Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:04 01/09/2026 UTC
Last updated: 23:04 31/08/2026 UTC

Latest updates

Browse →

Tectonic cryptocurrency lending platform hit by cyberattack

Incident

Updated: 31.08.2026 23:47 · First: 31.08.2026 23:47 · 📰 1 src / 1 articles · H score: 54

The Tectonic lending platform on Cronos suffered a price-manipulation exploit that let an attacker borrow $74 million in assets and caused major losses. Cronos halted and then restored the chain after the incident, keeping the platform under investigation and increasing concern about DeFi collateral manipulation.

Cronos blockchain network halt and restart after Tectonic exploit

Service Disruption

Updated: 31.08.2026 23:47 · First: 31.08.2026 23:47 · 📰 1 src / 1 articles · H score: 39

The Cronos blockchain network temporarily halted block production after a price-manipulation exploit on Tectonic disrupted transaction processing and froze funds in flight. The network later restarted and reported it was fully back online as of 2026-08-30 23:49:01 UTC. The interruption paused live trading activity on a DeFi platform tied to Cronos while stability checks continued.

Microsoft Exchange Online service disruption causing authentication and email failures

Service Disruption

Updated: 31.08.2026 19:56 · First: 31.08.2026 19:56 · 📰 1 src / 1 articles · H score: 0

Microsoft is investigating a widespread Exchange Online outage that is disrupting authentication and email delivery for tens of thousands of users. The issue is affecting message sending and receiving, mailbox operations, and access to Exchange Online and Outlook. Microsoft says it has isolated a common failure pattern and is working on remediation options.

OpenAI ChatGPT Work partial outage causing elevated errors

Service Disruption

Updated: 31.08.2026 19:50 · First: 31.08.2026 19:50 · 📰 1 src / 1 articles · H score: 0

OpenAI's ChatGPT Work is in a partial outage, leaving some users unable to start or continue tasks and driving elevated latency and errors. The issue began at 11:04 AM ET on Monday, August 31 and remained ongoing at 12:02 PM ET. Plus users appear especially affected because Work mode is unavailable for some accounts.

Berlin's state government hit by data theft breach

Incident

Updated: 29.08.2026 00:30 · First: 29.08.2026 00:30 · 📰 2 src / 2 articles · H score: 70

Berlin is dealing with a Rhysida ransomware extortion attempt after the gang listed the city on its data leak site. The city says the attack was discovered in mid-August, that it will not pay, and that the State Criminal Police Office, the public prosecutor's office, and federal security agencies are investigating. Rhysida’s post claimed 5.79 TB of data and about 1.44 million files from Berlin’s administrative network, while officials said there is no evidence election data was compromised and the Berlin House of Representatives election environment is secure. The leak-site claim also cited 148 IBANs, more than 3,200 nondisclosure agreements, and other records, but Berlin has not confirmed those figures.

Berlin administrative network data leak after Rhysida claim

Data Leak

Updated: 31.08.2026 16:30 · First: 31.08.2026 16:30 · 📰 1 src / 1 articles · H score: 74

Berlin faces a Rhysida-linked data leak threat after the group listed the city on its leak site and claimed a 5.79 TB exfiltration from Berlin’s administrative network. The alleged theft raises disclosure risk for government, financial, health, and identity records, along with credentials and other sensitive files. City officials say they will not pay and investigators are reviewing the scope of the theft.

Rhysida extortion over Berlin administrative network compromise

Case

Updated: 31.08.2026 16:30 · First: 29.08.2026 00:30 · 📰 0 src / 2 articles

Berlin has confirmed a compromise of its administrative network and is facing Rhysida leak-site extortion after the group publicly posted a Berlin entry on August 28. Available evidence ties related data outflow to mid-August activity, and the public claim asserts 5.79 TB of data and about 1.44 million files, including personal information on 12,076 individuals. Berlin says it will not pay the attacker, affected departments were isolated and later reconnected, and forensic scanning is still underway. Officials say there is no evidence election data was compromised, but the exact scope of stolen material and what may ultimately be published remain unconfirmed.

Claude infostealer session-hijack campaign

Campaign

Updated: 31.08.2026 15:11 · First: 31.08.2026 15:11 · 📰 1 src / 1 articles · H score: 38

A campaign is abusing stolen Claude sessions to enter affected accounts, drain usage limits, and force protective sign-outs. Anthropic says the session material came from infostealer malware on users' computers, including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer (AMOS) on some macOS devices. The company has signed out compromised sessions, removed saved payment methods, and refunded unauthorized charges. Users whose limits refilled and then drained without active use were told that account misuse was the likely cause.

Aurora campaign expands across multiple victims

Campaign

Updated: 31.08.2026 14:47 · First: 31.08.2026 14:47 · 📰 1 src / 1 articles · H score: 24

The Aurora (aka Aur0ra) ransomware operator used Cursor Agent with Claude Sonnet to assist hands-on exploitation against 10 targets between April 8 and May 21, 2026, extending a broader intrusion campaign across multiple victims. The activity increased the operator’s reach by combining AI-assisted tasking with direct exploitation work.

Anthropic Compliance API adds local session transcript endpoints for Claude Code

Security Tool/Service

Updated: 31.08.2026 14:31 · First: 31.08.2026 14:31 · 📰 1 src / 1 articles · H score: 11

Anthropic expanded the Compliance API for Claude Code with local session transcript endpoints, giving security teams better visibility into endpoint-side agent activity and governance over local AI agents on developer machines. The update surfaces `text`, `tool_use`, and `tool_result` blocks from local sessions, which helps track bash commands, file access, and MCP activity. It still leaves coverage gaps around local hooks, bypass modes, and non-Anthropic runtimes.

U.S. extradition and charges in sextortion case

Law Enforcement

Updated: 31.08.2026 12:22 · First: 31.08.2026 12:22 · 📰 1 src / 1 articles · H score: 14

Adekunle and Olawale were extradited to the U.S. and charged in a sextortion case tied to the deaths of two minor victims in Mississippi and North Carolina. The case centers on online blackmail that used stolen explicit images and threats to pressure victims. The suspects were arrested in Nigeria in August 2023 during Operation Artemis, a joint effort targeting sextortion rings. The prosecution raises the stakes for cross-border sextortion crews that prey on minors and other vulnerable users.

Fire Ant TacTap and BridgeAgent malware activity on IOS XR and Linux hosts

Malware Activity

Updated: 31.08.2026 12:04 · First: 31.08.2026 12:04 · 📰 2 src / 2 articles · H score: 26

The Fire Ant toolset added TacTap credential collection and a BridgeAgent Linux backdoor to its router-focused intrusion set, extending persistent access across Cisco IOS XR and Linux management hosts and increasing the risk of credential theft and packet capture.

Microsoft Defender Antivirus false 'turned off' alerts after latest updates

Security Tool/Service

Updated: 31.08.2026 11:29 · First: 31.08.2026 11:29 · 📰 1 src / 1 articles · H score: 11

Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though protection remains active. The warnings appear in the Windows Security app and can prompt users to click to turn Defender back on. The issue has been present in the Release Preview Channel since June and now includes Windows 11 26H1 and Windows Server 2025. Microsoft says a fix will ship in a future Microsoft Defender Antivirus update.

Infostealer malware hijacks Claude sessions

Malware Activity

Updated: 30.08.2026 17:30 · First: 30.08.2026 17:30 · 📰 1 src / 1 articles · H score: 36

Anthropic warned that infostealer malware is stealing Claude login sessions from infected PCs, letting attackers reuse them for account access and consumption of usage. The company is signing out affected users, removing saved payment methods, and refunding charges it identifies as unauthorized. Anthropic tied the activity to Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer (AMOS), with infections likely arriving through downloads or malicious apps.

Malicious Chrome and Edge browser-extension campaign

Campaign

Updated: 30.08.2026 17:17 · First: 30.08.2026 17:17 · 📰 1 src / 1 articles · H score: 16

A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto theft, credential theft, and browser-history exfiltration. The operation appears to have been active since early 2024, and one extension reached 70,000 Chrome users and 10,000 Edge installs before turning malicious. The campaign matters because its modular design and automatic-update abuse let attackers scale payload delivery across multiple extensions.

TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign

Campaign

Updated: 30.08.2026 10:36 · First: 30.08.2026 10:36 · 📰 2 src / 2 articles · H score: 37

The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk across multiple sectors. The lure pushes victims into Windows Terminal or PowerShell, where the payload can execute more reliably. The chain deploys a Python reverse-tunnel backdoor that grants persistent internal network access and reconnaissance capability. The intrusion path can also support data exfiltration and ransomware deployment.

Avada/Fusion Builder zero-click RCE (CVE-2026-18431)

Vulnerability

Updated: 27.08.2026 00:33 · First: 27.08.2026 00:33 · 📰 2 src / 2 articles · H score: 44

CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that lets an unauthenticated attacker trigger arbitrary PHP code execution and complete site compromise on affected WordPress servers. The flaw affects Avada up to 7.16 and Fusion Builder up to 3.16, with exposure limited to sites running both vulnerable components. Argus reproduced the six-step chain on July 30, Wordfence publicly detailed it on 2026-08-26, and ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25. The disclosed chain can also support malware planting, database access, rogue admin accounts, and malicious redirects on vulnerable sites.

Brave browser 1.94 adds Email Aliases and OPAQUE-based account authentication

Security Tool/Service

Updated: 29.08.2026 17:19 · First: 29.08.2026 17:19 · 📰 1 src / 1 articles · H score: 11

Brave browser 1.94 adds Email Aliases and strengthens Brave Accounts with OPAQUE-based authentication, reducing exposure of real email addresses and login secrets.

Manchester Airports Group customer booking and Wi-Fi sign-up data leak

Data Leak

Updated: 27.08.2026 16:00 · First: 27.08.2026 16:00 · 📰 2 src / 2 articles · H score: 68

Manchester Airports Group (MAG) disclosed unauthorized access to customer booking and in-airport Wi-Fi sign-up data tied to services across three UK airports. The exposed records included email addresses, phone numbers, vehicle registration numbers and postcodes, creating risk of phishing, smishing and unwanted contact. MAG said it contained the issue, contacted affected customers and temporarily suspended its Manage My Booking service. The reporting also noted that the affected system did not contain bank or payment details.

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 4 articles · H score: 51

PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the print management software. The company released an emergency patch for v25 and v26 and said it has confirmed customer incidents involving Internet-exposed PaperCut Application Servers. PaperCut also shared indicators of compromise, including suspicious activity from pc-app.exe and altered or missing server.log files, and told customers to restrict exposure with firewall rules or network access controls.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 20:12 · First: 28.08.2026 20:12 · 📰 2 src / 2 articles · H score: 51

PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code execution on susceptible instances. Huntress observed limited exploitation in two customer environments, including Base64-encoded commands and a Java `.class` file used for post-exploitation activity. PaperCut issued a second emergency patch with additional hardening, and exposed deployments should be removed from public access immediately.

PaperCut customer confirmed compromise incidents

Incident

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 3 articles · H score: 40

PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software. PaperCut released emergency patches for v25 and v26 and urged operators of Internet-exposed Application Servers to restrict access to trusted IP addresses immediately. The company shared indicators of compromise tied to suspicious activity from pc-app.exe and server.log files that are missing, truncated, or deleted. The investigation is ongoing, and PaperCut has not identified the flaw, the attackers, or any post-compromise actions.

GiveWP WordPress plugin command execution flaw (CVE-2026-82222)

Vulnerability

Updated: 28.08.2026 21:18 · First: 28.08.2026 21:18 · 📰 1 src / 1 articles · H score: 14

CVE-2026-82222 leaves GiveWP WordPress sites vulnerable to unauthenticated arbitrary command execution, putting more than 100,000 installs at risk of server compromise. The flaw affects GiveWP through version 4.16.7.1 and chains an unsafe unserialize helper, attacker-controlled serialized objects in the donation flow, and a bundled-library gadget chain. Patchstack says the attack can start through an exposed registration action even when WordPress registration is disabled. GiveWP 4.16.7.2 was released on August 27 to block serialized data and restrict object creation during deserialization.

GiveWP 4.16.7.2 security update for CVE-2026-82222

Security Patch Release

Updated: 28.08.2026 21:18 · First: 28.08.2026 21:18 · 📰 1 src / 1 articles · H score: 15

GiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222, a maximum-severity flaw in its WordPress donation plugin that allowed arbitrary command execution on hosting servers. The update blocks serialized data during donation processing, restricts object creation at deserialization points, and removes stored payloads from affected databases. Administrators running GiveWP through 4.16.7.1 are urged to install the patch immediately because exposed sites remain vulnerable until they upgrade.

Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults

Security Tool/Service

Updated: 28.08.2026 19:20 · First: 28.08.2026 19:20 · 📰 1 src / 1 articles · H score: 15

Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client Hello (ECH), enables ECH GREASE by default, enforces Local Network Protection, and turns on Certificate Transparency by default. Participating carriers can also default 2G off, cutting downgrade paths, rogue base-station exposure, and SMS blaster risk.

Philippine nuclear research body ownCloud file leak

Data Leak

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 31

A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included nuclear records, employee personal information, and credential stores, creating theft and follow-on abuse risk.

Nuclear research body in Philippines hit by network compromise

Incident

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 33

A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The compromise is tied to CVE-2023-49105, a critical WebDAV authentication bypass that let the attacker access data without supplying credentials. The stolen material included research records, employee personal information, and credential stores, increasing follow-on compromise risk.

OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)

Vulnerability

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 43

CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The flaw is a WebDAV API authentication bypass that can let an attacker access, modify, or delete files when a victim username is known and signing keys are not configured. ownCloud core 10.6.0 through 10.13.0 are affected, and 10.13.1 fixes the issue.

Paylogix November data leak exposing sensitive records

Data Leak

Updated: 28.08.2026 18:35 · First: 28.08.2026 18:35 · 📰 1 src / 1 articles · H score: 72

The Paylogix data leak exposed Social Security numbers, passport numbers, taxpayer IDs, and insurance and medical records for at least 67,789 people, creating identity-theft and privacy risk. Attackers stole files from the company's network over several days in November. The Akira ransomware group took credit for the attack. The affected people were reported across South Carolina, New Hampshire, and Vermont.

Superior malicious extension installation campaign

Campaign

Updated: 28.08.2026 18:27 · First: 28.08.2026 18:27 · 📰 2 src / 2 articles · H score: 17

The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrome Web Store users. The operation has been active since February 2024 and reached at least 19 extensions across Google Chrome and Microsoft Edge, including one with an 80,000-user install base.