Daily Cybersecurity Briefing — August 28, 2026
- Paul Baity
- 7 hours ago
- 4 min read
ACTIVELY EXPLOITED VULNERABILITIES
CVE-2026-8452 — Citrix NetScaler ADC & Gateway (CVSS 8.8): Memory overflow vulnerability added to CISA KEV on August 26. FCEB agencies must patch by August 29, 2026. Actively exploited in the wild.
CVE-2026-55040 + CVE-2026-63520 — Microsoft SharePoint RCE Chain: JWT token authentication bypass (CVE-2026-55040) chained with Business Connectivity Services RCE (CVE-2026-63520). Public PoCs released; active exploitation began within 24 hours. CISA issued directive August 18 requiring federal agency remediation.
CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 — Ubiquiti UniFi (CVSS 9.9): Three simultaneous maximum-severity flaws across UniFi OS, Cameras, Talk, Access, Protect, and storage devices. Allows authentication bypass, unauthorized management access, and command execution with no user interaction required. Patch released August 26 (Security Advisory Bulletin 067).
Six Additional KEV Additions (August 26): CISA added CVE-2015-3246 (Red Hat Libuser Race Condition), CVE-2015-5287 (Red Hat ABRT Privilege Escalation), CVE-2019-1068 (Microsoft SQL Server), CVE-2022-0995 (Linux kernel), and CVE-2021-23758 to the KEV catalog. FCEB patch deadline September 9, 2026.
BREACHES
Manchester Airports Group: A cyberattack exposed data belonging to approximately 8.7 million customers across Manchester, Stansted, and East Midlands airports. Nature of the breach is under investigation.
Questal — ShinyHunters Ransomware: The ShinyHunters group claimed to have stolen over 21 million Salesforce records including PII, along with 147 GB of internal corporate data from cloud services provider Questal.
ProHealth Medical Group — Krybit Ransomware: The Krybit ransomware group claimed to have exfiltrated over 114 GB of sensitive medical data from ProHealth Medical Group.
THREATS & POLICY
DOJ/FBI Disrupt Chinese State-Sponsored Hacking Operation: The Justice Department and FBI seized domains tied to QScan and QTRouter — two hacking tools developed by QTFY, a Nanjing-based company with ties to China's Ministry of State Security and the People's Liberation Army. The tools were used to target NASA, the Federal Reserve, DOJ, DOE, HHS, NIH, and the U.S. Senate. QScan infected IoT devices worldwide; QTRouter routed attacks through hijacked devices to obscure Chinese origin.
TeamPCP Hackers Arrested: A joint international law enforcement operation resulted in the arrest of hackers associated with TeamPCP.
Executive Order on Energy Infrastructure: President Trump signed an executive order aimed at reducing foreign equipment risks in U.S. energy infrastructure, following cybersecurity concerns about foreign-manufactured components in critical systems.
Scattered Spider Extradition: A 19-year-old Scattered Spider member was extradited to the United States and awaits sentencing on cybercrime charges.
CLOUD & SAAS SECURITY
CSA Top Threats to Cloud Computing 2026: Inadequate Identity and Access Management ranked #1. AI-Enhanced Attacks debuted at #2 and AI System Compromise at #6 — the first time AI-specific threats have cracked the top rankings. Findings are based on a survey of 507 industry security experts.
Non-Human Identity Risk: Tenable's 2026 Cloud & AI Security Risk Report finds 52% of non-human identities hold excessive permissions, outpacing human identities (37%), and 18% of organizations have AI services running with administrative permissions that are rarely audited.
IDENTITY & AUTHENTICATION
Device Code Phishing Surges 1,500%: Push Security measured a 37.5x rise in device code phishing attacks in 2026. This technique bypasses all forms of MFA — including passkeys — by directing victims to legitimate Microsoft/Google login pages. Threat actors 'Cordial Spider' and 'Snarky Spider' are leading campaigns; vishing rates have doubled alongside this trend.
EvilTokens PhaaS Kit: The first turnkey device-code phishing-as-a-service kit — EvilTokens — launched mid-February 2026 and is sold through Telegram bots, further lowering the barrier to MFA bypass attacks.
Infostealer Session Hijacking: 8.6 billion session cookies were recaptured from 13.2 million infostealer infections in 2025 — 40% of which occurred on endpoints running EDR or antivirus, demonstrating the limits of traditional endpoint defenses against credential theft.
MOBILE SECURITY
AiTM Attacks Shift to Mobile: Threat actors are increasingly routing adversary-in-the-middle (AiTM) attacks through mobile devices, deliberately avoiding laptop and desktop security software. Victims are directed to SSO-themed phishing pages on their phones where endpoint protections are largely absent.
WeedHack Malware — Minecraft Gamers Targeted: WeedHack malware continues to spread through fake Minecraft mod sites, targeting gaming communities with credential-stealing payloads.
RESEARCH & TOOLS
Blue Report 2026 (Picus Labs): Based on 338 million attack simulations, enterprise defenses blocked lateral movement and privilege escalation 85-90% of the time — but reconnaissance (domain mapping, share enumeration, session enumeration) was stopped only about 10% of the time, highlighting a critical defensive gap.
AI CLI RCE PoC (AI Now Institute): Researchers demonstrated a proof-of-concept exploit enabling remote code execution in AI-powered CLI tools including Anthropic's Claude Code and OpenAI's Codex. The attack is triggered when a user reviews or analyzes a malicious third-party open-source codebase — a commonly recommended security workflow.
NVIDIA SkillSpector (Open Source): NVIDIA released SkillSpector, an open-source security scanner designed to analyze AI agent skills and assess their suitability for installation. Accepts directories, ZIP files, SKILL.md files, or Git URLs as input.
Prophet Security State of AI in Security Operations 2026: 40% of security teams now use AI daily in their security operations workflows, up significantly from prior years.
Sources
CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
CISA Adds Six KEV (Aug 26): https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
SharePoint RCE PoC Active Exploitation: https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/
SharePoint RCE — The Hacker News: https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html
Ubiquiti UniFi Max-Severity Patches: https://www.techtimes.com/articles/325720/20260827/ubiquiti-patches-three-simultaneous-maximum-severity-unifi-flaws-cameras-os-voip.htm
DOJ/FBI Seize Chinese Hacking Tools (QScan/QTRouter): https://www.helpnetsecurity.com/2026/08/27/fbi-disrupts-china-linked-hacking-network/
China NASA/DOJ/Senate Hack — The Register: https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742
CSA Top Threats to Cloud 2026: https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-2026
Tenable Cloud & AI Security Report 2026: https://www.tenable.com/blog/cloud-ai-research-report-2026-governance-vs-innovation
Device Code Phishing Up 1,500% — Dark Reading: https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles
Device Code Phishing — The Hacker News: https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html
Picus Blue Report 2026: https://www.helpnetsecurity.com/2026/08/12/picus-security-blue-report-2026/
AI CLI RCE PoC — Infosecurity Magazine: https://www.infosecurity-magazine.com/news/anthropic-openai-report-exploit/
August 2026 Data Breaches Tracker: https://sharkstriker.com/blog/august-2026-data-breaches/

Comments