Cyber Threat Intelligence 31 August 2026
-
Industrial Sector
- You Need Cyber Deception For OT
"There are three statements that sum up the frustrating reality for defenders responding to a cyberattack on operational technology (OT) systems: The attack data is not there. There is no trail to follow. There is no history to sort through. While these dynamics will always be true for OT, defenders are getting help from cyber deception as it matures beyond honeypots to a more sophisticated, proactive cyber-defense tool."
https://www.darkreading.com/ics-ot-security/you-need-cyber-deception-ot
Vulnerabilities
- Unauthenticated PHP Object Injection To Remote Code Execution On GiveWP
"This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions where the chain is fully reachable, describes a default installation. The flaw chains a broken “safe unserialize” helper, a donation flow that feeds that helper attacker-controlled data, and a gadget chain in code that GiveWP ships. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html - ServiceNow Warns Of Three Max Severity Security Vulnerabilities
"ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances."
https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html - PaperCut Releases Second Emergency Patch For Exploited Flaws
"PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes."
https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/
https://www.huntress.com/blog/papercut-actively-exploited
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
https://therecord.media/papercut-warns-of-hackers-using-printer-management-vulnerabilities
https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/
https://securityaffairs.com/198107/uncategorized/hackers-are-probing-papercut-servers-and-47-still-have-no-patch.html - Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
"Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >= 0.7.0 < 0.7.2, and the fix shipped in v0.6.2 and v0.7.2 on August 19. Chain operators are told to upgrade to one of those releases or later, a change that is state-breaking and requires a coordinated network upgrade."
https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html - Critical cPanel Flaw Could Let One Hosting Customer Take Root Control Of a Whole Server
"cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server."
https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html - Over 8,300 Gitea Servers Vulnerable To Code Execution Attacks
"Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint."
https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/ - UniBLEed: Unauthenticated Root RCE On Any Unitree G1 Humanoid Robot Within Bluetooth Range
"Root on a $20,000 humanoid robot, via a cloud API that decrypts any G1's AES key from any free Unitree account without checking ownership. One BLE characteristic that accepts writes without pairing. A heredoc injection that hijacks WiFi. A path traversal in the robot's AI chatbot knowledge base that leaks the binary's load address. And a 1050-byte BSS buffer overflow that corrupts the event loop into calling system() as root. Below is the complete technical breakdown of a $6,700 bounty and the two CVEs it produced: CVE-2026-76639 / CVE-2026-76640."
https://boschko.ca/g1-ble-rce/
https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html
https://securityaffairs.com/198085/hacking/hack-one-robot-reach-the-next-unitree-g1-security-flaws.html
Malware
- Aurora Ransomware Targets ESXi, Abuses Cursor Agent For Exploitation
"Gambit Security’s Threat Intelligence team investigates emerging attacker tradecraft and the evolving ways threat actors disrupt organizations. As part of this research, we track threat actors and their operations to identify new techniques, tooling, and approaches to disruption. In a recent investigation, we identified exposed infrastructure associated with the Aurora ransomware group, providing visibility into the group’s operations across multiple victim environments."
https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation
https://www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/ - 19 Chrome And Edge Extensions Deliver a Wallet Drainer And Credential-Stealing Payloads
"Socket identified 19 malicious extensions published in the last six months, delivering an extendable malware framework. Identified malware samples create WebSocket communication channel with command and control (C2) server, perform CSP stripping and abuse XSS injection to trigger execution of malicious payloads previously downloaded from the C2 server. Malicious capabilities are primarily focused on, but not limited to, wallet secret stealing and crypto draining. The most impactful tactic is acquisition of established extensions offered for sale with an existing user base, which then get weaponized with malicious functionality."
https://socket.dev/blog/chrome-edge-extension-wallet-drainer
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/ - Chinese Implants In The Supply Chain
"After publishing ENDLESSDOORS, we wanted to know how far ZBT’s supply chain reached. The answer: everywhere. FCC filings, patent records, and archived web pages tied ZBT hardware to brands across the United States, Canada, Australia, the Philippines, Germany, and Russia. We'll trace that supply chain later in this blog. But first, we wanted to know which devices contained the ENDLESSDOORS implant. We started out by buying one router from a US supplier. The Deep Orange 3G/4G/LTE Router, pictured above, is a white-labeled ZBT-WE826-T2. We exploited a vulnerability in the telnet interface and rooted the device. With root access, we found the router’s firmware was built in 2019, predating ENDLESSDOORS. So ENDLESSDOORS wasn’t there."
https://www.vulncheck.com/blog/zbt-darklantern-speakingstone
https://www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html - BlueDelta Targets Defense And Diplomacy With HOOKEDGE
"Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 2025 meeting between Spanish and Moldovan officials."
https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ru-2026-0827.pdf
https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html
https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html - Fake Voicemails, Real Malware: Inside a 26,000-Email SVG Smuggling Campaign
"A two-month phishing campaign disguised malicious JavaScript as harmless voicemail attachments, mislabeling the files as plain text to slip past attachment scanners. INKY detected and flagged all 26,589 messages. Between June 1 and August 4, 2026, INKY tracked and detected a sustained phishing campaign that used a deceptively simple lure — a missed voicemail notification — to deliver malicious code hidden inside an image file. The campaign reached 5,527 organizations and generated 26,589 detected emails."
https://www.kaseya.com/blog/svg-smuggling-voicemail-phishing-campaign/
https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/ - Threat Actors Are Posing As OpenAI, Anthropic And DeepSeek To Target Credentials And Secrets
"GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies. These forged automated scanners have been observed requesting files often exposed on misconfigured web servers and by other commonly leaked secret and credential methods. A cluster of scanners impersonating 13 AI crawlers from eight companies requested .env files, cloud access keys, private keys and password stores. Six of those names came from the same 824 addresses in almost identical volume, and within this cluster none of the six requested /robots.txt."
https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers - Fake Invoices, Real Scammers: The Callback Phishing Playbook
"Traditional phishing attacks try to get victims to click a malicious link or open a dangerous attachment. The five attacks examined here simply asked recipients to call a phone number. Known as callback phishing or telephone-oriented attack delivery (TOAD), these attacks use fake invoices, receipts and billing notifications to create anxiety and doubt, encouraging the recipient to call a fraudulent support number where a live scammer takes over."
https://blog.barracuda.com/2026/08/28/callback-phishing-fake-invoice-toad-attacks - Philippine Nuclear Agency And Naval Contractor Targeted By Suspected Chinese-Speaking Operator Using Known Vulnerabilities
"Reported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations over the past several years has increased with ongoing tensions in the South China Sea. Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors. On August 13, 2026, Hunt.io Attack Capture identified an open directory on the host 31.58.209[.]241. The server staged custom Python scripts, per-file transfer logs, open-source offensive security tooling, and exfiltrated data from two Philippine organizations."
https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor
https://securityaffairs.com/198041/intelligence/philippine-nuclear-and-naval-targets-hit-by-suspected-chinese-operator.html - Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions To Drain Usage
"Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email sent to an affected user, who shared it on Reddit."
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/ - TerminalFix Campaign Deploys a Reverse Tunnel Through Multistage Intrusion
"Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully. Unlike earlier ClickFix variants that typically deliver a single infostealer, this TerminalFix campaign deploys a sophisticated multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant – giving the attacker persistent, network-level proxy access through the compromised host."
https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html - Caught In 4K: The Aurora Files
"An exposed open directory revealed months of activity from belonging to a Russian speaking Aurora ransomware affiliate, active against more than twenty organisations between April and July 2026. The directory included the operator's own toolkit and shell history alongside the Aurora encryptor itself, with the ransom note and onion address embedded directly in the binary. Four of the operator's victims have since been listed on Aurora's leak site. With keys recovered from the encryptor CloudSEK gained visibility into past ransom negotiations. In partnership with TRM Labs, CloudSEK traced the resulting payment on chain and found it converging with at least one other Aurora victim's payment through shared laundering infrastructure."
https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments - Open Directory Exposes Moobot Source Code And Ongoing Activity Post 2024 Court-Authorized Disruption
"A misconfigured open directory on 86[.]53[.]111[.]212:8080 exposed critical details of active cybercrime operator, including Moobot botnet source code, other denial of service (DOS) tools with attack records, and a fraudulent identity verification service – providing a rare view of a malicious operation in progress. Also present on the host is “StresD Pro+”, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the day of collection. The panel operates independently from the Moobot, generating attack traffic directly from the staging host using a purpose-built Minecraft Bedrock Edition RakNet flooder."
https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/
Breaches/Hacks/Leaks
- McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
"Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies. CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission."
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/ - Toy-Making Giant Hasbro Disclose Data Breach Affecting Employees
"Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble, Magic: The Gathering, Dungeons & Dragons, and many others. The company has filed data breach notification letters with the Massachusetts Attorney General's Office, but didn't disclose the total number of affected individuals or when the incident was detected."
https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/
https://www.securityweek.com/hasbro-data-breach-exposed-employee-personal-information/ - Love Electric Breach: 877,000 Driver Records Offered For $600
"A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the name “seraphims”, offered 877,000 records for $600 in cryptocurrency, with the price negotiable. That headline number needs a qualification. Ransomnews researchers examined a 999-row sample published with the listing and found strong evidence that the sample came from a genuine production database, but the claimed 877,000 records remain unverified. Love Electric had been contacted for comment at the time of publication."
https://securityaffairs.com/198033/data-breach/love-electric-breach-877000-driver-records-offered-for-600.html - Rhysida Ransomware Group Targets Berlin Government Ahead Of Vote
"Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included."
https://securityaffairs.com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html - FulcrumSec Claims Manchester Airports Hack, Theft Of 86 GB Of Data
"The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data. Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed."
https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
https://securityaffairs.com/198143/cyber-crime/extortion-group-fulcrumsec-claims-86gb-manchester-airports-group-data-theft.html
General News
- July 2026 Threat Trend Report On APT Attacks (South Korea)
"AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026."
https://asec.ahnlab.com/en/95171/ - Offensive Security Investments Surge As AI Threats Increase
"So far, agentic AI has proven more effective for cyberattacks than cyber defense, but that may be changing. Theresa Lanowitz, principal analyst at Omdia, spoke with Dark Reading's senior news director, Rob Wright, at the News Desk at Black Hat USA 2026 about new research regarding shifting enterprise investments in offensive cybersecurity practices, such as penetration testing, vulnerability assessments, and red teaming, amid growing concerns about AI-driven threats."
https://www.darkreading.com/cybersecurity-operations/offensive-security-investments-surge-ai-threats-increase - Defining An AI Kill Switch Is Hard, But Necessary
"The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent's operations if they go rogue. In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — "The AI Kill Switch Act" — that would require developers of advanced AI systems to "maintain the technical capability to throttle, suspend, or shut ... down" their systems and agents, according to a statement announcing the legislation."
https://www.darkreading.com/cybersecurity-operations/defining-ai-kill-switch-hard-but-necessary - The Vulnpocalypse Is Repricing The Bug Bounty Economy
"As the "vulnpocalypse" reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living. It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times."
https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy - What 90 Days And a Small Budget Can Buy In AI Agent Security
"In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. He walks through red-teaming AI agents, what counts as a failing result, and the five questions buyers should ask agent platforms. For teams with 90 days and little budget, he ranks inventory, blast radius reduction and ongoing testing as the order of work."
https://www.helpnetsecurity.com/2026/08/28/prasad-tharippala-versa-securing-ai-agents/ - Perturbation Probing: A New Diagnostic For The Fragility Of LLM Safety
"Our previous research on logit-gap steering demonstrated that the safety guardrails of an aligned LLM can be bypassed by closing a measurable gap in the model's output scores. That work answered the question of how an attacker bypasses alignment. A natural follow-up question is where inside the model the alignment lives in the first place — and how concentrated or how diffuse that defense actually is. The answer matters because it tells defenders whether safety is a thick perimeter or a thin layer of paint. Modern LLMs are aligned through reinforcement learning from human feedback (RLHF), a training stage that pushes the model toward refusing harmful prompts and complying with safe ones."
https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/ - The Evolution Of Hacktivism In Hybrid Warfare: Modern Tactics And Real-World Impact
"Hacktivism used to be perceived as digital graffiti, with lone-wolf threat actors defacing government websites or temporarily crashing banking portals to make a political point. However, Flashpoint is tracking a fundamental shift in how these groups operate. Modern hacktivism is evolving into a disciplined component of global hybrid warfare, capable of bridging digital disruptions with tangible real-world impact. Today, these operations blur the line between volunteer activism and coordinated state interest, leveraging crowdsourced infrastructure to disrupt critical utilities, manipulate media narratives, and target public infrastructure on a global scale. Unpacking these modern hacktivist collectives reveals what their tactics look like in practice and their far-reaching consequences across dozens of nations."
https://flashpoint.io/blog/evolution-hacktivism-hybrid-warfare-modern-tactics-real-world-impact/ - The State Of Ransomware In Education 2026
"This year's State of Ransomware survey showed promising signs that education providers are building resilience against ransomware attacks. But the costs and recovery timelines after attacks are still climbing. Recovery costs rose across lower education (students up to age 18) and higher education providers (over 18) this year, with higher education's average recovery bill growing by more than $1 million. And one education sector now ranks among the slowest to recover when compared to the complete list of sectors surveyed."
https://www.sophos.com/en-us/blog/state-of-ransomware-in-education-2026
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- You Need Cyber Deception For OT