top of page
Search

Daily Cybersecurity Briefing — August 28, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CVE-2026-8452 — Citrix NetScaler ADC & Gateway (CVSS 8.8): Memory overflow vulnerability added to CISA KEV on August 26. FCEB agencies must patch by August 29, 2026. Actively exploited in the wild.

  • CVE-2026-55040 + CVE-2026-63520 — Microsoft SharePoint RCE Chain: JWT token authentication bypass (CVE-2026-55040) chained with Business Connectivity Services RCE (CVE-2026-63520). Public PoCs released; active exploitation began within 24 hours. CISA issued directive August 18 requiring federal agency remediation.

  • CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 — Ubiquiti UniFi (CVSS 9.9): Three simultaneous maximum-severity flaws across UniFi OS, Cameras, Talk, Access, Protect, and storage devices. Allows authentication bypass, unauthorized management access, and command execution with no user interaction required. Patch released August 26 (Security Advisory Bulletin 067).

  • Six Additional KEV Additions (August 26): CISA added CVE-2015-3246 (Red Hat Libuser Race Condition), CVE-2015-5287 (Red Hat ABRT Privilege Escalation), CVE-2019-1068 (Microsoft SQL Server), CVE-2022-0995 (Linux kernel), and CVE-2021-23758 to the KEV catalog. FCEB patch deadline September 9, 2026.

BREACHES

  • Manchester Airports Group: A cyberattack exposed data belonging to approximately 8.7 million customers across Manchester, Stansted, and East Midlands airports. Nature of the breach is under investigation.

  • Questal — ShinyHunters Ransomware: The ShinyHunters group claimed to have stolen over 21 million Salesforce records including PII, along with 147 GB of internal corporate data from cloud services provider Questal.

  • ProHealth Medical Group — Krybit Ransomware: The Krybit ransomware group claimed to have exfiltrated over 114 GB of sensitive medical data from ProHealth Medical Group.

THREATS & POLICY

  • DOJ/FBI Disrupt Chinese State-Sponsored Hacking Operation: The Justice Department and FBI seized domains tied to QScan and QTRouter — two hacking tools developed by QTFY, a Nanjing-based company with ties to China's Ministry of State Security and the People's Liberation Army. The tools were used to target NASA, the Federal Reserve, DOJ, DOE, HHS, NIH, and the U.S. Senate. QScan infected IoT devices worldwide; QTRouter routed attacks through hijacked devices to obscure Chinese origin.

  • TeamPCP Hackers Arrested: A joint international law enforcement operation resulted in the arrest of hackers associated with TeamPCP.

  • Executive Order on Energy Infrastructure: President Trump signed an executive order aimed at reducing foreign equipment risks in U.S. energy infrastructure, following cybersecurity concerns about foreign-manufactured components in critical systems.

  • Scattered Spider Extradition: A 19-year-old Scattered Spider member was extradited to the United States and awaits sentencing on cybercrime charges.

CLOUD & SAAS SECURITY

  • CSA Top Threats to Cloud Computing 2026: Inadequate Identity and Access Management ranked #1. AI-Enhanced Attacks debuted at #2 and AI System Compromise at #6 — the first time AI-specific threats have cracked the top rankings. Findings are based on a survey of 507 industry security experts.

  • Non-Human Identity Risk: Tenable's 2026 Cloud & AI Security Risk Report finds 52% of non-human identities hold excessive permissions, outpacing human identities (37%), and 18% of organizations have AI services running with administrative permissions that are rarely audited.

IDENTITY & AUTHENTICATION

  • Device Code Phishing Surges 1,500%: Push Security measured a 37.5x rise in device code phishing attacks in 2026. This technique bypasses all forms of MFA — including passkeys — by directing victims to legitimate Microsoft/Google login pages. Threat actors 'Cordial Spider' and 'Snarky Spider' are leading campaigns; vishing rates have doubled alongside this trend.

  • EvilTokens PhaaS Kit: The first turnkey device-code phishing-as-a-service kit — EvilTokens — launched mid-February 2026 and is sold through Telegram bots, further lowering the barrier to MFA bypass attacks.

  • Infostealer Session Hijacking: 8.6 billion session cookies were recaptured from 13.2 million infostealer infections in 2025 — 40% of which occurred on endpoints running EDR or antivirus, demonstrating the limits of traditional endpoint defenses against credential theft.

MOBILE SECURITY

  • AiTM Attacks Shift to Mobile: Threat actors are increasingly routing adversary-in-the-middle (AiTM) attacks through mobile devices, deliberately avoiding laptop and desktop security software. Victims are directed to SSO-themed phishing pages on their phones where endpoint protections are largely absent.

  • WeedHack Malware — Minecraft Gamers Targeted: WeedHack malware continues to spread through fake Minecraft mod sites, targeting gaming communities with credential-stealing payloads.

RESEARCH & TOOLS

  • Blue Report 2026 (Picus Labs): Based on 338 million attack simulations, enterprise defenses blocked lateral movement and privilege escalation 85-90% of the time — but reconnaissance (domain mapping, share enumeration, session enumeration) was stopped only about 10% of the time, highlighting a critical defensive gap.

  • AI CLI RCE PoC (AI Now Institute): Researchers demonstrated a proof-of-concept exploit enabling remote code execution in AI-powered CLI tools including Anthropic's Claude Code and OpenAI's Codex. The attack is triggered when a user reviews or analyzes a malicious third-party open-source codebase — a commonly recommended security workflow.

  • NVIDIA SkillSpector (Open Source): NVIDIA released SkillSpector, an open-source security scanner designed to analyze AI agent skills and assess their suitability for installation. Accepts directories, ZIP files, SKILL.md files, or Git URLs as input.

  • Prophet Security State of AI in Security Operations 2026: 40% of security teams now use AI daily in their security operations workflows, up significantly from prior years.

Sources

CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

CISA Adds Six KEV (Aug 26): https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog

SharePoint RCE PoC Active Exploitation: https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/

SharePoint RCE — The Hacker News: https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html

Ubiquiti UniFi Max-Severity Patches: https://www.techtimes.com/articles/325720/20260827/ubiquiti-patches-three-simultaneous-maximum-severity-unifi-flaws-cameras-os-voip.htm

DOJ/FBI Seize Chinese Hacking Tools (QScan/QTRouter): https://www.helpnetsecurity.com/2026/08/27/fbi-disrupts-china-linked-hacking-network/

China NASA/DOJ/Senate Hack — The Register: https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742

CSA Top Threats to Cloud 2026: https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-2026

Tenable Cloud & AI Security Report 2026: https://www.tenable.com/blog/cloud-ai-research-report-2026-governance-vs-innovation

Device Code Phishing Up 1,500% — Dark Reading: https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles

Device Code Phishing — The Hacker News: https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html

Picus Blue Report 2026: https://www.helpnetsecurity.com/2026/08/12/picus-security-blue-report-2026/

AI CLI RCE PoC — Infosecurity Magazine: https://www.infosecurity-magazine.com/news/anthropic-openai-report-exploit/

August 2026 Data Breaches Tracker: https://sharkstriker.com/blog/august-2026-data-breaches/

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — August 27, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-21962 (CVSS 10.0) — Oracle HTTP Server / WebLogic Server Proxy Plug-in Authentication Bypass. Unauthenticated attackers with network access can read or modi

 
 
 
Daily Cybersecurity Briefing — August 26, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Double Free Vulnerability. Added to CISA KEV catalog Aug 18, 2026. FCEB patch deadline applies. CVE-2026-55040

 
 
 
Daily Cybersecurity Briefing — August 25, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-21962 (CVSS 10.0) | Oracle HTTP Server & WebLogic Server | Unauthenticated RCE via HTTP | Added to CISA KEV; FCEB agencies must patch by August 27, 2026 CVE

 
 
 

Comments


Post: Blog2_Post
bottom of page