These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
JFrog patched CVE-2026-82329, a 9.8-severity authentication bypass in default Artifactory configurations, on August 28. Days later watchTowr confirmed active exploitation: attackers minting themselves administrator tokens with no credentials at all, on self-hosted instances that sit at the centre of the software supply chain.
Manchester Airports Group confirmed on August 27 that extortion group FulcrumSec accessed customer data across Manchester, London Stansted and East Midlands airports by lifting Iterable API credentials that were sitting in plain sight inside client-side JavaScript. FulcrumSec claims 86GB of exfiltrated data covering roughly 8.7 million customers, making it the largest known breach of a British airport operator, and the entry point required no exploit at all, just a browser’s developer tools.
PaperCut shipped a second emergency patch on August 28, one day after its first fix, when watchTowr researchers found multiple ways to bypass it. The underlying chain, CVE-2026-81578 (8.8) and CVE-2026-82078 (9.4), lets an unauthenticated attacker reach PaperCut NG/MF’s web management interface and achieve remote code execution, and Huntress had already spotted active exploitation starting August 26, before any patch existed.
CISA’s August 26 batch of six additions to its Known Exploited Vulnerabilities catalogue includes two Red Hat flaws from 2015, a SQL Server bug from 2019, and an Ajax.NET Professional deserialization issue from 2021, alongside the freshly disclosed Citrix NetScaler CVE-2026-8452. Federal agencies had until August 29 to patch the SQL Server and NetScaler bugs, and until September 9 for the rest. The batch is a reminder that attackers don’t need a zero-day when a decade-old unpatched system is still sitting on the network.
Questel SAS, a French intellectual property management firm that handles patent and trademark portfolios for corporations and law firms, confirmed on August 13 that ShinyHunters accessed part of its Microsoft 365 environment through a single voice phishing call. The attacker talked their way into a Sales SharePoint site, not a technical exploit, and the extortion group has since added two more companies, Alcon and Lumenis, to the same leak site with the same tactic.
CVE-2026-8452, a memory overflow in NetScaler ADC and Gateway appliances running VPN or AAA virtual servers, was patched as a denial-of-service fix but has now been confirmed as an unauthenticated path to remote code execution as root. CISA added it to its Known Exploited Vulnerabilities catalogue on August 26 with a federal remediation deadline of August 29, and defenders have already found webshells planted on compromised appliances. More than 22,000 NetScaler ADC instances and nearly 1,800 Gateway instances remain internet-exposed with unknown patch status.
CVE-2026-60004 lets anyone who can create an account on a Gitea instance execute arbitrary shell commands as the Gitea service account, by submitting a malicious patch through the diffpatch API endpoint. Because Gitea ships with self-registration enabled by default, an attacker needs no prior credentials at all, just the ability to sign up. CISA has confirmed active exploitation, including a cryptocurrency-miner-style payload, and Shadowserver counts more than 8,300 internet-facing Gitea instances still unpatched against the fix in version 1.27.1.
Researchers have disclosed HOOKEDGE, a previously undocumented Windows backdoor attributed with moderate confidence to the Russian state-sponsored group APT28, used in a diplomatic-themed phishing campaign against government and diplomatic organisations in Romania, Spain and Turkiye between September 2025 and April 2026. Delivered through macro-enabled Word documents, HOOKEDGE routes its command-and-control and data exfiltration through webhook.site, a legitimate free service developers use for testing webhooks, letting malicious traffic blend into ordinary web activity that most security tools have no reason to block.
The Rhysida ransomware group claims to have stolen 5.79 terabytes of Berlin state agency data, including 46,500 contracts, emails, phone numbers and passwords, and is auctioning it starting at 30 bitcoin after the city refused to pay. The attack lands less than a month before Berlin’s September 20 election, and it is the latest in a long run of Rhysida attacks on European government and public-sector targets.
CISA has added CVE-2023-49105, a critical WebDAV authentication bypass in the German-built ownCloud file-sync platform, to its Known Exploited Vulnerabilities catalog after attackers used it to exfiltrate files from a nuclear research body. The flaw has been public and patchable since early 2024, and CISA’s deadline for federal remediation is August 30, 2026, tomorrow. Any organisation self-hosting ownCloud for the data sovereignty it offers needs to confirm it is not still running an unpatched core.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.