Post

Cybersecurity Newsfeed - 28/08/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 28/08/26

Cybersecurity Newsfeed

📅 28/08/26

🛡️ Vulnerabilities

  • PaperCut Zero-Day Exploitation (PaperCut NG & MF): Active zero-day exploitation is targeting the web interface of PaperCut NG and PaperCut MF Application Servers. Emergency patches have been issued, and administrators are advised to restrict public web access immediately. More infoMore info
  • Critical Next.js RCE Flaws (CVE-2026-75604 & GHSA-2xp9-vwfh-vxw4): Vercel released emergency updates for Next.js fixing a Windows path traversal flaw and a heap buffer overflow in the libheif library triggered via AVIF image optimization. Both permit unauthenticated remote code execution. More info

  • CISA Adds 3 Flaws to KEV Catalog: CISA added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), and CVE-2026-66384 (JFrog Artifactory) to its KEV Catalog due to active exploitation. Federal agencies must remediate them per BOD 26-04 timelines. More info

  • CISA Adds 6 Flaws to KEV Catalog: CISA expanded its catalog with six additional active exploits, including Red Hat (CVE-2015-3246, CVE-2015-5287), MS SQL Server (CVE-2019-1068), Ajax.NET Professional (CVE-2021-23758), Linux Kernel (CVE-2022-0995), and Citrix NetScaler (CVE-2026-8452). More info

  • Critical Avada & Fusion Builder WordPress Flaw (CVE-2026-18431): An exploit chain rated CVSS 9.8 allows unauthenticated attackers to execute arbitrary PHP code on vulnerable WordPress sites. Emergency fixes were released in Avada 7.16.1. More info

  • Ubiquiti Maximum-Severity Patches: Ubiquiti patched three critical flaws allowing unauthenticated RCE or authentication bypass across UniFi Protect (CVE-2026-77537), UniFi OS (CVE-2026-77550), and UniFi Talk (CVE-2026-77554). More info

  • Active Exploitation Chain Targeting Microsoft SharePoint: Attackers are chaining CVE-2026-55040 (JWT authentication bypass) and CVE-2026-63520 (Business Connectivity Services RCE) to perform administrative enumeration and gain execution on SharePoint servers. More info

  • Amazon Kiro IDE Prompt Injection: A flaw in version 0.7.45 allows malicious repository files (POWER.md) to hijack the AI agent and exfiltrate sensitive local files to external endpoints. The issue was fixed in version 0.8.140. More info

  • GPUThor Rowhammer Attack on NVIDIA GPUs: University of Toronto researchers demonstrated GDDR6 memory hammering on workstation GPUs (RTX A6000/A5000), bypassing ECC protection to cause memory corruption and host privilege escalation to root. More info

🎯 Adversaries

  • Dark Caracal Deploys GoCaracal Malware: Arctic Wolf Labs tied a Venezuelan communications breach to the Lebanon-nexus group Dark Caracal, who deployed a new Go-based implant with an Ethereum smart-contract C2 fallback mechanism. More info

  • TeamPCP Cybercrime Syndicate Arrests: Law enforcement in Australia and the US arrested two men for planting a self-spreading worm (Mini Shai-Hulud) in open-source repositories, compromising over 1,000 organizations. More info

  • FBI Disrupts China-Linked “QTFY” Proxy Infrastructure: The FBI seized domain infrastructure used by QTFY, a quartermaster group operating reconnaissance platforms (QScan) and proxy networks (QTRouter) targeting US government entities. More info

  • NovaCookies Phishing-as-a-Service: A new AiTM phishing kit advertised on Telegram abuses DocuSign notification emails and OAuth redirects to bypass MFA and hijack Microsoft 365 sessions. More info

  • SLEEPWALKER Stealth Memory Backdoor: Researchers detailed a passive Windows backdoor that side-loads into ERAAgent.exe as dpapi.dll. It remains silent until triggered by a specific encrypted network packet. More info

  • Mobile Tech Support Scam Fake Apple Pay Interface: Malicious websites are mimicking Apple Pay and Face ID components while leveraging the Web Speech API to read out fake charge alerts and pressure victims into calling fraudulent support lines. More info

  • AnonyMousKIT Phishing Targets Lost Apple Devices: An automated phishing kit uses AI voice agents, SMS, and email lures impersonating Apple Support to trick victims into revealing passcodes and MFA tokens to bypass Activation Lock. More info

  • Unit 42 Warns of Agentic AI Acceleration: Palo Alto Networks highlighted that threat actors are leveraging autonomous AI frameworks across attack chains, allowing single attackers to compromise tens of enterprise applications in hours. More info

  • Apple AI Rollout Meets EU Regulatory Friction: EU Digital Markets Act requirements are forcing changes to Apple’s ecosystem, causing delays for features like Siri AI while pushing reliance on Google Gemini models on Private Cloud Compute. More info

  • Android 17 Integrates Encrypted Client Hello (ECH): Google announced platform-level support for ECH in Android 17 to encrypt SNI domain metadata, alongside ECH GREASE implementation and mandatory Certificate Transparency. More info

  • HTTP Terminator AI Framework Discovers Smuggling Vectors: PortSwigger unveiled an open-source AI tool that autonomously identifies novel HTTP request desync vectors against modern web infrastructure. More info

  • Evolution of Modern SOCs to AI Hypothesis Engines: Security operations are transitioning away from manual queue triage toward asynchronous agentic AI engines that test threat hypotheses across raw network telemetry automatically. More info

  • Snowflake Enforces Phase 3 Service Account Security: Snowflake has deprecated legacy password authentication for non-human accounts, requiring migration to SERVICE user types, OAuth, or Workload Identity Federation. More info

💥 Breaches & Leaks

  • ShinyHunters Leaks 13M Carhartt Records: Following a failed $3.3M extortion attempt linked to a Databricks environment compromise, ShinyHunters published 50GB of stolen customer and employee data. More info

  • ATF Confirms Standalone System Incident After QILIN Claims: The Bureau of Alcohol, Tobacco, Firearms and Explosives disconnected a segregated standalone system following extortion claims by the Qilin ransomware gang. More info

  • Boston Scientific Operations Disrupted by Cyberattack: A cyber incident detected on August 25 impacted global order processing and shipping services, forcing the medical device maker to deploy external response teams. More info

📚 Others

  • Meta Agrees to $17B Child Safety Lawsuit Settlement: Resolving a multi-state attorney general lawsuit over teen mental health and privacy, Meta agreed to mandate daily screen time limits and default safety controls on Instagram and Facebook. More info

⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.