//threat-feed.ai

free to use · primary sources · no accounts

The intelligence desk for humans and AI agents. Primary sources, organized into operational context — what happened, who's hit, how bad, what's next. Updates on the tick.

Fetching latest threat intelligence…
Daily briefing
1 crit 2 high 17 med
Lead · top story
Vulnerability/CVE · Help Net Security

Patch Citrix NetScaler ADC/Gateway for CVE-2026-8452 -- CISA KEV Deadline Today, 22,000+ Appliances Still Exposed

CISA's federal remediation deadline for CVE-2026-8452, a Citrix NetScaler ADC/Gateway memory-corruption flaw in SAML message parsing, lands today, August 29, three days after the agency added it to its Known Exploited Vulnerabilities catalog on August 26. Citrix patched the CVSS 8.8 flaw on June 30 (versions 14.1-72.61 and 13.1-63.18+), describing it only as a denial-of-service issue, but watchTowr Labs published a proof-of-concept on August 14 showing the unauthenticated, network-reachable heap overflow chains into full remote code execution on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Security firms Previdian (formerly KEVIntel) and Defused subsequently observed real-world exploitation; per The Hacker News' reporting on that telemetry, 36 exploitation attempts from 12 unique attacker IP addresses were detected over 12 days, with attackers dropping web shells named x.php and z.php and running id/echo discovery commands. Shadowserver data reported by BleepingComputer counts over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances still reachable from the internet as of August 27-28, underscoring how much of the affected fleet has yet to remediate as the deadline arrives. No authentication or user interaction is required to exploit an unpatched, internet-facing appliance.

Key points
  • FLAW -- CVE-2026-8452 (CVSS 8.8) is a heap overflow in Citrix NetScaler ADC/Gateway's SAML SSO message parsing, network-reachable with no authentication or user interaction required.
  • PATCH GAP -- Citrix shipped the fix June 30, 2026 (14.1-72.61+, 13.1-63.18+) describing it as a denial-of-service bug; watchTowr Labs' August 14 proof-of-concept showed it actually chains into full unauthenticated remote code execution, which is why unpatched appliances are now under active attack.
  • EXPLOITATION -- Previdian and Defused telemetry, reported by The Hacker News, found 36 exploitation attempts from 12 unique attacker IPs over 12 days, with attackers dropping x.php/z.php web shells and running id/echo discovery commands on compromised appliances.
  • EXPOSURE -- Shadowserver data reported by BleepingComputer counts over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances still reachable from the internet as of August 27-28, indicating widespread unpatched exposure even as the federal deadline arrives.
  • SCOPE -- Exploitable only where NetScaler is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; CISA's KEV addition bundled five other actively exploited flaws (Microsoft SQL Server, Linux Kernel, two Red Hat components, Ajax.NET Professional) in the same August 26 batch.
Identity & Access · The Hacker News

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

SaaS Breach · DataBreaches.net

De: Hackers demand 30 bitcoin from Berlin as sensitive data breach widens

DPA reports: The Berlin state government has declined to comment on the demands made by hackers who targeted the city’s administrative data network two weeks ago, a spokeswoman said on Saturday. The government is also withholding information about which data the attackers accessed and exactly who is behind the cyberattack. “For reasons of investigative tactics,... Source

Vulnerability/CVE · DataBreaches.net

US officials backpedal on claims that government agencies were hacked by Chinese

AJ Vicens and Raphael Satter report: U.S. officials are backpedaling on claims that several government agencies were hacked by Chinese spies, now saying that the organizations were among the hackers’ targets. In a freshly edited statement, the Justice Department said Friday that the U.S. Senate, the Federal Reserve, NASA, and others were “among the targets... Source

Uncategorized · Bleeping Computer

Brave browser adds email aliases to help users evade tracking

The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]

Ransomware · DataBreaches.net

PEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silent

SuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim is South Plains Rural Health Services, Inc. (SPRHS), a nonprofit healthcare organization that has provided services to rural communities across West Texas for decades. The information... Source

Vulnerability/CVE · Security Affairs

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical […]

SaaS Breach · SecurityWeek

Hasbro Data Breach Exposed Employee Personal Information

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach. The post Hasbro Data Breach Exposed Employee Personal Information appeared first on SecurityWeek.

SaaS Breach · DataBreaches.net

Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder

Nitin Naresh revisits the significant Star Health breach of 2024. Previous coverage of the hack-and-leak incident can be found linked in the Related section below this post, which includes coverage of threats made to the insurance firm’s executives, court injunctions that, of course, did not stop a threat actor from leaking data, and lawsuits against... Source

Ransomware · Security Affairs

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]

Vulnerability/CVE · Security Affairs

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities in internet-facing ownCloud and WordPress systems. The activity was uncovered after Hunt.io found an exposed […]

Malware/Infostealer · Microsoft Security Blog

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

AI Security · Binarly

MLTracer: Syscall-Based Malicious Model Detection and Labeling, with Static-Scanner Evasion Taxonomy

The Binarly REsearch team used dynamic analysis to analyze model files on a large scale on Hugging Face and compared their results with scanners deployed on the platform. They categorized the 21 static-scanner evasion techniques behind common detection misses. Most of these were based on techniques or concepts that had already been documented in previous studies, which highlights an inherent limitation of static pattern matching.

SaaS Breach · Ransomware.live

🏴‍☠️ Shadowbyt3$ has just published a new victim : BayView Real Estate

Guess your too busy focusing on your clients then changing password and protecting your clients. We breached them through pm.livable.com. You can see screenshots and file tree in the proof section. Also bleepingcomputer we will send you the data so you can confirm it too. Were not bluffing BayView Real Estate guess you guys didn't learn your lesson from the 26 million lawsuit but now you will. The following data was stolen: 1. Corporate Identity and Admin Profiles 6 Individual Administrator Profiles: Complete web profile exports, account configurations, and visible permission mappings for six active employees: - Breanna Tiu - Diana Nguyen - Elise Hou - Jeanne David - Wendy Wu - Zhen Deng 2. High-Density Financial Database Dumping - Building Statement Reports: The core database extraction file (Building-nK37xrmRYcoCMHymv-statements-report.pdf - Sample Distribution Summaries: Multi-property accounting records detailing exactly how utility expenses are balanced and divided across real estate assets (including specialized trackers for 394 Midway Street). 3. Operational Infrastructure & Platform Playbooks - Internal Corporate Handbooks: Step-by-step business guides detailing how money is processed and collected: - Bill & Collect: Manuals for handling payments routed directly through Livable's platform. - Convergent: Frameworks detailing workflows where tenants pay the property group directly. - Software Integration Guides: Training documentation teaching personnel how to map customer data tables between platforms: - AppFolio ID and Charges mapping logs - Yardi system integration guides Complete Video Tutorial Playbooks: Over 100 MB of internal instructional videos teaching how to navigate the portal, manage profiles, and export tenant lists: - 01 PM Portal Intro - 02 How to Setup a Tenant's Account - 03 How to Access the Tenant's Account - 04 How to Access the Allocation Table - 05 Move Out Processing - 06 Export tenant charges and download CSV files - PM Portal Training - Portfolio Overview & Building Profile - PM Portal Training - Resident Profile & Allocation Tables - PM Portal Training - Utility Recovery Proforma, Add a Building, Export Monthly Tenant Charges 4. Tenant Communication Scripts & Branding Graphics - Official Digital Graphics: High-resolution templates used by the company for onboarding and platform access: - Bill & Collect Welcome Email interface maps - Convergent Welcome Email branding templates - Resident Portal dashboard graphical layouts - Physical Outreach Letters: Word and PDF versions of letters sent directly to tenants regarding payments and billing statuses: - Bill & Collect / Convergent / Net Zero Billing Tenant Welcome Letters - Delinquency Template notification forms - Physical Billing Statements and Net Zero Statement layouts 5. Legal Leases & Regional Utility Addenda - 30-Day Notice Templates: Legally binding notification documents used to alter tenant agreements (30 Day Notice_Billing Method Change, Notice of Supplier Change, and Notice of Supplier and Allocation Formula Change). - Geographic Lease Addenda Collections: Specific legal attachments containing the rules and formulas for utility billing across different municipal districts: - California Addenda (including localized frameworks for Hayward and Los Angeles) - National Utility Addenda / US Addenda (including localized parameters for Seattle) - Exhibit B - Submetered Water regulatory documents - Lease Addendum Guide instructional packets Uncompressed size: 216653153 bytes(216.6 MB) compressed size: 78.0MB mirror 1: https://pixeldrain.com/u/pc8VfBLf mirror 2: https://fex.net/s/vydmesb

SaaS Breach · DataBreaches.net

McKesson is investigating a cybersecurity incident after ShinyHunters claims patient data theft

Lawrence Abrams reports: Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to... Source

SaaS Breach · Ransomware.live

🏴‍☠️ Shinyhunters has just published a new victim : McKesson Corporation

Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING

SaaS Breach · Ransomware.live

🏴‍☠️ Shinyhunters has just published a new victim : Elekta AB

This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING

SaaS Breach · Bleeping Computer

McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]

AI Security · Unit42 Palo Alto

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

Vulnerability/CVE · The Hacker News

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment

Vulnerability/CVE · Aikido Security

Popular code generator for TanStack Query hit by supply chain worm

A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats

Vulnerability/CVE · The Hacker News

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=

Ransomware · CyberScoop

ATF confirms cyberattack hit system containing info on its investigation targets

The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first on CyberScoop.

Vulnerability/CVE · Aikido Security

Securing Docker images

Most of a container's vulnerabilities come from the base image. How to harden Docker images, why hardening is ongoing, and how to patch the base you already run. Category: Guides & Best Practices

SaaS Breach · Security Affairs

Love Electric Breach: 877,000 Driver Records Offered for $600

Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the […]

Vulnerability/CVE · Bleeping Computer

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]

Vulnerability/CVE · Dark Reading

Offensive Security Investments Surge as AI Threats Increase

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.

Cloud Security · AWS Security Bulletins

CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent

Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is directed to retrieve. This issue may lead to arbitrary code execution as root if specific sensitive files are overwritten. To remediate this issue, customers should upgrade amazon-ssm-agent to version 3.3.4515.0 or later. Impacted versions: Amazon amazon-ssm-agent from 2.0.767.0 to 3.3.4364.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

OT/ICS · Security Affairs

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption. The timing matters. The White House points to the rapid expansion of […]

Vulnerability/CVE · The Hacker News

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

SaaS Breach · ReversingLabs

Shai-Hulud worm arrests: What you need to know

The alleged actors behind one of the most active supply chain threats were arrested in Australia — but this is not the end of Shai-Hulud.

Cloud Security · AWS Security Bulletins

CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the intended cache directory, to any path writable by the user running awsdac. Depending on the file written, this can lead to arbitrary code execution. Leveraging this issue requires processing a definition file from an untrusted source. This can occur when: - awsdac is run without definition trust restrictions (versions prior to 0.22.4 had no trust distinction; version 0.22.4 and later require the −−allow−untrusted−definitions flag), or - a definition file is loaded from the local filesystem ('Type: LocalFile'), which bypasses the definition URL allowlist. CI/CD environments that process definition files from untrusted or semi-trusted sources are the primary risk scenario. awsdac is a client-side CLI tool that renders architecture diagrams locally. This issue does not affect any AWS service, AWS account, or customer data. The impact is limited to the machine on which awsdac runs. Impacted versions: awsdac: versions 0.10 through 0.23 (inclusive) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Vulnerability/CVE · The Hacker News

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem