CYBER THREAT INTEL
DAILY BRIEFING · 2026-08-31 15:51 UTC · REPORT BRIEF-20260831-155149
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: The Hacker News, BleepingComputer, Krebs on Security, DarkReading
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
16/15
Stories Featured
4
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that tricks users into running a malicious command in Windows Terminal or PowerShell. Unlike traditional ClickFix campaigns that direct victims to the Windows Run dialog, TerminalFix targets Windows Terminal or PowerShell, significantly increasing the likelihood of successful malicious command execution and reverse-tunnel backdoor deployment.
SRC: The Hacker News
Sun, 30 Aug 2026 13:06:33 +0530
https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
02
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities were identified by Wordfence and Patchstack, with one flaw rated at CVSS 9.8 for authentication bypass.
SRC: The Hacker News
Sat, 29 Aug 2026 21:55:03 +0530
https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
03
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, with the company releasing a fresh emergency fix that includes additional hardening. The vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, enabling arbitrary Java code execution inside the application's process.
SRC: The Hacker News
Fri, 28 Aug 2026 22:42:15 +0530
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
04
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned CVE-2026-65643, impacts all supported versions of cPanel and WHM and poses an extreme risk to shared hosting environments.
SRC: The Hacker News
Fri, 28 Aug 2026 15:15:15 +0530
https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
05
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability, CVE-2026-60004 (CVSS 9.8), allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the unprivileged git user, and reported attacks have dropped cryptocurrency miner-like payloads.
SRC: The Hacker News
Wed, 26 Aug 2026 11:57:07 +0530
https://thehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html
06
Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage limits. This emerging attack vector demonstrates how traditional credential theft tools are adapting to target AI-powered services, raising concerns about the broader implications for AI platform security.
SRC: BleepingComputer
Sun, 30 Aug 2026 10:30:25 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
07
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor can exfiltrate credentials and blind critical security logs, severely impairing defensive visibility.
SRC: The Hacker News
Mon, 31 Aug 2026 14:34:55 +0530
https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
08
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead clarifying that they were among those targeted in a broader campaign. The correction highlights the sensitivity of attribution in ongoing U.S.-China cyber operations and the importance of precise language in national security communications.
SRC: The Hacker News
Mon, 31 Aug 2026 13:26:53 +0530
https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html
09
FulcrumSec Claims Manchester Airports Hack, Theft of 86 GB of Data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group, with BleepingComputer validating one traveller's record that revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. The breach exposes the personal data of airport travelers and highlights the vulnerability of public-facing digital infrastructure at major transportation hubs.
SRC: BleepingComputer
Sun, 30 Aug 2026 11:00:21 -0400
https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
10
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government confirmed it is the target of an extortion attempt following the August compromise of the city's state administrative network and stated it will not meet the hackers' demands. Forensic work revealed further data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, amplifying concerns about municipal cybersecurity posture.
SRC: The Hacker News
Sat, 29 Aug 2026 03:00:52 +0530
https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
11
Chrome Web Store Extensions Caught Stealing Crypto, Browser Data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, while also injecting ClickFix lures. The extensions shared similarities in code and tradecraft, indicating a coordinated campaign active over the past six months that abused the Chrome Web Store and Microsoft Edge Add-ons distribution channels.
SRC: BleepingComputer
Sun, 30 Aug 2026 10:17:44 -0400
https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/
12
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Cosmos Labs warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, was published without a CVE identifier, weakness classification, or CVSS score, raising concerns about disclosure practices for critical shared infrastructure components.
SRC: The Hacker News
Sat, 29 Aug 2026 02:08:47 +0530
https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
13
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers disclosed details of a phishing-as-a-service platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support. The platform, tracked as AnonyMousKIT by SOCRadar STRU, is credit-metered and drives lures across multiple channels, representing an alarming convergence of AI technology and device theft operations.
SRC: The Hacker News
Wed, 26 Aug 2026 11:17:28 +0530
https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html
14
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA added six flaws to its Known Exploited Vulnerabilities catalog citing evidence of active exploitation, including a high-severity vulnerability impacting Citrix NetScaler ADC and Gateway, Linux kernel issues, and Microsoft SQL Server bugs. The KEV catalog additions underscore the urgency for federal agencies and critical infrastructure operators to patch these vulnerabilities immediately.
SRC: The Hacker News
Thu, 27 Aug 2026 12:35:28 +0530
https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html
15
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
CISA published results of two simultaneous red team assessments against critical infrastructure organizations, using similar tradecraft but recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both the red team achieved additional access, highlighting significant gaps in detection and response capabilities at targeted critical infrastructure operators.
SRC: The Hacker News
Wed, 26 Aug 2026 18:37:02 +0530
https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html
16
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Academic researchers disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes, enabling denial-of-service and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto and represents a significant advancement in GPU-side-channel and memory corruption attacks.
SRC: The Hacker News
Thu, 27 Aug 2026 13:43:11 +0530
https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
| CVE-2026-53362 | Kernel (Linux) | 2026-08-27 |
| CVE-2026-66384 | Artifactory (JFrog) | 2026-08-27 |
| CVE-2021-23758 | Ajax.NET Professional (Ajax.NET Professional) | 2026-08-26 |
| CVE-2015-3246 | Libuser (Red Hat) | 2026-08-26 |
| CVE-2015-5287 | Automatic Bug Reporting Tool (Red Hat) | 2026-08-26 |
| CVE-2022-0995 | Kernel (Linux) | 2026-08-26 |
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway (Citrix) | 2026-08-26 |
| CVE-2019-1068 | SQL Server (Microsoft) | 2026-08-26 |
| CVE-2026-60004 | Gitea (Gitea) | 2026-08-25 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b 8c0e 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-08-31 15:51 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
