Cisco's orchestration and workload-security platforms. Not consumer Cisco kit, and nothing on a home network.

### One click could drain your Copilot's connected apps

Researchers disclosed **CVE-2026-24301**, nicknamed CoSnitch, in **Copilot Personal** - the consumer assistant at copilot.microsoft.com, not Microsoft 365 Copilot. [A single click on a crafted link](https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html) silently pulled data from whatever the session could reach: mail bodies and metadata, calendar entries with attendees and locations, Google Drive file names, full chat history, and the memory store of saved instructions. Closing the tab did not stop it - "the prompt runs to completion even if the victim closes the Copilot tab immediately after the page loads."

Reported to Microsoft in December 2025, patched 18 August 2026, no evidence of exploitation.

**Who's exposed:** anyone who connected mail or Drive to consumer Copilot - but it is already fixed, so nothing to do. The durable lesson is that every app you connect to an AI assistant widens what one bad link can reach.

### Malware is now shipping through car head units

Researchers found malware distributed [through the built-in update mechanism of Android head units running DoFun firmware](https://thehackernews.com/2026/08/android-car-malware-spreads-through.html) - the screens in the dashboard, both factory-fitted and aftermarket. A system app called TWCore pulled APKs via a compromised MQTT broker, delivering a dropper for ad fraud and a reverse-proxy module that enrols the car into a proxy botnet.

The update channel itself was the delivery mechanism, which is the part worth sitting with: the thing designed to keep the device current was the thing that infected it.

**Who's exposed:** owners of DoFun-based head units specifically, not every Android-powered car. The distribution abuse has been fixed following disclosure, no device count was published, and there is no owner-side action offered - which is its own commentary on how patching works for a screen bolted into a dashboard.

### Week 34's critical CVEs

| Identifier | Product | Exploited? | Patch |
|---|---|---|---|
| CVE-2026-19478 | GitLab (self-managed) | Yes, honeypot-confirmed | Yes |
| CVE-2021-33044 / -33045 | Dahua cameras | Yes, 1,923 devices | Yes, since 2021 |
| CVE-2026-69836 | Microsoft Entra ID | No, initial report corrected | Fixed service-side |
| CVE-2026-24301 | Copilot Personal | No | Yes, 18 Aug |
| 5 x CVSS 10.0 | Cisco Crosswork / Secure Workload | No | Yes |
| arrayref 0.3.10 | Rust crates.io | No evidence, 86-min window | Pulled |

---

## Worth knowing about

**TikTok settled a children's privacy case for $400 million.** The [US Department of Justice and FTC alleged "massive-scale invasions of children's privacy"](https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html) under COPPA: letting under-13s create accounts, collecting data from users in Kids Mode, and failing to honour parental deletion requests. $300 million is payable now, $100 million on vacating a prior consent decree. Affected families receive nothing directly - the money goes to the government, which is worth noticing whenever a privacy fine is reported as a win for users.

**The supply-chain attacks were not limited to Rust.** The same week brought [14 trojanised npm packages](https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html) dropping a Linux backdoor, and [16 typosquatted RubyGems](https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html) harvesting browser credentials and crypto wallets. Three ecosystems in seven days, all going after developer machines rather than production. A developer laptop holds credentials to everything, which is the pattern behind most of the incidents in [what actually breaks company security](/blog/what-actually-breaks-company-security-2026).

**A hardware wallet vendor leaked customer data.** SafePal disclosed that a flaw [exposed information belonging to nearly 40,000 customers](https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html). Wallet funds were not affected, but a confirmed list of people who own crypto hardware is precisely the targeting data phishing crews want. Expect tailored lures to that list, and treat any "SafePal security notice" in your inbox with suspicion.

**Someone is extorting ransomware victims twice.** A group calling itself Ransom Busters [claims to have hacked ransomware operators' servers](https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html) and is now asking victims for up to $60,000 - to delete data the original attackers stole. Whether or not the claim is genuine, it is a new position in the extortion market: the people who supposedly rescued your data want paying too.

---

## Summary

1. **Check WhatsApp's Linked Devices list** and remove anything unfamiliar. Attackers are getting people to approve genuine device links.
2. **If you run Dahua cameras, patch the firmware and disable P2P.** Two of the flaws being used were fixed five years ago.
3. **Rust developers: check `~/.cargo/registry/cache`** and pin `arrayref` at 0.3.9 or earlier.
4. **Three things worth remembering:** the disclosure-to-exploitation window is now hours or days and shrinking, developer machines are the current supply-chain target across every package ecosystem, and a CVSS 10.0 can still be nobody's emergency.

Two stories this week ended with "nothing for you to do" - the Entra ID 10.0 and the Copilot flaw - and both were fixed before most people heard of them. That is the system working. The ones that actually cost people something were older and duller: a five-year-old camera patch nobody applied, and a phishing call convincing someone to press Approve.

---

*Want to know which of this week's flaws touch what you actually run? [Get in touch](/#contact) - the bluwarden team can map your stack against what's genuinely being exploited.*

*This roundup is general information, not a substitute for a vulnerability assessment of your own environment. Severity and exploitation status change quickly; check vendor advisories for the current position before acting on anything here.*
