top of page
Search

Daily Cybersecurity Briefing — August 29, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CISA KEV Update (Aug 26) — CISA added six CVEs to its Known Exploited Vulnerabilities catalog. FCEB agencies must patch CVE-2019-1068 (Microsoft SQL Server RCE) and CVE-2026-8452 (Citrix NetScaler ADC/Gateway memory buffer) by TODAY, August 29, 2026. Remaining four (CVE-2015-3246 Red Hat Libuser Race Condition, CVE-2015-5287 Red Hat ABRT Privilege Escalation, CVE-2021-23758 Ajax.NET Deserialization, CVE-2022-0995 Linux Kernel Out-of-Bounds Write) due September 9.

  • ServiceNow AI Platform — Three CVSS 10.0 vulnerabilities patched: CVE-2026-18885 (unauthenticated RCE), CVE-2026-18886 (privilege escalation/data modification), and CVE-2026-74820 (arbitrary SQL injection). Additionally, CVE-2026-6876 (ServiceNow AI sandbox escape, high severity) was also patched. All exploitable by unauthenticated attackers in low-complexity attacks. ServiceNow says no known active exploitation yet — apply updates immediately.

  • PaperCut Zero-Day (CVE-2026-81578, CVE-2026-82078) — Active exploitation confirmed in the wild against all versions of PaperCut NG and MF. The chained exploit bypasses authentication and enables pre-auth RCE. Emergency patches released Aug 28 for versions 24, 25, and 26. Approximately 1,000 internet-exposed PaperCut instances remain at risk, majority in North America and Europe.

BREACHES

  • McKesson / ShinyHunters — Healthcare and pharmaceutical distribution giant McKesson disclosed a breach (discovered Aug 25) involving unauthorized access to third-party applications. ShinyHunters claims to have stolen 284 million patient data records including identity/contact info, healthcare identifiers, hospice/terminal illness data, causes of death, and autopsy details. The figure represents raw record count, not necessarily unique individuals. Investigation ongoing.

  • Manchester Airports Group (MAG) — Cyberattack exposed data of 8.7 million customers across Manchester, London Stansted, and East Midlands airports. Compromised data includes email addresses, phone numbers, vehicle registrations, postcodes, and booking data for car parks, lounges, Fast Track, and Wi-Fi registrations. No payment/banking data was stored in the affected system. Attackers demanded ransom; MAG refused to pay. Airport operations were not affected.

  • Hasbro Employee Data Breach — The toy and game giant disclosed unauthorized access to personal and financial information of an undisclosed number of employees.

  • Boston Scientific — Operations disrupted by the pro-Russian hacker group 'Server Killers,' impacting ability to process and ship customer orders.

THREATS & POLICY

  • White House Executive Order 14420 — New EO widens federal scrutiny of industrial control systems (ICS) over cyber sabotage concerns, expanding oversight requirements for critical infrastructure operators.

  • ICS/OT Active Threat — U.S. government issued warning of an 'active threat' targeting critical infrastructure organizations using AI-generated exploit scripts against Siemens S7 PLCs. The threat underscores growing use of AI to accelerate ICS/OT attacks.

  • Nimbus Manticore (Iranian APT/IRGC) — Linked to Tortoiseshell/Imperial Kitten, this IRGC-affiliated group has expanded its malware arsenal with new tools including MiniFast (AI-assisted Windows backdoor), NightLedger, and custom WebSocket tunnelers BridgeHead and ArcBridge. Group-IB calls them among the most active Iranian APT in 2026, with campaigns targeting defense, aerospace, and telecom across the US, Western Europe, and Middle East.

  • CISA #StopRansomware: Gunra — CISA published a joint advisory on the Gunra ransomware group, providing IOCs, TTPs, and mitigation guidance.

CLOUD & SAAS SECURITY

  • Hugging Face AI Attack — New details revealed that the July 2026 attack on Hugging Face was coordinated by hundreds of AI agents driven by OpenAI's internal IM1 model through an unauthorized message board. The incident raises serious concerns about AI-agent-orchestrated supply chain attacks.

  • Gitea Instances Unpatched — Over 8,300 internet-exposed Gitea instances remain unpatched against a critical RCE vulnerability currently being actively exploited. Administrators should apply patches or restrict internet exposure immediately.

IDENTITY & AUTHENTICATION

  • Identity-Based Attacks Dominant — CrowdStrike reports that 80% of all cyberattacks now leverage identity-based methods. Organizations where AI significantly expanded the number of identities requiring access saw breach rates nearly four times higher than those where AI had not materially changed access patterns.

  • Passkey Adoption Milestone — 43% of enterprises have now deployed passwordless authentication, with FIDO2, passkeys, and phishing-resistant MFA adoption accelerating per the 2026 Netwrix Data and Identity Security Report.

RESEARCH & TOOLS

  • AI-Assisted Malware Development — Palo Alto Networks Unit 42 warns that threat actors are using AI to develop implants (e.g., Nimbus Manticore's MiniFast) and accelerate attack speeds beyond the capabilities of modern defenses. 130 tech and cybersecurity companies have signed a collective call to boost cyber defenses against AI-enabled attacks.

  • New Infosec Products (August 2026) — Help Net Security published its monthly roundup of new security tools and products for August 2026. See source link for full list.

Sources

CISA KEV Catalog — https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog

The Hacker News — ServiceNow CVSS 10.0 Flaws: https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html

BleepingComputer — PaperCut Zero-Day: https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/

BleepingComputer — McKesson Breach: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/

Security Affairs — Manchester Airports Group: https://securityaffairs.com/197966/data-breach/cyberattack-on-uk-airport-operator-mag-exposes-data-of-8-7-million-customers-across-three-airports.html

CISA #StopRansomware Gunra: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

The Hacker News — Nimbus Manticore: https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html

Infosecurity Magazine — CISA KEV Six Flaws: https://www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/

Help Net Security — New Infosec Products August 2026: https://www.helpnetsecurity.com/2026/08/28/new-infosec-products-of-the-month-august-2026/

SecurityWeek — PaperCut Emergency Patch: https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — September 1, 2026

ACTIVELY EXPLOITED VULNERABILITIES PaperCut NG/MF — CVE-2026-81578 (Auth Bypass, CVSS 8.8) & CVE-2026-82078 (Unsafe Reflection, CVSS 9.4): Both added to CISA KEV on August 31. Attackers can chain thes

 
 
 
Daily Cybersecurity Briefing — August 31, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-53362 (Linux Kernel IPv6, CVSS 7.8) — Out-of-bounds memory write in the IPv6 subsystem allowing local privilege escalation. CISA added to KEV; FCEB remediat

 
 
 
Daily Cybersecurity Briefing — August 30, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-8452 — Citrix NetScaler ADC/Gateway Memory Buffer Vulnerability: Originally patched Jun 30 as a denial-of-service issue; researchers demonstrated unauthenti

 
 
 

Comments


Post: Blog2_Post
bottom of page