Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:04 31/08/2026 UTC
  • Malware Activity H score 36 Infostealer malware hijacks Claude sessions Anthropic says infostealer malware is stealing Claude login sessions and reusing them for account access, prompting user sign-outs, payment-method removals, and charge refunds as the latest development expands real-world impact beyond credential theft.
  • Campaign H score 36 TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign The TerminalFix campaign’s fake Cloudflare CAPTCHA lure is now linked to malicious PowerShell execution that deploys a Python reverse-tunnel backdoor, advancing intrusions toward persistent internal access, reconnaissance, and potential exfiltration/ransomware staging.
  • Campaign H score 16 Malicious Chrome and Edge browser-extension campaign Attackers abusing legitimate Chrome/Edge extensions for malware delivery put large user bases at risk for crypto and credential theft, and the latest findings highlight how modular design and auto-update abuse let the operation scale.
Last updated: 23:49 30/08/2026 UTC

Latest updates

Browse →

Infostealer malware hijacks Claude sessions

Malware Activity

Updated: 30.08.2026 17:30 · First: 30.08.2026 17:30 · 📰 1 src / 1 articles · H score: 36

Anthropic warned that infostealer malware is stealing Claude login sessions from infected PCs, letting attackers reuse them for account access and consumption of usage. The company is signing out affected users, removing saved payment methods, and refunding charges it identifies as unauthorized. Anthropic tied the activity to Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer (AMOS), with infections likely arriving through downloads or malicious apps.

Malicious Chrome and Edge browser-extension campaign

Campaign

Updated: 30.08.2026 17:17 · First: 30.08.2026 17:17 · 📰 1 src / 1 articles · H score: 16

A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto theft, credential theft, and browser-history exfiltration. The operation appears to have been active since early 2024, and one extension reached 70,000 Chrome users and 10,000 Edge installs before turning malicious. The campaign matters because its modular design and automatic-update abuse let attackers scale payload delivery across multiple extensions.

TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign

Campaign

Updated: 30.08.2026 10:36 · First: 30.08.2026 10:36 · 📰 1 src / 1 articles · H score: 36

The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk across multiple sectors. The lure pushes victims into Windows Terminal or PowerShell, where the payload can execute more reliably. The chain deploys a Python reverse-tunnel backdoor that grants persistent internal network access and reconnaissance capability. The intrusion path can also support data exfiltration and ransomware deployment.

Avada/Fusion Builder zero-click RCE (CVE-2026-18431)

Vulnerability

Updated: 27.08.2026 00:33 · First: 27.08.2026 00:33 · 📰 2 src / 2 articles · H score: 44

CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that lets an unauthenticated attacker trigger arbitrary PHP code execution and complete site compromise on affected WordPress servers. The flaw affects Avada up to 7.16 and Fusion Builder up to 3.16, with exposure limited to sites running both vulnerable components. Argus reproduced the six-step chain on July 30, Wordfence publicly detailed it on 2026-08-26, and ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25. The disclosed chain can also support malware planting, database access, rogue admin accounts, and malicious redirects on vulnerable sites.

Brave browser 1.94 adds Email Aliases and OPAQUE-based account authentication

Security Tool/Service

Updated: 29.08.2026 17:19 · First: 29.08.2026 17:19 · 📰 1 src / 1 articles · H score: 11

Brave browser 1.94 adds Email Aliases and strengthens Brave Accounts with OPAQUE-based authentication, reducing exposure of real email addresses and login secrets.

Berlin's state government hit by data theft breach

Incident

Updated: 29.08.2026 00:30 · First: 29.08.2026 00:30 · 📰 1 src / 1 articles · H score: 70

Berlin's state government confirmed a compromise of the city's state administrative network and said it is facing an extortion attempt, raising the risk that personal or other non-public data was taken. Forensic work found additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated August 7-12, 2026. The network was partially cut off and later reconnected on August 23, while forensic scanning continues. Officials said they are not paying the attackers and that the investigation remains open.

Manchester Airports Group customer booking and Wi-Fi sign-up data leak

Data Leak

Updated: 27.08.2026 16:00 · First: 27.08.2026 16:00 · 📰 2 src / 2 articles · H score: 68

Manchester Airports Group (MAG) disclosed unauthorized access to customer booking and in-airport Wi-Fi sign-up data tied to services across three UK airports. The exposed records included email addresses, phone numbers, vehicle registration numbers and postcodes, creating risk of phishing, smishing and unwanted contact. MAG said it contained the issue, contacted affected customers and temporarily suspended its Manage My Booking service. The reporting also noted that the affected system did not contain bank or payment details.

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 4 articles · H score: 51

PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the print management software. The company released an emergency patch for v25 and v26 and said it has confirmed customer incidents involving Internet-exposed PaperCut Application Servers. PaperCut also shared indicators of compromise, including suspicious activity from pc-app.exe and altered or missing server.log files, and told customers to restrict exposure with firewall rules or network access controls.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 20:12 · First: 28.08.2026 20:12 · 📰 2 src / 2 articles · H score: 51

PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code execution on susceptible instances. Huntress observed limited exploitation in two customer environments, including Base64-encoded commands and a Java `.class` file used for post-exploitation activity. PaperCut issued a second emergency patch with additional hardening, and exposed deployments should be removed from public access immediately.

PaperCut customer confirmed compromise incidents

Incident

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 3 articles · H score: 40

PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software. PaperCut released emergency patches for v25 and v26 and urged operators of Internet-exposed Application Servers to restrict access to trusted IP addresses immediately. The company shared indicators of compromise tied to suspicious activity from pc-app.exe and server.log files that are missing, truncated, or deleted. The investigation is ongoing, and PaperCut has not identified the flaw, the attackers, or any post-compromise actions.

GiveWP WordPress plugin command execution flaw (CVE-2026-82222)

Vulnerability

Updated: 28.08.2026 21:18 · First: 28.08.2026 21:18 · 📰 1 src / 1 articles · H score: 14

CVE-2026-82222 leaves GiveWP WordPress sites vulnerable to unauthenticated arbitrary command execution, putting more than 100,000 installs at risk of server compromise. The flaw affects GiveWP through version 4.16.7.1 and chains an unsafe unserialize helper, attacker-controlled serialized objects in the donation flow, and a bundled-library gadget chain. Patchstack says the attack can start through an exposed registration action even when WordPress registration is disabled. GiveWP 4.16.7.2 was released on August 27 to block serialized data and restrict object creation during deserialization.

GiveWP 4.16.7.2 security update for CVE-2026-82222

Security Patch Release

Updated: 28.08.2026 21:18 · First: 28.08.2026 21:18 · 📰 1 src / 1 articles · H score: 15

GiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222, a maximum-severity flaw in its WordPress donation plugin that allowed arbitrary command execution on hosting servers. The update blocks serialized data during donation processing, restricts object creation at deserialization points, and removes stored payloads from affected databases. Administrators running GiveWP through 4.16.7.1 are urged to install the patch immediately because exposed sites remain vulnerable until they upgrade.

Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults

Security Tool/Service

Updated: 28.08.2026 19:20 · First: 28.08.2026 19:20 · 📰 1 src / 1 articles · H score: 15

Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client Hello (ECH), enables ECH GREASE by default, enforces Local Network Protection, and turns on Certificate Transparency by default. Participating carriers can also default 2G off, cutting downgrade paths, rogue base-station exposure, and SMS blaster risk.

Philippine nuclear research body ownCloud file leak

Data Leak

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 31

A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included nuclear records, employee personal information, and credential stores, creating theft and follow-on abuse risk.

Nuclear research body in Philippines hit by network compromise

Incident

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 33

A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The compromise is tied to CVE-2023-49105, a critical WebDAV authentication bypass that let the attacker access data without supplying credentials. The stolen material included research records, employee personal information, and credential stores, increasing follow-on compromise risk.

OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)

Vulnerability

Updated: 28.08.2026 18:56 · First: 28.08.2026 18:56 · 📰 1 src / 1 articles · H score: 43

CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The flaw is a WebDAV API authentication bypass that can let an attacker access, modify, or delete files when a victim username is known and signing keys are not configured. ownCloud core 10.6.0 through 10.13.0 are affected, and 10.13.1 fixes the issue.

Paylogix November data leak exposing sensitive records

Data Leak

Updated: 28.08.2026 18:35 · First: 28.08.2026 18:35 · 📰 1 src / 1 articles · H score: 72

The Paylogix data leak exposed Social Security numbers, passport numbers, taxpayer IDs, and insurance and medical records for at least 67,789 people, creating identity-theft and privacy risk. Attackers stole files from the company's network over several days in November. The Akira ransomware group took credit for the attack. The affected people were reported across South Carolina, New Hampshire, and Vermont.

Superior malicious extension installation campaign

Campaign

Updated: 28.08.2026 18:27 · First: 28.08.2026 18:27 · 📰 2 src / 2 articles · H score: 17

The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrome Web Store users. The operation has been active since February 2024 and reached at least 19 extensions across Google Chrome and Microsoft Edge, including one with an 80,000-user install base.

SVG voicemail phishing campaign

Campaign

Updated: 28.08.2026 16:00 · First: 28.08.2026 16:00 · 📰 1 src / 1 articles · H score: 42

The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and follow-on compromise. Attackers used SVG attachments disguised as voicemail files to smuggle obfuscated JavaScript past filters. The campaign ran in waves from June 1 through August 4, 2026, and was still active when the analysis closed.

Unitree G1 EDU BLE provisioning root RCE (CVE-2026-76640)

Vulnerability

Updated: 28.08.2026 15:07 · First: 28.08.2026 15:07 · 📰 1 src / 1 articles · H score: 28

Unitree G1 EDU owners face a disclosed CVE-2026-76640 chain that can turn BLE proximity into root code execution on the Locomotion PC. The initial BLE write path accepts the bootstrap interaction without Bluetooth pairing, while later Wi‑Fi provisioning operations depend on the application's authenticated BLE state. Researchers tied the chain to a buffer overflow in provisioning and said no confirmed fixed firmware release was verified in accessible guidance. The cloud-account ownership check used in the proof-of-concept was patched in July 2026, but that does not provide a verified firmware remediation target for the vulnerability itself.

Hasbro Massachusetts employee data breach

Data Leak

Updated: 28.08.2026 14:46 · First: 28.08.2026 14:46 · 📰 1 src / 1 articles · H score: 40

The Hasbro employee data breach exposed personal and financial information tied to a compromised account, creating identity-theft and fraud risk for affected workers. A Massachusetts filing says the impacted records included Social Security numbers, financial account information, credit/debit card numbers, and driver's license information for 436 employees. Hasbro said it disabled the compromised employee account, terminated unauthorized access, and added safeguards. The disclosure centers on sensitive employee data rather than customer information.

ZBT router firmware factory implants (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 13:58 · First: 28.08.2026 13:58 · 📰 1 src / 1 articles · H score: 43

VulnCheck disclosed two previously undocumented factory implants in ZBT router firmware, exposing affected devices to unauthenticated root command execution. The implants are tracked as CVE-2026-74232 and CVE-2026-74233 and affect routers built by Shenzhen Zhibotong Electronics (ZBT). One implant, SPEAKINGSTONE, uses a hardcoded C2 path, while DARKLANTERN listens on UDP/9992 with weak authentication. Public evidence shows exposed devices and proof-of-concept status for CVE-2026-74233, making the flaw set operationally risky for deployed routers.

ServiceNow AI Platform security patch release (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)

Security Patch Release

Updated: 28.08.2026 13:29 · First: 28.08.2026 13:29 · 📰 1 src / 1 articles · H score: 36

ServiceNow released patches for ServiceNow AI Platform flaws that could enable code injection, SQL injection, privilege escalation, and sandbox escape attacks across cloud and self-hosted instances. The advisory covered CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, with CVE-2026-6876 fixed in the same release. ServiceNow said it was not aware of active malicious exploitation and urged customers to promptly apply updates or upgrade to patched releases.

CPanel & WHM security patch release for CVE-2026-65643

Security Patch Release

Updated: 28.08.2026 12:45 · First: 28.08.2026 12:45 · 📰 1 src / 1 articles · H score: 46

cPanel released patched builds for CVE-2026-65643 in cPanel & WHM, closing a flaw that could let an authenticated domain user reach root code execution on supported servers.

CPanel & WHM parked/addon domain root code execution flaw (CVE-2026-65643)

Vulnerability

Updated: 28.08.2026 12:45 · First: 28.08.2026 12:45 · 📰 1 src / 1 articles · H score: 9

cPanel has patched CVE-2026-65643 in cPanel & WHM, a flaw in parked and addon domain handling that could let an authenticated user reach root code execution on all supported versions. The fix is available in updated builds for the supported branches, including 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP Squared). Administrators can install the patch now, and unsupported releases must be upgraded to receive it.

Microsoft KB5120998 starts rolling out administrator protection on Windows 11

Security Tool/Service

Updated: 28.08.2026 12:10 · First: 28.08.2026 12:10 · 📰 1 src / 1 articles · H score: 11

A staged rollout of administrator protection is beginning in Windows 11 KB5120998, giving 25H2 and 24H2 devices just-in-time admin elevation controls. The feature adds profile separation and is intended to reduce elevation-of-privilege exposure while staying off by default. Administrators can enable it through Microsoft Intune or Group Policy.

HOOKEDGE backdoor deployment via macro-enabled Word documents

Malware Activity

Updated: 28.08.2026 11:20 · First: 28.08.2026 11:20 · 📰 1 src / 1 articles · H score: 23

The HOOKEDGE backdoor is being deployed through macro-enabled Microsoft Word documents, giving attackers a lightweight Windows batch foothold for remote command execution and data exfiltration. The payload uses webhook[.]site for command-and-control, staging, and exfiltration, which helps the traffic blend into normal web activity. The activity has been observed against government and diplomatic organizations in Romania, Spain, and Türkiye during late September 2025 to early April 2026.

Aurora ransomware Cursor Agent exploitation campaign

Campaign

Updated: 28.08.2026 11:00 · First: 28.08.2026 11:00 · 📰 1 src / 1 articles · H score: 5

The Aurora ransomware operators used Cursor Agent to streamline post-compromise exploitation across 10 victims, increasing the speed and consistency of their intrusions. They paired the AI tool with Claude Sonnet to scan victim environments, check privileges, install a VPN client, and run certificate attacks. The activity was observed between April 8 and May 26, 2026, showing how adversaries are folding AI assistants into ransomware operations.

Artifactory token-refresh via legacy credential endpoint security flaw

Vulnerability

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 2 src / 2 articles · H score: 44

Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeover risk for affected deployments. The flaw enabled privileged access through a weak refresh path rather than normal authentication. JFrog was alerted after the abuse was uncovered.

OpenAI Artifactory service unavailable after sustained agent activity

Service Disruption

Updated: 27.08.2026 21:36 · First: 27.08.2026 21:36 · 📰 1 src / 1 articles · H score: 29

OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outage signaled that the service had been pushed beyond its intended operating conditions. OpenAI later rebuilt Artifactory, revoked agent credentials, and tightened access controls to restore containment.