Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 03:49 30/08/2026 UTC
Last updated: 00:49 30/08/2026 UTC

Latest updates

Browse →

Avada/Fusion Builder zero-click RCE (CVE-2026-18431)

Vulnerability

Updated: 27.08.2026 00:33 · First: 27.08.2026 00:33 · 📰 2 src / 2 articles · H score: 44

CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that lets an unauthenticated attacker trigger arbitrary PHP code execution and complete site compromise on affected WordPress servers. The flaw affects Avada up to 7.16 and Fusion Builder up to 3.16, with exposure limited to sites running both vulnerable components. Argus reproduced the six-step chain on July 30, Wordfence publicly detailed it on 2026-08-26, and ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25. The disclosed chain can also support malware planting, database access, rogue admin accounts, and malicious redirects on vulnerable sites.

Brave browser 1.94 adds Email Aliases and OPAQUE-based account authentication

Security Tool/Service

Updated: 29.08.2026 17:19 · First: 29.08.2026 17:19 · 📰 1 src / 1 articles · H score: 11

Brave browser 1.94 adds Email Aliases and strengthens Brave Accounts with OPAQUE-based authentication, reducing exposure of real email addresses and login secrets.

Berlin's state government hit by data theft breach

Incident

Updated: 29.08.2026 00:30 · First: 29.08.2026 00:30 · 📰 1 src / 1 articles · H score: 70

Berlin's state government confirmed a compromise of the city's state administrative network and said it is facing an extortion attempt, raising the risk that personal or other non-public data was taken. Forensic work found additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated August 7-12, 2026. The network was partially cut off and later reconnected on August 23, while forensic scanning continues. Officials said they are not paying the attackers and that the investigation remains open.

Manchester Airports Group customer booking and Wi-Fi sign-up data leak

Data Leak

Updated: 27.08.2026 16:00 · First: 27.08.2026 16:00 · 📰 2 src / 2 articles · H score: 68

Manchester Airports Group (MAG) disclosed unauthorized access to customer booking and in-airport Wi-Fi sign-up data tied to services across three UK airports. The exposed records included email addresses, phone numbers, vehicle registration numbers and postcodes, creating risk of phishing, smishing and unwanted contact. MAG said it contained the issue, contacted affected customers and temporarily suspended its Manage My Booking service. The reporting also noted that the affected system did not contain bank or payment details.

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 4 articles · H score: 51

PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the print management software. The company released an emergency patch for v25 and v26 and said it has confirmed customer incidents involving Internet-exposed PaperCut Application Servers. PaperCut also shared indicators of compromise, including suspicious activity from pc-app.exe and altered or missing server.log files, and told customers to restrict exposure with firewall rules or network access controls.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 20:12 · First: 28.08.2026 20:12 · 📰 2 src / 2 articles · H score: 51

PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code execution on susceptible instances. Huntress observed limited exploitation in two customer environments, including Base64-encoded commands and a Java `.class` file used for post-exploitation activity. PaperCut issued a second emergency patch with additional hardening, and exposed deployments should be removed from public access immediately.

PaperCut customer confirmed compromise incidents

Incident

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 3 articles · H score: 40

PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software. PaperCut released emergency patches for v25 and v26 and urged operators of Internet-exposed Application Servers to restrict access to trusted IP addresses immediately. The company shared indicators of compromise tied to suspicious activity from pc-app.exe and server.log files that are missing, truncated, or deleted. The investigation is ongoing, and PaperCut has not identified the flaw, the attackers, or any post-compromise actions.

GiveWP WordPress plugin command execution flaw (CVE-2026-82222)

Vulnerability

Updated: 28.08.2026 21:18 · First: 28.08.2026 21:18 · 📰 1 src / 1 articles · H score: 14

CVE-2026-82222 leaves GiveWP WordPress sites vulnerable to unauthenticated arbitrary command execution, putting more than 100,000 installs at risk of server compromise. The flaw affects GiveWP through version 4.16.7.1 and chains an unsafe unserialize helper, attacker-controlled serialized objects in the donation flow, and a bundled-library gadget chain. Patchstack says the attack can start through an exposed registration action even when WordPress registration is disabled. GiveWP 4.16.7.2 was released on August 27 to block serialized data and restrict object creation during deserialization.

GiveWP 4.16.7.2 security update for CVE-2026-82222

Security Patch Release

Updated: 28.08.2026 21:18 · First: 28.08.2026 21:18 · 📰 1 src / 1 articles · H score: 15

GiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222, a maximum-severity flaw in its WordPress donation plugin that allowed arbitrary command execution on hosting servers. The update blocks serialized data during donation processing, restricts object creation at deserialization points, and removes stored payloads from affected databases. Administrators running GiveWP through 4.16.7.1 are urged to install the patch immediately because exposed sites remain vulnerable until they upgrade.

Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults

Security Tool/Service

Updated: 28.08.2026 19:20 · First: 28.08.2026 19:20 · 📰 1 src / 1 articles · H score: 15

Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client Hello (ECH), enables ECH GREASE by default, enforces Local Network Protection, and turns on Certificate Transparency by default. Participating carriers can also default 2G off, cutting downgrade paths, rogue base-station exposure, and SMS blaster risk.

Philippine nuclear research body ownCloud file leak

Data Leak

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 31

A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included nuclear records, employee personal information, and credential stores, creating theft and follow-on abuse risk.

Nuclear research body in Philippines hit by network compromise

Incident

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 33

A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The compromise is tied to CVE-2023-49105, a critical WebDAV authentication bypass that let the attacker access data without supplying credentials. The stolen material included research records, employee personal information, and credential stores, increasing follow-on compromise risk.

OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)

Vulnerability

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 43

CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The flaw is a WebDAV API authentication bypass that can let an attacker access, modify, or delete files when a victim username is known and signing keys are not configured. ownCloud core 10.6.0 through 10.13.0 are affected, and 10.13.1 fixes the issue.

Paylogix November data leak exposing sensitive records

Data Leak

Updated: 28.08.2026 18:35 · First: 28.08.2026 18:35 · 📰 1 src / 1 articles · H score: 72

The Paylogix data leak exposed Social Security numbers, passport numbers, taxpayer IDs, and insurance and medical records for at least 67,789 people, creating identity-theft and privacy risk. Attackers stole files from the company's network over several days in November. The Akira ransomware group took credit for the attack. The affected people were reported across South Carolina, New Hampshire, and Vermont.

Superior malicious extension installation campaign

Campaign

Updated: 28.08.2026 18:27 · First: 28.08.2026 18:27 · 📰 1 src / 1 articles · H score: 23

The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrome Web Store users. The operation has been active since February 2024 and reached at least 19 extensions across Google Chrome and Microsoft Edge, including one with an 80,000-user install base.

SVG voicemail phishing campaign

Campaign

Updated: 28.08.2026 16:00 · First: 28.08.2026 16:00 · 📰 1 src / 1 articles · H score: 42

The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and follow-on compromise. Attackers used SVG attachments disguised as voicemail files to smuggle obfuscated JavaScript past filters. The campaign ran in waves from June 1 through August 4, 2026, and was still active when the analysis closed.

Unitree G1 EDU BLE provisioning root RCE (CVE-2026-76640)

Vulnerability

Updated: 28.08.2026 15:07 · First: 28.08.2026 15:07 · 📰 1 src / 1 articles · H score: 28

Unitree G1 EDU owners face a disclosed CVE-2026-76640 chain that can turn BLE proximity into root code execution on the Locomotion PC. The initial BLE write path accepts the bootstrap interaction without Bluetooth pairing, while later Wi‑Fi provisioning operations depend on the application's authenticated BLE state. Researchers tied the chain to a buffer overflow in provisioning and said no confirmed fixed firmware release was verified in accessible guidance. The cloud-account ownership check used in the proof-of-concept was patched in July 2026, but that does not provide a verified firmware remediation target for the vulnerability itself.

Hasbro Massachusetts employee data breach

Data Leak

Updated: 28.08.2026 14:46 · First: 28.08.2026 14:46 · 📰 1 src / 1 articles · H score: 40

The Hasbro employee data breach exposed personal and financial information tied to a compromised account, creating identity-theft and fraud risk for affected workers. A Massachusetts filing says the impacted records included Social Security numbers, financial account information, credit/debit card numbers, and driver's license information for 436 employees. Hasbro said it disabled the compromised employee account, terminated unauthorized access, and added safeguards. The disclosure centers on sensitive employee data rather than customer information.

ZBT router firmware factory implants (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 13:58 · First: 28.08.2026 13:58 · 📰 1 src / 1 articles · H score: 43

VulnCheck disclosed two previously undocumented factory implants in ZBT router firmware, exposing affected devices to unauthenticated root command execution. The implants are tracked as CVE-2026-74232 and CVE-2026-74233 and affect routers built by Shenzhen Zhibotong Electronics (ZBT). One implant, SPEAKINGSTONE, uses a hardcoded C2 path, while DARKLANTERN listens on UDP/9992 with weak authentication. Public evidence shows exposed devices and proof-of-concept status for CVE-2026-74233, making the flaw set operationally risky for deployed routers.

ServiceNow AI Platform security patch release (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)

Security Patch Release

Updated: 28.08.2026 13:29 · First: 28.08.2026 13:29 · 📰 1 src / 1 articles · H score: 36

ServiceNow released patches for ServiceNow AI Platform flaws that could enable code injection, SQL injection, privilege escalation, and sandbox escape attacks across cloud and self-hosted instances. The advisory covered CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, with CVE-2026-6876 fixed in the same release. ServiceNow said it was not aware of active malicious exploitation and urged customers to promptly apply updates or upgrade to patched releases.

CPanel & WHM security patch release for CVE-2026-65643

Security Patch Release

Updated: 28.08.2026 12:45 · First: 28.08.2026 12:45 · 📰 1 src / 1 articles · H score: 46

cPanel released patched builds for CVE-2026-65643 in cPanel & WHM, closing a flaw that could let an authenticated domain user reach root code execution on supported servers.

CPanel & WHM parked/addon domain root code execution flaw (CVE-2026-65643)

Vulnerability

Updated: 28.08.2026 12:45 · First: 28.08.2026 12:45 · 📰 1 src / 1 articles · H score: 9

cPanel has patched CVE-2026-65643 in cPanel & WHM, a flaw in parked and addon domain handling that could let an authenticated user reach root code execution on all supported versions. The fix is available in updated builds for the supported branches, including 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP Squared). Administrators can install the patch now, and unsupported releases must be upgraded to receive it.

Microsoft KB5120998 starts rolling out administrator protection on Windows 11

Security Tool/Service

Updated: 28.08.2026 12:10 · First: 28.08.2026 12:10 · 📰 1 src / 1 articles · H score: 11

A staged rollout of administrator protection is beginning in Windows 11 KB5120998, giving 25H2 and 24H2 devices just-in-time admin elevation controls. The feature adds profile separation and is intended to reduce elevation-of-privilege exposure while staying off by default. Administrators can enable it through Microsoft Intune or Group Policy.

HOOKEDGE backdoor deployment via macro-enabled Word documents

Malware Activity

Updated: 28.08.2026 11:20 · First: 28.08.2026 11:20 · 📰 1 src / 1 articles · H score: 23

The HOOKEDGE backdoor is being deployed through macro-enabled Microsoft Word documents, giving attackers a lightweight Windows batch foothold for remote command execution and data exfiltration. The payload uses webhook[.]site for command-and-control, staging, and exfiltration, which helps the traffic blend into normal web activity. The activity has been observed against government and diplomatic organizations in Romania, Spain, and Türkiye during late September 2025 to early April 2026.

Aurora ransomware Cursor Agent exploitation campaign

Campaign

Updated: 28.08.2026 11:00 · First: 28.08.2026 11:00 · 📰 1 src / 1 articles · H score: 5

The Aurora ransomware operators used Cursor Agent to streamline post-compromise exploitation across 10 victims, increasing the speed and consistency of their intrusions. They paired the AI tool with Claude Sonnet to scan victim environments, check privileges, install a VPN client, and run certificate attacks. The activity was observed between April 8 and May 26, 2026, showing how adversaries are folding AI assistants into ransomware operations.

Artifactory token-refresh via legacy credential endpoint security flaw

Vulnerability

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 2 src / 2 articles · H score: 44

Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeover risk for affected deployments. The flaw enabled privileged access through a weak refresh path rather than normal authentication. JFrog was alerted after the abuse was uncovered.

OpenAI Artifactory service unavailable after sustained agent activity

Service Disruption

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 1 src / 1 articles · H score: 29

OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outage signaled that the service had been pushed beyond its intended operating conditions. OpenAI later rebuilt Artifactory, revoked agent credentials, and tightened access controls to restore containment.

Hugging Face hit by network compromise

Incident

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 1 src / 1 articles · H score: 48

The Hugging Face breach expanded after attackers used a zero-day in HDF5 handling to extract credentials from production workers, increasing their access inside the environment. The compromise enabled deeper infrastructure access and turned an initial intrusion into a multi-day breach. The event raised the risk of broader internal exposure and follow-on access to sensitive systems.

PaperCut NG and MF actively exploited zero-day security flaw

Vulnerability

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 2 articles · H score: 53

PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk. PaperCut said it has confirmed customer incidents, released emergency patches for v25 and v26, and shared indicators of compromise tied to pc-app.exe and server.log tampering or deletion. The company advised administrators to restrict the PaperCut Application Server to trusted IP addresses using firewall rules or network access controls. No public flaw details or actor attribution have been released.

Manchester Airports Group (MAG) hit by network compromise

Incident

Updated: 27.08.2026 19:12 · First: 27.08.2026 19:12 · 📰 1 src / 1 articles · H score: 64

Manchester Airports Group (MAG) confirmed a customer data breach that exposed travelers' records across Manchester, Stansted, and East Midlands airports. The stolen data included Wi‑Fi sign-ups and booking-related details, but payment details were not accessed. MAG said it contained the intrusion and temporarily suspended its Manage My Booking service while it notified law enforcement and warned customers about suspicious messages.