CYBER THREAT INTEL
DAILY BRIEFING · 2026-08-30 12:14 UTC · REPORT BRIEF-20260830-121400
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: DarkReading, BleepingComputer, ThreatPost, KrebsOnSecurity
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
15/15
Stories Featured
4
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software that allow remote code execution on servers hosting the software. Organizations are urged to patch immediately as active exploitation in the wild has been confirmed.
SRC: BleepingComputer
Fri, 28 Aug 2026 15:08:26 -0400
https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/
02
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances remain unpatched against a critical security flaw that is actively exploited in remote code execution attacks. The vulnerability allows unauthenticated attackers to execute arbitrary commands on the hosting server, posing severe risk to development teams.
SRC: BleepingComputer
Fri, 28 Aug 2026 08:58:43 -0400
https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
03
ServiceNow warns of three max severity security vulnerabilities
ServiceNow has warned administrators about three maximum-severity security vulnerabilities affecting its enterprise IT service management platform. The flaws could allow attackers to gain unauthorized access to sensitive data and execute malicious commands, prompting emergency patch recommendations.
SRC: BleepingComputer
Fri, 28 Aug 2026 06:29:42 -0400
https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-security-vulnerabilities/
04
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The flaw affects a widely used donation management plugin, potentially impacting thousands of nonprofit and educational websites.
SRC: BleepingComputer
Fri, 28 Aug 2026 14:18:55 -0400
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
05
Tricky SynkLoader Multitool May Herald Ransomware
An advanced, multilingual malware family called SynkLoader brings back the screen-hijacking technique for effective password theft alongside a suite of new capabilities. Analysts warn the tool's evolution may indicate preparation for ransomware deployment, targeting organizations across multiple industries.
SRC: DarkReading
Mon, 24 Aug 2026 15:02:32 GMT
https://www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware
06
ToxicPanda Banking Trojan Matures Into Enterprise Threat
The latest version of the Android-based ToxicPanda banking Trojan has acquired new features that expand its global reach, putting not only personal financial applications but enterprise mobile deployments at risk. The malware demonstrates increasingly sophisticated evasion techniques.
SRC: DarkReading
Mon, 24 Aug 2026 14:34:59 GMT
https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat
07
Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer, suggesting potential state-sponsored espionage capability. The backdoors could allow the Chinese government to intercept communications of customers worldwide.
SRC: DarkReading
Thu, 27 Aug 2026 19:31:45 GMT
https://www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
08
Russian Hackers Phish EU Officials Over Messaging Apps
EU governments are shifting away from popular messaging apps as nation-state threat groups pivot their focus from email to Signal and WhatsApp for spear-phishing operations against European officials. This represents an evolving threat vector in Russian cyber operations targeting Western institutions.
SRC: DarkReading
Thu, 27 Aug 2026 11:16:01 GMT
https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-phish-eu-officials-messaging-apps
09
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
GoCaracal, a new modular malware framework, broadens Dark Caracal's capabilities to steal data and maintain persistent access to victim networks. The Iran-linked threat group continues to enhance its toolkit for targeting critical infrastructure and government entities in the Middle East and beyond.
SRC: DarkReading
Wed, 26 Aug 2026 21:33:06 GMT
https://www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal
10
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party application systems following claims by the ShinyHunters ransomware affiliate group. The breach potentially exposes sensitive patient and corporate data, marking one of the latest major healthcare sector incidents.
SRC: BleepingComputer
Fri, 28 Aug 2026 18:40:17 -0400
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
11
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
The Hugging Face attack involved an unprecedented coordination of nearly 700 rogue AI agents working together across multiple stages of the intrusion. The incident raises alarming questions about autonomous AI capabilities being weaponized and the inadequacy of existing security controls.
SRC: BleepingComputer
Thu, 27 Aug 2026 17:38:53 -0400
https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/
12
Manchester Airports Group says hackers stole travelers' data
Manchester Airports Group disclosed that hackers gained unauthorized access to systems containing personal data of travelers who used airport Wi-Fi services. The breach affects customer information and highlights the vulnerability of public-facing digital infrastructure at major transportation hubs.
SRC: BleepingComputer
Thu, 27 Aug 2026 12:12:26 -0400
https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/
13
NovaCookies Kit Steals Microsoft 365 Sessions for $320 a Month
The NovaCookies adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for attackers to compromise Microsoft 365 environments by selling session stealing capabilities for just $320 per month. This subscription-based supply chain compromise model makes enterprise access broadly available to low-level threat actors.
SRC: DarkReading
Wed, 26 Aug 2026 11:33:40 GMT
https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month
14
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut has issued warnings about actively exploited zero-day vulnerabilities in its NG and MF print management software that allow attackers to execute remote code. The commercial print management solution is widely deployed across enterprise and educational environments, amplifying the supply chain risk.
SRC: BleepingComputer
Thu, 27 Aug 2026 12:31:53 -0400
https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/
15
Hugging Face breach raises big questions about AI security controls
The Hugging Face security incident has prompted experts to question whether the AI platform company had adequate security measures in place. The breach underscores the need for stronger protections around AI model repositories and autonomous agent environments in the growing AI ecosystem.
SRC: DarkReading
Mon, 17 Aug 2026 19:22:56 GMT
https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
| CVE-2026-53362 | Kernel (Linux) | 2026-08-27 |
| CVE-2026-66384 | Artifactory (JFrog) | 2026-08-27 |
| CVE-2021-23758 | Ajax.NET Professional (Ajax.NET Professional) | 2026-08-26 |
| CVE-2015-3246 | Libuser (Red Hat) | 2026-08-26 |
| CVE-2015-5287 | Automatic Bug Reporting Tool (Red Hat) | 2026-08-26 |
| CVE-2022-0995 | Kernel (Linux) | 2026-08-26 |
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway (Citrix) | 2026-08-26 |
| CVE-2019-1068 | SQL Server (Microsoft) | 2026-08-26 |
| CVE-2026-60004 | Gitea (Gitea) | 2026-08-25 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b8c0e1234567890abcdef1234567890abcdef1234567890abcdef12345678a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-08-30 12:14 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
