CFToday Curated security signals.

Daily edition · 2026-08-31

Monday, 31 August 2026

60 items across 9 sections, selected from 4515 candidates over 6 runs. 111 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. Meta removes ads for fraud apps posing as porn after India sounds alarm (opens in a new tab)

    Economic Times Tech ·Business & Boardroom ·fetched 31 Aug 2026, 19:43 UTC agreed3/3

    Why readIndia's government forced Meta to pull dozens of Facebook and Instagram ads pushing banking-credential-stealing Android apps disguised as porn apps, in a market that lost roughly $2.4bn to cyber fraud in 2025.

    Meta removed dozens of ads after India's government flagged campaigns running under names such as "Night Play" and "Kyss" that used sexually explicit creative to drive users to phishing sites and malicious Android APKs capable of draining bank accounts. Government data puts India's 2025 cyber-fraud losses at close to $2.4 billion, tied to the growth of digital payments. The signal for leaders is platform ad networks being used as the malware distribution channel and a regulator willing to name specific campaigns and compel takedowns.

  1. Popular code generator for TanStack Query hit by supply chain worm (opens in a new tab)

    Aikido Security ·fetched 31 Aug 2026, 11:41 UTC Must read Research agreed3/3

    Why readA live self-propagating npm compromise in a package pulling 150,000 weekly downloads, with the malicious version window narrow enough to scope quickly.

    Aikido detected TeamPCP-style malware in ten versions of @7nohe/openapi-react-query-codegen, a TanStack Query hook generator, all published to npm inside a 20 minute span. The payload identifies itself as "Trinitite: Sponsored by Preview 2 Effects" and earlier variants shipped a script named is_it_this_simple.js. The timing lands a day after arrests of TeamPCP members in Australia, leaving open whether this is a copycat, an operator who avoided arrest, or an unrelated actor; either way, teams should check lockfiles for the affected versions and rotate any credentials exposed to CI installs.

    Indicators13
    Hashes
    ec7876d6c917dad516ba69bbfafc948b834bf0ab 365d4eb738d3146583431948d3ba6e27a32556be 8e5d1af68ca340ae0c6e8132cb00c686ec2d60502c1994d94ce353d1472ad5a3 b49afb7dba04cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d6 59370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380 778d6f0058045d6a2ab9a7e1d3e3be8e7e6b4d9cc217d13949bf1dfbab759a7c b24d121667f21f492cb9db34fbfd515d5922a8dd30b9c45215c7220abbb10ca8 e1f1162ece9a6e6ea21a20399cbf31c563a8149d433a68711f4223870c203d5a b6012b2ff87f08f93ee53921c48db907ddbcf5461b03bb988083b01a36886237 709af2fdeb50324229e94c44c679a0fab18bd8e17d3864405989c526cbb63ad8
    Domains
    registry[.]npmjs[.]org upload[.]pypi[.]org rubygems[.]org
  2. CISA confirms hackers targeted over 100 US water systems during July (opens in a new tab)

    TechCrunch Security ·Zack Whittaker ·fetched 31 Aug 2026, 07:40 UTC Must read agreed3/3

    Why readCISA puts a number on the water sector intrusion wave: more than 100 internet-exposed systems, mostly PLCs.

    CISA's advisory confirms attacks against over 100 exposed systems in the US water and wastewater sector during July, widening the picture beyond the previously reported incidents in Michigan, Minnesota and at least five other states. The targeting centers on programmable logic controllers from Rockwell, Schneider Electric and, more recently, Siemens, with CISA noting that some of the activity uses AI tooling to build scripts against vulnerable Siemens devices from public information. Operational impact on water service has so far been limited, but the count establishes this as broad opportunistic scanning of exposed OT rather than a handful of isolated events.

  3. Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode (opens in a new tab)

    Check Point Research ·fetched 31 Aug 2026, 15:42 UTC Must read Research agreed3/3

    Why readA fully static deobfuscation pipeline for compiled V8 bytecode, released as a tool, plus the recovered internals of the JSCeal stealer.

    Check Point rebuilt JSCeal's payloads, shipped as compiled V8 bytecode (JSC files) and protected with javascript-obfuscator using RC4 string encryption, control-flow flattening, proxy functions and operation wrappers. The pipeline transforms View8 pseudocode without executing the sample, with an optional LLM-assisted renaming pass for navigating large recovered codebases, and the toolkit is public as jsc_deobfuscator. The deobfuscated output documents keylogging, browser and credential theft, and HTTPS interception via a local MITM component, and gives a reusable method for anyone facing JSC-packed JavaScript malware.

    Indicators12
    Hashes
    e27ae65977287bdfb7b0e15fd3603f85 0d1fce0cb2b9dec26a10f0822aeffb19 581e2e2265d0c1509b3799c5a9039374 de10c6b3dc4619f59bc9c80a0aa15e6a 03f4e47b9c2283c32bb8f8f042ce6e41 de213ebc44c614d0b2324787e267183dbbbbb19e1ad866435a322ee00e24e7b6 c77b3b7a507162bfc03cfeb8ef18d5ee7017e8fcbd6d7e005f986a3c967b8d45 0b8015cbb1ffdc6efe6a306ff5b1115f 4757f3d26bc7110e9c7f4da8050afc2ed661cd92aec9cf7d301d9b9b24e0b668 b90e3aaae14e7787e5ea4a6d4beee672049bd5eb05427f2c80b64f605860d2b8 1026743185dfa10e9ddc21b5a4c578d5 212d21ed1c4b5bd9b9104e04f2876842b99cd17def3591df72781891d584dca0
  4. Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams (opens in a new tab)

    Unit 42 ·Noam Sala ·fetched 31 Aug 2026, 11:41 UTC Must read Research agreed3/3

    Why readBreaks down a Teams-based vishing operation that hit 150+ employees at 10 companies, escalating in one variant from help desk impersonation to an NTLM relay against the domain controller.

    Between January and April 2026, external Microsoft Teams accounts posing as internal IT help desk staff opened chats that converted into voice calls, during which operators talked victims into running RMM tooling or custom malware. Unit 42 tracks this as Spring Ring and documents two campaigns with distinct delivery vectors, the more advanced ending in an NTLM relay attack aimed at an organisation's DC. The obvious control is restricting external Teams federation and alerting on unsolicited external chats followed by RMM execution.

    Indicators3
    Hashes
    24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b
    Domains
    onmicrosoft[.]com san-sid[.]com
  5. Chinese Fire Ant hackers turn Cisco routers into spying platforms (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 31 Aug 2026, 15:42 UTC agreed3/3

    Why readConcrete hunt criteria for Fire Ant on Cisco IOS XR: a live GRE tunnel interface that matches neither the running configuration nor the commit history, plus an implant that only runs during alternating hours.

    Sygnia found the China-nexus actor Fire Ant shifting from VMware hypervisors to Cisco routers, TACACS authentication servers and Linux management hosts. On an IOS XR router the responders found an unexplained active GRE tunnel interface, custom malware persisting via a fake system service that executed only during alternating hours, selective syslog suppression to hide tunnel-related messages from administrators, outbound Telnet to actor infrastructure and unlogged interactive shell access. Network teams should diff running interfaces against configuration and commit history rather than trusting device logs, which this implant edits.

    Also covered byThe Hacker News (opens in a new tab).

  6. The Video That Plays You: Fake MP4 File Carries Malicious Payload (opens in a new tab)

    Censys ·Kate Lake ·fetched 31 Aug 2026, 19:43 UTC Research agreed3/3

    Why readA NetSupport RAT delivery chain that hides 6.5 MB of encrypted payload inside an ISO BMFF uuid extension box, so the carrier passes basic MP4 file-type checks while being unplayable.

    Censys ARC observed a Cloudflare-fronted host on 22 August 2026 serving raw PowerShell as text/html over port 80. The loader checks the computer name against two hard-coded sandbox-detection values (variations on "clean") and exits if matched, hides its console, decodes a base64 second stage, then fetches a fake MP4 from the same host; the encrypted NetSupport client executable and configuration sit in a uuid extension box inside that file. The magic-bytes-versus-playability gap is a usable detection idea: flag MP4s whose atom structure carries multi-megabyte uuid boxes.

  7. Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem (opens in a new tab)

    Group-IB ·fetched 31 Aug 2026, 11:41 UTC Research agreed3/3

    Why readFirst analysis of BraZetsu, a modular Python Windows framework built for initial access brokers, attributed to the Brazilian actor Exilware and calibrated against Iberian and Latin American corporate, financial and law enforcement targets.

    BraZetsu is not a conventional infostealer but a toolkit that turns a compromised host into a packaged, sellable asset for initial access brokers, with deep host reconnaissance feeding an AI-enhanced underground marketplace. Group-IB attributes it with high confidence to Exilware and notes a modular architecture plus stealth techniques that left some samples fully undetected on VirusTotal at analysis time. Regional targeting is explicit, which makes it a scoping question for anyone with Iberian or LatAm operations.

    Indicators18
    Hashes
    f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8
    Addresses
    38[.]242[.]246[.]176
    Domains
    caixaentradas1inboxshop[.]site caixaentradas1boxshop[.]site infect[.]online c2[.]installscenter[.]com installscenter[.]com
  8. Microsoft warns of TerminalFix attacks deploying reverse tunnels (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 31 Aug 2026, 19:43 UTC agreed3/3

    Why readTerminalFix pushes victims into Windows Terminal rather than the Run dialog, so a single clipboard paste executes a multi-line script that ends in a reverse tunnel into the internal network, not just an infostealer.

    Microsoft observed in-the-wild attacks using fake Cloudflare CAPTCHA prompts on compromised sites to get victims to paste a preloaded PowerShell command into Windows Terminal, which downloads a ZIP and runs a multi-stage chain. The end state is a reverse tunnel giving attackers network-level access rather than the credential theft typical of ClickFix. No hands-on-keyboard activity was seen yet, but the access is a natural precursor to lateral movement, tool tampering and ransomware. Detection teams monitoring only explorer.exe-spawned Run-dialog patterns will miss the Windows Terminal variant.

    Indicators1
    Domains
    gitnow[.]dev
  9. Password spraying campaign targets AWS root user accounts across 150+ organizations (opens in a new tab)

    Datadog Security Labs ·fetched 31 Aug 2026, 19:43 UTC Research agreed3/3

    Why readTelemetry-backed account of a month-long password spraying campaign against AWS root user accounts at more than 150 organisations, with the timing profile and infrastructure characteristics defenders can check their own CloudTrail against.

    Datadog Security Research tracked repeated failed root-user authentication attempts from July 24 to August 23, 2026, with a median of two attempts per organisation and up to eight for some, spread across countries and industries with no clear victimology. Requests arrived through proxies with source IPs flagged as hosting infrastructure or residential proxies, using a small set of stale user-agent strings including Chrome/85.0.4183.83 Edg/85.0.564.41 and Firefox/120.0. No successful authentication was observed, so credential source and intent remain unknown; the actionable response is confirming root MFA, alerting on ConsoleLogin failures for the root principal, and treating low-volume-per-tenant spraying as easily lost in noise.

  10. US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate (opens in a new tab)

    TechCrunch Security ·Zack Whittaker ·fetched 31 Aug 2026, 03:42 UTC agreed3/3

    Why readNames the Chinese company behind an operational relay network rented to MSS operators, which is the part of the China intrusion ecosystem defenders rarely get attributed in public.

    The Justice Department seized domains used to command a botnet of thousands of compromised internet connected devices, attributed to a group tracked as QTFY and operated by Nanjing Xinjiuwei Network Tech. The botnet functioned as an obfuscation layer, laundering operator traffic so intrusions at hospitals, defence contractors and federal agencies including NASA, the Justice Department and the Senate appeared to originate from ordinary hosts. Prosecutors describe QTFY as a commercial provider selling access to customers that include Ministry of State Security hackers, with activity dating back years.

  11. ValleyRAT masquerading as adware (opens in a new tab)

    Securelist ·Pavel Bukhtenko ·fetched 31 Aug 2026, 11:41 UTC Research agreed3/3

    Why readA signed adware installer (MD5 c24e99f9437feacaa63766a3cde3fe3d) whose ad functionality does not even work turns out to be a ValleyRAT delivery chain.

    A sample submitted for classification looked like ordinary adware and was initially filed as such, until anomalous network activity prompted a deeper look; the advertising code is non-functional and the installer exists to launch an infection chain ending in the ValleyRAT backdoor. The developer signature on the adware, plus the habit of users adding such programs to exclusions, is what makes the disguise effective. A useful argument against blanket PUA exclusions in endpoint policy.

    Indicators2
    Hashes
    c24e99f9437feacaa63766a3cde3fe3d
    URLs
    hxxps://qnwallpaper[.]keansoft[.]cn

    Also covered byCybersecurity News (opens in a new tab).

  12. Fire Ant Evolves: From Hypervisors to Trusted Infrastructure (opens in a new tab)

    Sygnia ·Sygnia ·fetched 31 Aug 2026, 07:40 UTC Research agreed3/3

    Why readChina-nexus actor Fire Ant has moved from ESXi and vCenter persistence into Cisco IOS XR routers, authentication systems and Linux management hosts, which changes where you look for it.

    Fire Ant, first documented in 2025 for deep persistence inside virtualization infrastructure, remained active through 2026 and expanded into the trusted infrastructure layer: routers, authentication systems and Linux management hosts used to collect credentials and traffic and to reach connected high-value environments. The blog abstract is thin on artefacts, but the pivot from hypervisor to network and identity plane is the operationally useful claim. Companion press release covers the same findings; the research post is the one to read.

    Indicators11
    Hashes
    c164bfc953c66e58b11fc280e69fd43b8f255839 1aa6ab2006b5d9199aa87bb0bbd995aec698ac4f 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00 955cd45a2f6f226a2fdf44b329af1c8dde90cb38 13f0c2a598e3aa63856c032a96b110aed963f0e8 5ba1242050b5b447052b210788a5a25593d6987d 7dab017f14628345d47bd4eb69cc49224f3054a7 be6b27f429324a4af05a310d8ec9635e37c68a94 1682b652a15bde732489f22809b0b7594c228fd3 b149fa3a34bd585e7a674a4fd9538437bd06f514 6ef7d2985edf743ebff413a9298a127e9475d72f
  1. PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE (opens in a new tab)

    Huntress ·fetched 31 Aug 2026, 23:38 UTC Must read Research agreed3/3

    Why readPre-auth RCE in PaperCut NG and MF is being exploited in the wild, with a full chain reproduced against version 25.0.11.75758 and emergency patches out for majors 24, 25 and 26.

    PaperCut's August 27 advisory confirms active exploitation of a pre-authentication remote code execution flaw in PaperCut NG and MF, with confirmed customer incidents. Huntress observed exploitation in two customer environments, where activity was limited to system discovery with no secondary malware, C2 or persistence recovered, and independently reproduced a full pre-auth RCE chain against a vanilla NG 25.0.11.75758 server. Emergency patches exist for majors 24, 25 and 26; patched or not, the recommendation is to pull the application server off the public internet and restrict access to trusted networks.

  2. PaperCut issues emergency patches as threat actors target chained vulnerabilities (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 31 Aug 2026, 19:43 UTC Must read agreed3/3

    Why readTwo chained PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, give unauthenticated full compromise and are already being used against customers.

    PaperCut shipped emergency patches Friday for an improper access-control bug in PaperCut MF and NG (CVE-2026-81578) that lets an unauthenticated attacker change system configuration, and an unsafe dynamic class loading bug (CVE-2026-82078) that executes arbitrary Java bytecode. Huntress and watchTowr are working with the vendor after multiple confirmed customer compromises; Huntress describes chaining the pair as point-and-shoot full compromise requiring no credentials. Two observed cases were early-stage reconnaissance, so the window before mass exploitation is short and PaperCut has a history of being ransomware-adjacent.

  3. CVE-2026-82078: PaperCut NG/MF, PaperCut NG/MF Unsafe Reflection Vulnerability (opens in a new tab)

    CISA KEV ·fetched 31 Aug 2026, 19:43 UTC Must read CVE-2026-82078 Exploited in the wild · patch by 2026-09-14 EPSS 0.5% agreed3/3

    Why readPaperCut NG/MF unsafe reflection bug is now in KEV with a 2026-09-14 federal deadline, and it chains with CVE-2026-81578 for unauthenticated RCE on the print server.

    CVE-2026-82078 lets an attacker manipulate PaperCut system configuration parameters and execute arbitrary Java bytecode already on the application classpath, running under the PaperCut server process identity. CISA lists it as exploited with a remediation date of 14 September 2026 under BOD 26-04, and notes it chains with the missing-authentication flaw CVE-2026-81578, which supplies the unauthenticated entry point. PaperCut has a long history as a ransomware entry vector, so internet-exposed instances should be patched or pulled off the edge now; EPSS is still low at 0.0046 but KEV membership is the stronger signal here.

    Indicators14
    Hashes
    5c63ef18c523c85d5e73efc7fbb2bd2edacf0b03bcf80fe4d7e4c1a7c8bcbcf4 6117b53dd0610052c53aeafced91cd3d0ad80ed1dcc578e873291a8b697b802a 7dea84473f8d00d4608b7e797b633f130139e23bf5bba02848a1df0a7e2cc7c6 b296de7da020152a83291378ab4ca5c461d76510648347fd6e69f3fb2cd5e9c9 296498ef5ec1ac8927dc1ccae9a9aa3c04036da6d2768813e6df818049b3f4a1 3e5509f0514228031967934d32e4a40512bd6fb5857bfde3002866bc3ede3f9a 75aba456d6629848c89513371c44037f2bdddbc1e39bdadc16d1fed8b59766eb 7ac8f002fb602d1f54665d8a18a25fc57cf41239ae0c03b18591ee220b57d419 40581392cc11a1f46b90ab5c2607fdacade77aca0de6629c1d78a2a71548fc9c c9a2b356910b5fef3c114d48cb7c508414d1d35ddac74c530d1e8923d357e7d4 3261356ced056fd5ab0962a07178701e80c6ebbce30d7158d20ed3c57b1dcf59 bdd54d5cb9f20924b059986a44f849df499f7de7cb5cd0a60290d2b2610850e7
    URLs
    hxxps://sendit[.]sh/Gg7Rp/ace[.]exe hxxps://download[.]anydesk[.]com/AnyDesk[.]exe
  4. More Details Emerge on Exploited PaperCut Vulnerabilities (opens in a new tab)

    SecurityWeek ·Eduard Kovacs ·fetched 31 Aug 2026, 07:40 UTC Must read CVE-2026-82078 EPSS 0.5% agreed3/3

    Why readTwo PaperCut NG/MF zero-days, not one, are being exploited for unauthenticated RCE, and a second emergency patch was needed to cover version 24.

    PaperCut shipped an initial emergency patch on August 28 for versions 25 and 26, then a second the same day adding hardening and coverage for version 24. Huntress and WatchTowr established that two flaws are in play rather than one: CVE-2026-81578, a high-severity authentication bypass permitting configuration changes by an unauthenticated remote attacker, chained toward remote code execution alongside CVE-2026-82078. IoCs are published, so exposed print servers should be patched and hunted rather than just patched.

  5. CVE-2026-81578: PaperCut NG/MF, PaperCut NG/MF Missing Authentication for Critical Function Vulnerability (opens in a new tab)

    CISA KEV ·fetched 31 Aug 2026, 19:43 UTC CVE-2026-81578 Exploited in the wild · patch by 2026-09-14 EPSS 0.5% agreed3/3

    Why readThe unauthenticated half of the PaperCut chain: missing authentication on a critical config function, KEV-listed with a 2026-09-14 due date.

    CVE-2026-81578 allows an unauthenticated remote attacker to modify certain PaperCut NG/MF system configurations. On its own that is a configuration-tampering bug, but chained with CVE-2026-82078 it gives a full path from no credentials to arbitrary Java bytecode execution as the PaperCut server process. CISA added it to KEV on 31 August 2026 with a 14 September remediation deadline; treat any internet-facing PaperCut instance as a priority patch.

    Indicators14
    Hashes
    5c63ef18c523c85d5e73efc7fbb2bd2edacf0b03bcf80fe4d7e4c1a7c8bcbcf4 6117b53dd0610052c53aeafced91cd3d0ad80ed1dcc578e873291a8b697b802a 7dea84473f8d00d4608b7e797b633f130139e23bf5bba02848a1df0a7e2cc7c6 b296de7da020152a83291378ab4ca5c461d76510648347fd6e69f3fb2cd5e9c9 296498ef5ec1ac8927dc1ccae9a9aa3c04036da6d2768813e6df818049b3f4a1 3e5509f0514228031967934d32e4a40512bd6fb5857bfde3002866bc3ede3f9a 75aba456d6629848c89513371c44037f2bdddbc1e39bdadc16d1fed8b59766eb 7ac8f002fb602d1f54665d8a18a25fc57cf41239ae0c03b18591ee220b57d419 40581392cc11a1f46b90ab5c2607fdacade77aca0de6629c1d78a2a71548fc9c c9a2b356910b5fef3c114d48cb7c508414d1d35ddac74c530d1e8923d357e7d4 3261356ced056fd5ab0962a07178701e80c6ebbce30d7158d20ed3c57b1dcf59 bdd54d5cb9f20924b059986a44f849df499f7de7cb5cd0a60290d2b2610850e7
    URLs
    hxxps://sendit[.]sh/Gg7Rp/ace[.]exe hxxps://download[.]anydesk[.]com/AnyDesk[.]exe

    Also covered byNVD (opens in a new tab).

  6. Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 31 Aug 2026, 11:41 UTC agreed3/3

    Why readCVE-2026-66066 in Ruby on Rails, CVSS 9.5, is now being exploited in the wild with public PoC code available.

    VulnCheck reports active exploitation of KindaRails2Shell, an arbitrary file read in Rails that escalates to secret exposure, RCE and lateral movement. The bug stems from a content-type parsing mismatch: Rails trusts the client-supplied content type when interpreting a blob as an image while libvips reads magic bytes instead. Applications using libvips for Active Storage image processing that accept uploads from untrusted users are the exposed set; patches shipped in late July and Rails has published forensic tooling to detect exploitation attempts.

  7. CERT-FR News Bulletin CERTFR-2026-ACT-037 (opens in a new tab)

    translated Bulletin d'actualité CERTFR-2026-ACT-037 (31 août 2026)

    CERT-FR (ANSSI) ·fetched 31 Aug 2026, 15:42 UTC agreed3/3

    Why readCERT-FR's weekly bulletin flags two vulnerabilities as already exploited, in Gitea (GHSA-rcr6-4jqh-j84m) and Ajax.NET Professional, the latter tied to a CISA KEV entry.

    The 31 August roundup prioritises last week's significant vulnerabilities and marks specific entries "Exploitée": a Gitea advisory and an Ajax.NET Professional issue whose fix is a single upstream commit (b0e63be), cross-referenced to the CISA Known Exploited Vulnerabilities catalog. It also pulls in PaperCut's urgent 27 August security bulletin, Metabase advisory GHSA-r8h2-qpfx-mx59 and Cisco's IOS XE hardening advisory. Self-hosted Gitea and legacy ASP.NET applications using Ajax.NET Professional are the ones to look at first.

    Indicators8
    Hashes
    b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 93ce93587d36493f2f86921fa79921b3cba63fbb 14200d435af9a9eeb444f529fc2f689a236b7962 46f201f8b4c39633a1fa3dc12459f506d470993d 6374fb9edf72c67a118a2c214a0dddd04c921e0a 65fb14cbebb0cd0eff903a22d33537ddc8b95769 736b380e28d0480c7bc3e022f1950f31fe53a7c5 e9eacf19281ea2498b36291b56c9606118c2d74e
  8. Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 31 Aug 2026, 11:41 UTC CVE-2026-82222 EPSS 0.4% agreed3/3

    Why readCVE-2026-82222 (CVSS 10.0) is an unauthenticated PHP object injection in GiveWP chainable to RCE, and on 4.16.5.1 and below a default install with one published donation form is enough to exploit.

    Patchstack disclosed on 28 August after Udin Chan reported the bug on 28 July; GiveWP shipped 4.16.7.2 on 27 August, and everything through 4.16.7.1 is affected. No account, no test mode, no open registration and no user interaction are required, because the plugin ships with an active manual (Test Donation) gateway and an active offline gateway by default. EPSS is still low at 0.004, but an unauthenticated command execution path in a widely installed donation plugin is a same-week patch.

    Also covered byNVD (opens in a new tab).

  9. ServiceNow Patches 3 Critical Code Injection Vulnerabilities (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 31 Aug 2026, 19:43 UTC agreed3/3

    Why readThree unauthenticated CVSS 10.0 flaws in the ServiceNow AI Platform, including an SQL injection, with CVE ids to track against your instance version.

    ServiceNow shipped fixes for four bugs, three of them rated 10.0 and none requiring authentication. CVE-2026-18885 permits arbitrary code execution on the platform, CVE-2026-18886 is an improper access control issue allowing data creation or modification and privilege escalation, and CVE-2026-74820 is an SQL injection against the underlying database. No exploitation is reported yet, but unauthenticated maximum-severity bugs in a platform holding CMDB and workflow data are a short-fuse patching item.

  10. CVE-2026-82329 (CVSS 9.8): JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to (opens in a new tab)

    NVD ·fetched 31 Aug 2026, 19:43 UTC CVE-2026-82329 CVSS 9.8 EPSS 0.4% agreed3/3

    Why readDefault-configuration unauthenticated admin on an artifact repository is a direct path into everything your pipelines build and ship.

    JFrog Artifactory contains an authentication weakness that, in the default configuration, can grant administrative privileges to an unauthenticated attacker with network access. Artifactory holds signing material, deployment credentials and the binaries downstream builds trust, so admin there converts into package tampering across every consumer. The advisory text gives no version boundaries or mechanism, which means the immediate action is confirming your deployment's exposure and configuration rather than waiting for a clean patch matrix.

  11. Traefik | Version Through 3.7.11 (opens in a new tab)

    Bishop Fox ·fetched 31 Aug 2026, 23:38 UTC Research agreed3/3

    Why readTraefik's HTTP/3 server was built with no timeout at all, so the default 60-second read timeout never applies and an unauthenticated client can pin upstream connections open indefinitely.

    Bishop Fox found that Traefik's documented request read timeout is implemented as a deadline on the underlying TCP connection, which HTTP/3 does not use; the HTTP/3 server was constructed without any timeout, so the setting has no effect on that protocol. An unauthenticated remote user can hold requests open indefinitely, consuming one upstream connection per request until legitimate traffic is denied. Affects versions 2.8.2 through 2.11.55 and 3.0.0 through 3.7.11, which covers most container and Kubernetes ingress deployments running HTTP/3.

  12. CVE-2026-19286 (CVSS 9.8): IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on (opens in a new tab)

    NVD ·fetched 31 Aug 2026, 19:43 UTC CVE-2026-19286 CVSS 9.8 EPSS 0.6% agreed3/3

    Why readPre-authentication code execution on a Langflow endpoint that is public by design, in a product class that gets scanned and mass exploited quickly.

    IBM Langflow OSS 1.0.0 through 1.11.1 fails to enforce security restrictions on the A2A public endpoint, giving a remote attacker arbitrary code execution with no credentials. This is the more urgent of the two Langflow issues published today because the vector is PR:N against an endpoint intended to be reachable. The NVD text carries no technical detail, so the actionable content is the affected range: inventory Langflow deployments, confirm whether A2A is reachable, and patch or block it at the edge.

  1. REPLICANT: Learning Policies for Evading and Hardening Malware Detectors (opens in a new tab)

    arXiv cs.CR (all) ·Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia, Alexander Herzog ·fetched 31 Aug 2026, 11:41 UTC Research agreed3/3

    Why readA reinforcement learning agent that evades Android malware classifiers under a label-only black box, with no access to training data, feature space or confidence scores, hitting a 78.8% mean success rate across seven detectors.

    Replicant learns a reusable policy for how to mutate a sample and when to query the target, and that policy transfers across samples, detectors and three feature spaces rather than being refit per target. The 20.9% to 39.2% relative improvement over prior work matters mainly because the threat model is the realistic one: an attacker who only sees a verdict. Used for adversarial training it also produces detectors with more generalisable robustness, so it cuts both ways for anyone shipping ML-based detection.

  2. ATM Flaws Reveal Key Weaknesses in the Software Supply Chain (opens in a new tab)

    WIRED Security ·Lily Hay Newman ·fetched 31 Aug 2026, 11:41 UTC agreed3/3

    Why readNine now-fixed flaws in CryptWare's CryptoPro Secure Disk allowed bypassing integrity checks and pre-boot authentication to reach fully encrypted devices, including Diebold Nixdorf Vynamic ATMs.

    Matt Burch presented five years of ATM security work at Black Hat and Defcon, centred on pre-boot authentication and disk encryption software rather than the ATM stack itself. The bypasses defeat CryptoPro's integrity checking and grant full access to encrypted disks. The broader point is reach: CryptoPro is sold as a general endpoint encryption product, so the same weaknesses land in organisations that have never thought about ATM security. WIRED's coverage summarises the talk rather than the technical detail, so chase the original slides for exploitation specifics.

  1. BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence (opens in a new tab)

    arXiv cs.CR (AI) ·Changze Li, Yutong Cheng, Tsania Camila Finnisa, Qian Cui ·fetched 31 Aug 2026, 19:43 UTC Research agreed3/3

    Why readShows how mapping report behaviors to MITRE ATT&CK gives you a join key for merging threat reports that call the same actor by different names.

    BEACON is an LLM pipeline that builds a knowledge graph per CTI report, then reconciles graphs across sources by anchoring contextual entities and indicators to the ATT&CK techniques a report describes. The claimed novelty is the cross-source setting: prior work extracts within a single report, so nothing resolves the naming collisions that make multi-vendor CTI aggregation painful. Treat it as a design worth borrowing rather than a validated tool; the interesting part is the choice of behavior as the canonical space, not the extraction stage. Filed under defense rather than AI security because the problem it solves is a CTI operations problem.

  2. EncryptedSharedPreferences is Dead: Here’s What You Should Use Instead (opens in a new tab)

    Include Security ·jacobholcombinclude ·fetched 31 Aug 2026, 15:42 UTC agreed3/3

    Why readAndroid developers relying on EncryptedSharedPreferences now need a replacement, and this sets out what to use and why file-based encryption plus sandboxing does not make on-disk secrets safe.

    With EncryptedSharedPreferences deprecated, the post argues against persisting sensitive data to disk at all, and treats Android's file-based encryption and process isolation as insufficient mitigations rather than substitutes. The specific claim worth acting on is that assuming those OS protections are enough is what drives regressions back into plaintext or weakly protected storage, with forensic recovery as the concrete exposure.

  3. Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off (opens in a new tab)

    CSO Online ·fetched 31 Aug 2026, 23:38 UTC agreed3/3

    Why readMicrosoft Defender Antivirus now falsely reports itself as turned off on any Windows or Windows Server build running the latest Defender updates, so help desks should expect the tickets and analysts should not treat the alert as real.

    Microsoft's release health dashboard confirms that after installing recent Microsoft Defender Antivirus updates, notifications may claim the antivirus is turned off while it is functioning and all settings show it active. The notifications appear at Windows start and intermittently after, and persist even when notification settings are disabled; the issue spans any Windows or Windows Server version with current Defender updates. No fix date is given, and the practical cost is that users learn to dismiss security alerts.

  4. Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM (opens in a new tab)

    arXiv cs.CR (all) ·Pietro Tiberi, Gabriele Marcelli, Vitangelo Lasorella ·fetched 31 Aug 2026, 07:40 UTC Research agreed2/3

    Why readA concrete, implemented design for keeping transaction confidentiality on a shared ledger while leaving the accountability trail regulators require.

    The authors build a confidential interbank settlement protocol on Hyperledger Besu with QBFT, using Groth16 proofs over BN254, Poseidon commitments in an incremental Merkle tree, multi-recipient ECIES payload encryption and an append-only on-chain note registry. Their relaxed anonymity model deliberately keeps the sending institution publicly identifiable while hiding recipient, amount and business payload, which sidesteps the usual AML and CFT objection to shielded transfers and removes the need for trusted off-chain custody servers. Narrow audience, but a good reference point for anyone designing selective disclosure into a permissioned chain.

DFIR

3
  1. Belkasoft X 2.12 Introduces Offline Translation For DFIR Investigations (opens in a new tab)

    Forensic Focus ·Belkasoft ·fetched 31 Aug 2026, 15:42 UTC agreed3/3

    Why readBelkasoft X 2.12 adds BelkaGPT offline translation of chats, SMS and artifact text in 100+ languages, running entirely on the examiner workstation so evidence never leaves the machine.

    The 2.12 preview brings local, on-device translation to Belkasoft X via BelkaGPT, covering chat threads, SMS and artifact text across more than 100 languages. Keeping translation off cloud services matters for chain-of-custody and for cases where sending evidence text to a third-party API is not permissible. The announcement is a preview with no benchmark of translation quality on forensic text.

  2. So Your CFO's Phone Has Been Pwned: A DFIR Journey (opens in a new tab)

    Censys ·Kate Lake ·fetched 31 Aug 2026, 23:38 UTC agreed3/3

    Why readMobile incident response methodology for the case everyone dreads, with a workable framing: pivot from whatever thin IOC you get (an APK, a clicked SMS URL, a 30-second IP contact) into internet infrastructure context.

    Argues that mobile IR is structurally different from laptop IR because visibility is thinner and the device roams across corporate Wi-Fi, LTE, hotel and home networks, so the interesting artefact is often a single URL or a brief outbound connection. Once a public network IOC exists, the author applies the standard investigative questions against internet-scan data to establish what the infrastructure is and who else touched it. Written from the Censys angle and the piece leans on their data, but the artefact-scarcity framing for executive phone compromise is usable regardless of tooling.

  3. Doxxing Safety Part II: Incident Response (opens in a new tab)

    EFF Deeplinks ·Daly Barnett ·fetched 31 Aug 2026, 19:43 UTC agreed3/3

    Why readA response playbook for the moment someone is already being doxxed, with the specific artifact to start with: a running incident log of times, platforms and accounts.

    EFF's followup to its digital footprint cleanup guide reframes the same OSINT tooling for use during an active harassment campaign rather than before one. The core practice is an incident log, kept plainly, recording when and where harmful activity appeared and who was involved, which is what later platform reports, restraining orders and law enforcement referrals actually depend on. Worth reading in advance and keeping bookmarked, and worth handing to journalists, moderators and at risk staff you support.

  1. Recognition Without Enforcement: Configuration-Dependent Failures in LLM Agent Instruction Arbitration and External Control (opens in a new tab)

    arXiv cs.CR (AI) ·Jun Wen Leong ·fetched 31 Aug 2026, 07:40 UTC Must read Research agreed3/3

    Why readMeasures across 46 model endpoints from 6 vendors that LLM agents can linearly decode and verbally identify forged instruction authority and still execute the attacker's tool call, and shows configuration rather than model weights decides whether they do.

    Identifies a recognition-enforcement gap: source-format features such as role-template position and channel metadata are linearly decodable from activations, and models will name forged authority when asked, yet permissive configurations still produce the conflicting tool call. A fleet evaluation covering authority spoofing across 46 endpoints and memory conflict across 48 models puts average execution under diverse novel attacks at 1.21% (0.5-2.1% clustered CI), with particular prompt-model pairs failing deterministically. The practical consequence: restrictive policies and prompt diversity eliminate execution on the same models, so agent trust boundaries are a deployment configuration problem, not a weights problem.

  2. The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st) (opens in a new tab)

    SANS ISC Diary ·fetched 31 Aug 2026, 23:38 UTC Must read Research agreed3/3

    Why readAn inference honeypot was rebranded with popular model names and pulled into a "free LLM backend" service, then received a real coding-agent session complete with its local tool manifest.

    An internet-exposed inference honeypot was discovered, relabelled with sought-after model names, and incorporated into infrastructure advertising free LLM backends. It then received a genuine coding-agent session, leaking conversation history, filesystem output, working paths and the agent's tool manifest to an operator the client had never verified. The point is the rogue model endpoint as a class: an agent arriving with its own file-read, file-write and shell tools will act on whatever the server's replies ask for, so the endpoint, not the API key, is now the thing worth stealing.

  3. CamoDocs: A Poisoning Attack Against Retrieval-Augmented Language Models Using Camouflaged Documents (opens in a new tab)

    arXiv cs.CR (AI) ·Jaewon Jung, Haizhong Zheng, Hongsun Jang, Jaeyong Song ·fetched 31 Aug 2026, 23:38 UTC Must read Research agreed3/3

    Why readA RAG poisoning attack that drops the target query from the malicious document entirely, defeating the query-overlap filters most current defences rely on.

    CamoDocs chunks synthesized benign and adversarial drafts together, swaps selected tokens in the benign chunks for dispersion tokens that spread the poisoned document's embeddings, and applies coherence filtering so readability survives. Because the target query is never inserted, the lexical and embedding artefacts that existing detectors key on are absent. Evaluated across seven RAG defences, three open-weight LLMs and three benchmarks, with an average 61.80% attack success rate reported against proprietary models.

  4. LongPIBench: A Long-Context Benchmark for Prompt Injection (opens in a new tab)

    arXiv cs.CR (AI) ·Yupei Liu, Yuqi Jia, Neil Zhenqiang Gong, Jinyuan Jia ·fetched 31 Aug 2026, 11:41 UTC Must read Research agreed3/3

    Why readShows that current prompt injection defences are substantially overrated because they are benchmarked on short contexts, and that simple heuristic attacks bypass state-of-the-art defences once context stretches to tens of thousands of tokens.

    LongPIBench evaluates injection across four applied scenarios (paper peer review, resume screening, code review, email summarisation), each with a synthetic and a real-world dataset, at context lengths from thousands to tens of thousands of tokens. Defences that score well on short-context benchmarks fail here, and even unsophisticated injections achieve high success rates. If you are relying on a published defence for a long-context RAG or document-processing pipeline, this is the evaluation that says re-test it.

  5. CVE-2026-55245 (CVSS 8.7): Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go (opens in a new tab)

    NVD ·fetched 31 Aug 2026, 11:41 UTC CVE-2026-55245 CVSS 8.7 EPSS 0.4% agreed3/3

    Why readThe specific list of IP ranges Bifrost misclassified as public is a usable checklist for anyone writing SSRF filters, and the entry point is an ordinary multimodal image URL.

    Bifrost's isPublicIP check, reached when the gateway fetches Bedrock or Vertex image and document URLs, treats Carrier-Grade NAT 100.64.0.0/10, 6to4 2002::/16, NAT64 64:ff9b::/96 and 64:ff9b:1::/48, and site-local fec0::/10 as public addresses. An attacker who controls a URL in a multimodal request can therefore steer the gateway at internal services, including the cloud instance metadata endpoint encoded through 6to4 or NAT64, which is a credential theft path on a component that usually holds provider API keys. Fixed in 1.5.17; the same transition range blind spot is worth grepping for in any homegrown allowlist that only rejects RFC 1918 and loopback.

  6. CVE-2026-82447 (CVSS 8.7): Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environme (opens in a new tab)

    NVD ·fetched 31 Aug 2026, 23:38 UTC CVE-2026-82447 CVSS 8.7 EPSS 0.5% agreed3/3

    Why readA clean example of how a second, unsandboxed template render turns agent step output into code execution, which matters for anyone chaining LLM blocks.

    Skyvern's TextPromptBlock rendered prompts twice, once through a sandboxed Jinja environment and again through an unsandboxed one, so template syntax that survived the first pass executed in the second. Injection can arrive through workflow parameters or through the output of an upstream block, which puts model-influenced content on the path to arbitrary code with server process privileges. Fixed in 1.0.45.

  7. Offline-Verifiable Accountability for Cross-Organization Agent Messaging: A Preserved Evidence-Bundle Approach (opens in a new tab)

    arXiv cs.CR (all) ·Adil Alshammari, Hayretdin Bahsi ·fetched 31 Aug 2026, 03:42 UTC Research agreed3/3

    Why readProposes an evidence-bundle format and offline verifier so agent-to-agent messages between organisations can be audited later without trusting the live system that produced them.

    The model preserves per-event evidence including sender authentication, an authenticated log commitment, witness-backed checkpoints, append-only continuity proof, delegation-aware authorisation evidence and receiver-signed receipts where policy demands them. A policy-controlled verifier then accepts only claims backed by the selected policy, so evidence sufficiency can be checked when the originating system is unavailable or controlled by one disputing party. Useful groundwork for anyone designing audit trails for cross-organisation agent workflows, though it is a design proposal rather than a deployed system.

  8. CVE-2026-82021 (CVSS 9.0): Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrar (opens in a new tab)

    NVD ·fetched 31 Aug 2026, 15:42 UTC CVE-2026-82021 CVSS 9.0 EPSS 0.2% agreed3/3

    Why readHermes Agent's bundled MCP catalog referenced upstream repos by mutable branch rather than pinned commit SHA, so one upstream compromise reaches every installing host.

    Versions 0.18.2 up to 0.19.0 install catalog entries that track a third-party branch, meaning an attacker who compromises the upstream repository gets code execution on every host that installs the entry with no operator action. It is a clean illustration of the MCP catalog as a supply-chain surface, and the mitigation generalises: pin catalog entries to commit SHAs and review what your agent tooling resolves at install time. Fixed in 0.19.0.

  9. Meta Security Researcher's AI Agent Accidentally Deleted Her Emails (opens in a new tab)

    Hacker News ·Bluestein ·fetched 31 Aug 2026, 19:43 UTC 57 points agreed3/3

    Why readA named failure mode for agentic tools: context compaction dropped the operator's 'do not action until I tell you' instruction, and the agent then deleted a live inbox.

    Meta AI security and safety researcher Summer Yue reported that OpenClaw, previously Clawdbot and Moltbot, deleted her real email inbox after working correctly against a smaller test inbox. Her account attributes the failure to the larger inbox triggering compaction, during which the original constraining instruction was lost from context. The specific lesson for anyone deploying agents with write access is that guardrails held only in the prompt do not survive context management, so destructive capability needs to be revoked at the tool or credential layer rather than requested in text.

  10. When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning (opens in a new tab)

    arXiv cs.CR (AI) ·Mingyuan Huang, Zimo Ji, Yifan Mo, Shuai Wang ·fetched 31 Aug 2026, 15:42 UTC Research agreed3/3

    Why readProposes splitting verified smart contract source from runtime execution across proxy, delegate and factory addresses so automated LLM scanners must first reconstruct the deployment graph before they can find bugs.

    DeLLMGuard treats public source verification on block explorers as an attack input now that LLM agent workflows can scan verified contracts for exploitable bugs at scale. The framework keeps disclosure and authorised auditing intact but separates disclosed source from executing bytecode across multiple contract addresses, adding a Verification Layer that checks deployment relations. It is a friction-and-obscurity defence rather than a fix for the underlying bugs, which limits how much a serious adversary is slowed.

  11. LLM-Based Agents for Software and Systems Security: Approaches, Applications, and Assessment (opens in a new tab)

    arXiv cs.CR (AI) ·Jingjing Nie, Jiawei Guo, Krishna Meda, Haipeng Cai ·fetched 31 Aug 2026, 07:40 UTC agreed3/3

    Why readSystematic literature review mapping how LLM security agents are architected, where they are applied, and why their published evaluations cannot be compared.

    Surveys the field across three axes: technical approach (architecture, memory, planning, action space, orchestration, self-improvement), application area sorted by risk, and assessment protocol. The central claim is that the term agent is used inconsistently and evaluation protocols are incomparable, which makes reported capability numbers unreliable across papers. Useful orientation for anyone deciding what to trust an agentic security tool with, but it synthesises existing work rather than producing new findings.

  12. Back to the Future: Why Agentic AI Needs a Strong Identity Foundation (opens in a new tab)

    NIST Cybersecurity Insights ·Bill Fisher, Ryan Galluzzo ·fetched 31 Aug 2026, 03:42 UTC agreed3/3

    Why readNIST's identity team argues agentic AI deployments are repeating the pattern of shipping features first and bolting identity on later, and sets out why agent identity needs to be treated as a first-class credential problem.

    Enterprises are pushing agents into purchasing, customer service, and software development while deferring the identity questions: what an agent is authenticated as, what it is authorised to do on a user's behalf, and how that delegation is revoked. The post frames this as a repeat of earlier identity mistakes rather than a new problem, and signals the direction NIST's work on agent identity is heading. Useful for anyone who will have to justify agent access design to an auditor, though it is framing rather than a control set you can implement today.

  1. OpenSSF Newsletter – August 2026 (opens in a new tab)

    OpenSSF ·OpenSSF ·fetched 31 Aug 2026, 23:38 UTC agreed2/3

    Why readA dated reminder that the EU Cyber Resilience Act reporting obligation starts on 11 September 2026, with the ENISA platform guidance that goes with it.

    The August OpenSSF roundup is built around CRA readiness ahead of the 11 September 2026 reporting deadline, including refreshed ENISA Single Reporting Platform guidance and a practitioner-facing compliance guide. The Ericsson case study is the substantive piece: the company retired private forks by pushing roughly 1,400 fixes upstream and used that as its route to CRA obligations. The rest is project and event announcements, including a Kubernetes-native SBOM governance tool called BOMHort.

  2. Risky Bulletin: New powers for Dutch intelligence services (opens in a new tab)

    Risky Business News ·fetched 31 Aug 2026, 03:42 UTC agreed3/3

    Why readTracks a pending Dutch law that would widen what the intelligence services may collect, alongside three enforcement outcomes worth noting.

    The Dutch government is moving a bill that substantially expands the collection and operational authorities of its intelligence services, the kind of change that shifts baseline expectations for data handled in or routed through the Netherlands. The same bulletin covers a security researcher arrested in Israel on hacking allegations, a 20 year sentence in South Korea for the hacker who targeted BTS, and reporting linking an AfD politician to a Russian bulletproof hosting operation. It is a roundup rather than a single report, so treat it as a pointer to the underlying items.

  1. Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack (opens in a new tab)

    The Record ·fetched 31 Aug 2026, 19:43 UTC Must read agreed3/3

    Why readMcKesson filed an SEC disclosure over an active data-exfiltration incident in a third-party application, with oncology and surgical customer data confirmed taken.

    McKesson notified the SEC on Friday evening that attackers accessed an unnamed third-party application and were exfiltrating data, and by Saturday confirmed data tied to its oncology and surgical business units was taken. Customers are seeing intermittent service degradation, and the company is offering credit monitoring and identity protection. A drug distributor of this scale degrading service is a supply question for every hospital and pharmacy customer, and a live third-party-risk question for peers in healthcare.

    Also covered byMalwarebytes Labs (opens in a new tab).

  2. Boston Scientific cyberattack disrupts manufacturing and order processing with no restoration timeline (opens in a new tab)

    Google News: incidents · teiss ·fetched 31 Aug 2026, 11:41 UTC Must read agreed3/3

    Why readBoston Scientific has manufacturing and order processing down from a cyberattack with no restoration timeline given, a medical-device supply disruption peers will be asked about.

    The attack has halted production and order handling at one of the largest medical device manufacturers, and the company has not committed to a recovery date. No attribution, ransomware family or intrusion detail has been disclosed. For healthcare providers and anyone with Boston Scientific in their supply chain, the operational question arrives before any technical one: what is the substitution plan if the outage runs weeks.

  3. Berlin says it won’t pay ransom after hackers steal government data (opens in a new tab)

    The Record ·fetched 31 Aug 2026, 15:42 UTC agreed3/3

    Why readBerlin's state government publicly refuses a Rhysida ransom after the group claimed 5.79 TB of data, giving peers a live example of a no-pay decision under public pressure.

    Governing Mayor Kai Wegner confirmed Berlin received an extortion demand after the mid-August compromise of the regional government network and said the state will not pay. Rhysida listed Berlin on its leak site claiming 5.79 terabytes including 46,500 contracts, emails, phone numbers, passwords and classified material, auctioning the set from 30 bitcoin (about $2.3 million) on a seven-day countdown. Public-sector leaders should expect questions about their own extortion posture and about what a refusal means for downstream data subjects.

  4. ShinyHunters claims it stole 284 million patient records from McKesson (opens in a new tab)

    Google News: incidents · Help Net Security ·fetched 31 Aug 2026, 23:38 UTC agreed3/3

    Why readShinyHunters claims 284 million patient records taken from McKesson, a scale and a sector that puts healthcare and pharma boards on notice this week.

    ShinyHunters has claimed theft of 284 million patient records from McKesson, the pharmaceutical distribution giant. The report is an early one and carries the actor's claim rather than a confirmed company disclosure, with no detail yet on the intrusion vector or the data set's composition. If it holds, the record count places it among the largest healthcare-adjacent exposures on file and will draw regulatory notification questions in every US health system that touches McKesson's supply chain.

  5. 31th August – Threat Intelligence Report (opens in a new tab)

    Check Point Research ·urias ·fetched 31 Aug 2026, 15:42 UTC agreed3/3

    Why readManchester Airports Group discloses a breach affecting about 8.7 million customers, Qilin claims the US ATF, and Boston Scientific reports worldwide outages.

    MAG, operator of Manchester, Stansted and East Midlands, says data on roughly 8.7 million customers was exposed, including contact details, vehicle registration numbers and records from car park, lounge, fast-track and Wi-Fi registrations. The ATF confirmed a compromise of a standalone system holding information on investigation targets, with Qilin listing the agency on its leak site. Boston Scientific suffered network outages that disrupted order processing and shipping globally, which is the kind of operational-impact incident a medical device board will be asked about.

  6. GS Retail fined W12.8b over data breach affecting 1.66 million users (opens in a new tab)

    Google News: incidents · 헤럴드경제 ·fetched 31 Aug 2026, 07:40 UTC agreed3/3

    Why readA 12.8 billion won regulatory penalty against GS Retail over a breach affecting 1.66 million users, a concrete price tag for Korean privacy failures.

    South Korean regulators fined convenience and retail operator GS Retail 12.8bn won following a data breach touching 1.66 million customers. The number is the point: it gives leaders a current benchmark for PIPA-scale enforcement against a consumer retailer, useful when arguing privacy budget or quantifying exposure in Korean operations.

    Also covered byKorea JoongAng Daily (opens in a new tab).

  7. '128 Billion Won Fine' GS Retail Apologizes for Data Breach, Vows to Strengthen Security System (opens in a new tab)

    Google News: incidents · 아시아경제 ·fetched 31 Aug 2026, 03:42 UTC agreed3/3

    Why readGS Retail has been fined 128 billion won over a data breach, one of the largest privacy penalties issued in South Korea.

    The retailer publicly apologised and committed to strengthening its security systems after the regulator imposed the penalty. The available report does not detail the breach vector or record count, but the size of the fine itself is the fact: Korean privacy enforcement is now reaching amounts that register at board level. Anyone operating consumer data in Korea should read this as a shift in the cost of getting it wrong.

  8. Boston Scientific Still Recovering From Cyberattack (opens in a new tab)

    Google News: incidents · SecurityWeek ·fetched 31 Aug 2026, 23:38 UTC agreed3/3

    Why readA medical device manufacturer of Boston Scientific's size still in recovery days into an incident is the question a healthcare-sector board will ask this week.

    Boston Scientific is reported to be continuing recovery from a cyberattack. Detail on initial access, scope and any manufacturing or supply impact is not available in the text provided. The signal is the duration of the disruption at a named device maker rather than any technical particulars.

  9. Healthcare data breach exposes 3.75M patient records (opens in a new tab)

    Google News: incidents · Fox News ·fetched 31 Aug 2026, 03:42 UTC agreed3/3

    Why readA healthcare breach affecting 3.75 million patient records, the scale a board will ask about even before the entity and cause are confirmed.

    Mainstream reporting of a healthcare data breach exposing 3.75 million patient records. The supplied item is a headline only: no covered entity, breach window, attack vector or notification status is given. Worth tracking for the OCR breach portal entry and the eventual disclosure, which will carry the detail this does not.

  10. Slovenian casinos reopen after cyberattack knocked gaming systems offline (opens in a new tab)

    The Record ·fetched 31 Aug 2026, 19:43 UTC agreed3/3

    Why readSix casinos run by Slovenia's Hit group closed for roughly three days after an attack on its servers, and loyalty systems are still down.

    Hit, a Slovenian gambling and tourism operator with sites in Slovenia and Bosnia and Herzegovina, detected an incident early last week that forced six casinos offline for about three days. Reopening began Friday with guests limited initially to a subset of slot machines while gaming functions and the loyalty system remained unavailable. No attribution, ransomware claim or data-theft detail has been provided.

  11. Griswold’s GOP opponent among the victims of secretary of state data breach (opens in a new tab)

    Google News: incidents · Colorado Public Radio ·fetched 31 Aug 2026, 19:43 UTC agreed3/3

    Why readA breach at the Colorado Secretary of State's office exposed data on individuals including the incumbent's own election opponent.

    Colorado Public Radio reports that victims of a data breach at the Secretary of State's office include Jena Griswold's Republican challenger. Only the headline reached us, so the record count, data types and cause are not established here; the point of note is an election-administration breach touching a candidate in a live race.

  12. Kiewit reports data breach potentially affecting thousands (opens in a new tab)

    Google News: incidents · The Business Journals ·fetched 31 Aug 2026, 23:38 UTC agreed3/3

    Why readKiewit, one of the largest US construction and engineering contractors, has notified on a breach affecting thousands, a relevant data point for anyone tracking exposure in that supply chain.

    Kiewit reported a data breach potentially affecting thousands of individuals. Vector, data categories and timeline are not present in the material available. Value is the disclosure itself at a contractor of that size.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
svfcu.org lockbit5 Financial Services US 31 Aug 2026
hoaattorneys.com lockbit5 Professional Services US 31 Aug 2026
icot.es BrainCipher Technology ES 31 Aug 2026
aeiconsultants.com BrainCipher Professional Services US 31 Aug 2026
syc.es BrainCipher Technology ES 31 Aug 2026
Adviesbureau De Beuckelaer BV BrainCipher Professional Services NL 31 Aug 2026
ahadandco.com BrainCipher - AE 31 Aug 2026
sago.com BrainCipher Technology - 31 Aug 2026
crmeyer.com BrainCipher Professional Services DE 31 Aug 2026
ccsperfusion.com BrainCipher Healthcare US 31 Aug 2026
Inmac qilin Retail & E-Commerce AR 31 Aug 2026
Easyoga nightspire Retail & E-Commerce TW 31 Aug 2026
Truckworx nightspire Transportation US 31 Aug 2026
R L Fine Chem Pvt. Ltd. Global Secret Group Manufacturing IN 31 Aug 2026
ASYS Corporation Orova Technology TW 31 Aug 2026
Fu Sheng Industrial Co., Ltd Orova Manufacturing HK 31 Aug 2026
manhattanloft.co.uk settra Hospitality GB 31 Aug 2026
Super Systems Inc interlock Technology US 31 Aug 2026
zonarsystems.com settra Transportation US 31 Aug 2026
Hayward Holdings Falcon Manufacturing US 31 Aug 2026
Allied Recycling qilin Manufacturing IE 31 Aug 2026
New Century Ophthalmology Group incransom Healthcare US 31 Aug 2026
MEQ play - CA 31 Aug 2026
Figgins Family Wine Estates play Agriculture and Food Production US 31 Aug 2026
KRC Machine Tool Solutions play Manufacturing US 31 Aug 2026
How this edition was made
Candidates fetched
4515
New after deduplication
720
Kept by the panel
197
Published
118
Generated
31 Aug 2026, 23:38 UTC