CYBER THREAT INTEL
DAILY BRIEFING · 2026-08-29 17:39 UTC · REPORT BRIEF-20260829-173938
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: BleepingComputer, Krebs on Security, The Hacker News
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
10/75
Stories Featured
3
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. […].
critical
SRC: BleepingComputer
Fri, 28 Aug 2026 18:40:17 -0400
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
02
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment.
high
SRC: The Hacker News
Sat, 29 Aug 2026 03:00:52 +0530
https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
03
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are =.
critical
SRC: The Hacker News
Sat, 29 Aug 2026 02:08:47 +0530
https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
04
PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. […].
critical
SRC: BleepingComputer
Fri, 28 Aug 2026 15:08:26 -0400
https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/
05
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. […].
high
SRC: BleepingComputer
Fri, 28 Aug 2026 14:18:55 -0400
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
06
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's.
critical
SRC: The Hacker News
Fri, 28 Aug 2026 22:42:15 +0530
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
07
68-year-old imprisoned after making $1.3 million by pirating IPTV services
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. […].
medium
SRC: BleepingComputer
Fri, 28 Aug 2026 12:36:47 -0400
https://www.bleepingcomputer.com/news/security/68-year-old-imprisoned-after-making-13-million-by-pirating-iptv-services/
08
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem.
medium
SRC: The Hacker News
Fri, 28 Aug 2026 21:50:46 +0530
https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html
09
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of.
critical
SRC: The Hacker News
Fri, 28 Aug 2026 21:26:55 +0530
https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
10
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active.
medium
SRC: The Hacker News
Fri, 28 Aug 2026 20:57:26 +0530
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
| CVE-2026-53362 | Kernel (Linux) | 2026-08-27 |
| CVE-2026-66384 | Artifactory (JFrog) | 2026-08-27 |
| CVE-2021-23758 | Ajax.NET Professional (Ajax.NET Professional) | 2026-08-26 |
| CVE-2015-3246 | Libuser (Red Hat) | 2026-08-26 |
| CVE-2015-5287 | Automatic Bug Reporting Tool (Red Hat) | 2026-08-26 |
| CVE-2022-0995 | Kernel (Linux) | 2026-08-26 |
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway (Citrix) | 2026-08-26 |
| CVE-2019-1068 | SQL Server (Microsoft) | 2026-08-26 |
| CVE-2026-60004 | Gitea (Gitea) | 2026-08-25 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b8c0e12345678…a1b2c3d4e5f6a1b2…f1e2d3c4b5a6f1e2…185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-08-29 17:39 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
