The intelligence desk for humans and AI agents. Primary sources, organized into operational context — what happened, who's hit, how bad, what's next. Updates on the tick.
CISA's federal remediation deadline for CVE-2026-8452, a Citrix NetScaler ADC/Gateway memory-corruption flaw in SAML message parsing, lands today, August 29, three days after the agency added it to its Known Exploited Vulnerabilities catalog on August 26. Citrix patched the CVSS 8.8 flaw on June 30 (versions 14.1-72.61 and 13.1-63.18+), describing it only as a denial-of-service issue, but watchTowr Labs published a proof-of-concept on August 14 showing the unauthenticated, network-reachable heap overflow chains into full remote code execution on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Security firms Previdian (formerly KEVIntel) and Defused subsequently observed real-world exploitation; per The Hacker News' reporting on that telemetry, 36 exploitation attempts from 12 unique attacker IP addresses were detected over 12 days, with attackers dropping web shells named x.php and z.php and running id/echo discovery commands. Shadowserver data reported by BleepingComputer counts over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances still reachable from the internet as of August 27-28, underscoring how much of the affected fleet has yet to remediate as the deadline arrives. No authentication or user interaction is required to exploit an unpatched, internet-facing appliance.
Key points
FLAW -- CVE-2026-8452 (CVSS 8.8) is a heap overflow in Citrix NetScaler ADC/Gateway's SAML SSO message parsing, network-reachable with no authentication or user interaction required.
PATCH GAP -- Citrix shipped the fix June 30, 2026 (14.1-72.61+, 13.1-63.18+) describing it as a denial-of-service bug; watchTowr Labs' August 14 proof-of-concept showed it actually chains into full unauthenticated remote code execution, which is why unpatched appliances are now under active attack.
EXPLOITATION -- Previdian and Defused telemetry, reported by The Hacker News, found 36 exploitation attempts from 12 unique attacker IPs over 12 days, with attackers dropping x.php/z.php web shells and running id/echo discovery commands on compromised appliances.
EXPOSURE -- Shadowserver data reported by BleepingComputer counts over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances still reachable from the internet as of August 27-28, indicating widespread unpatched exposure even as the federal deadline arrives.
SCOPE -- Exploitable only where NetScaler is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; CISA's KEV addition bundled five other actively exploited flaws (Microsoft SQL Server, Linux Kernel, two Red Hat components, Ajax.NET Professional) in the same August 26 batch.
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 30 Aug 2026 | Warning: FINAL WARNING
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
DPA reports: The Berlin state government has declined to comment on the demands made by hackers who targeted the city’s administrative data network two weeks ago, a spokeswoman said on Saturday. The government is also withholding information about which data the attackers accessed and exactly who is behind the cyberattack. “For reasons of investigative tactics,... Source
AJ Vicens and Raphael Satter report: U.S. officials are backpedaling on claims that several government agencies were hacked by Chinese spies, now saying that the organizations were among the hackers’ targets. In a freshly edited statement, the Justice Department said Friday that the U.S. Senate, the Federal Reserve, NASA, and others were “among the targets... Source
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
SuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim is South Plains Rural Health Services, Inc. (SPRHS), a nonprofit healthcare organization that has provided services to rural communities across West Texas for decades. The information... Source
A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical […]
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach. The post Hasbro Data Breach Exposed Employee Personal Information appeared first on SecurityWeek.
Nitin Naresh revisits the significant Star Health breach of 2024. Previous coverage of the hack-and-leak incident can be found linked in the Related section below this post, which includes coverage of threats made to the insurance firm’s executives, court injunctions that, of course, did not stop a threat actor from leaking data, and lawsuits against... Source
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]
An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities in internet-facing ownCloud and WordPress systems. The activity was uncovered after Hunt.io found an exposed […]
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.
The Binarly REsearch team used dynamic analysis to analyze model files on a large scale on Hugging Face and compared their results with scanners deployed on the platform. They categorized the 21 static-scanner evasion techniques behind common detection misses. Most of these were based on techniques or concepts that had already been documented in previous studies, which highlights an inherent limitation of static pattern matching.
Guess your too busy focusing on your clients then changing password and protecting your clients. We breached them through pm.livable.com. You can see screenshots and file tree in the proof section. Also bleepingcomputer we will send you the data so you can confirm it too. Were not bluffing BayView Real Estate guess you guys didn't learn your lesson from the 26 million lawsuit but now you will. The following data was stolen: 1. Corporate Identity and Admin Profiles 6 Individual Administrator Profiles: Complete web profile exports, account configurations, and visible permission mappings for six active employees: - Breanna Tiu - Diana Nguyen - Elise Hou - Jeanne David - Wendy Wu - Zhen Deng 2. High-Density Financial Database Dumping - Building Statement Reports: The core database extraction file (Building-nK37xrmRYcoCMHymv-statements-report.pdf - Sample Distribution Summaries: Multi-property accounting records detailing exactly how utility expenses are balanced and divided across real estate assets (including specialized trackers for 394 Midway Street). 3. Operational Infrastructure & Platform Playbooks - Internal Corporate Handbooks: Step-by-step business guides detailing how money is processed and collected: - Bill & Collect: Manuals for handling payments routed directly through Livable's platform. - Convergent: Frameworks detailing workflows where tenants pay the property group directly. - Software Integration Guides: Training documentation teaching personnel how to map customer data tables between platforms: - AppFolio ID and Charges mapping logs - Yardi system integration guides Complete Video Tutorial Playbooks: Over 100 MB of internal instructional videos teaching how to navigate the portal, manage profiles, and export tenant lists: - 01 PM Portal Intro - 02 How to Setup a Tenant's Account - 03 How to Access the Tenant's Account - 04 How to Access the Allocation Table - 05 Move Out Processing - 06 Export tenant charges and download CSV files - PM Portal Training - Portfolio Overview & Building Profile - PM Portal Training - Resident Profile & Allocation Tables - PM Portal Training - Utility Recovery Proforma, Add a Building, Export Monthly Tenant Charges 4. Tenant Communication Scripts & Branding Graphics - Official Digital Graphics: High-resolution templates used by the company for onboarding and platform access: - Bill & Collect Welcome Email interface maps - Convergent Welcome Email branding templates - Resident Portal dashboard graphical layouts - Physical Outreach Letters: Word and PDF versions of letters sent directly to tenants regarding payments and billing statuses: - Bill & Collect / Convergent / Net Zero Billing Tenant Welcome Letters - Delinquency Template notification forms - Physical Billing Statements and Net Zero Statement layouts 5. Legal Leases & Regional Utility Addenda - 30-Day Notice Templates: Legally binding notification documents used to alter tenant agreements (30 Day Notice_Billing Method Change, Notice of Supplier Change, and Notice of Supplier and Allocation Formula Change). - Geographic Lease Addenda Collections: Specific legal attachments containing the rules and formulas for utility billing across different municipal districts: - California Addenda (including localized frameworks for Hayward and Los Angeles) - National Utility Addenda / US Addenda (including localized parameters for Seattle) - Exhibit B - Submetered Water regulatory documents - Lease Addendum Guide instructional packets Uncompressed size: 216653153 bytes(216.6 MB) compressed size: 78.0MB mirror 1: https://pixeldrain.com/u/pc8VfBLf mirror 2: https://fex.net/s/vydmesb
Lawrence Abrams reports: Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to... Source
Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING
This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING
This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=
The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first on CyberScoop.
Most of a container's vulnerabilities come from the base image. How to harden Docker images, why hardening is ongoing, and how to patch the base you already run. Category: Guides & Best Practices
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the […]
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is directed to retrieve. This issue may lead to arbitrary code execution as root if specific sensitive files are overwritten. To remediate this issue, customers should upgrade amazon-ssm-agent to version 3.3.4515.0 or later. Impacted versions: Amazon amazon-ssm-agent from 2.0.767.0 to 3.3.4364.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption. The timing matters. The White House points to the rapid expansion of […]
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the intended cache directory, to any path writable by the user running awsdac. Depending on the file written, this can lead to arbitrary code execution. Leveraging this issue requires processing a definition file from an untrusted source. This can occur when: - awsdac is run without definition trust restrictions (versions prior to 0.22.4 had no trust distinction; version 0.22.4 and later require the −−allow−untrusted−definitions flag), or - a definition file is loaded from the local filesystem ('Type: LocalFile'), which bypasses the definition URL allowlist. CI/CD environments that process definition files from untrusted or semi-trusted sources are the primary risk scenario. awsdac is a client-side CLI tool that renders architecture diagrams locally. This issue does not affect any AWS service, AWS account, or customer data. The impact is limited to the machine on which awsdac runs. Impacted versions: awsdac: versions 0.10 through 0.23 (inclusive) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem