Skip to content
feed: live
>_0dayNews
Briefing · Aug 24-30, 2026

Week in Review: Aug 24-30, 2026

36 articles, seven days: PaperCut patched twice, ServiceNow CVSS 10.0 triple, ATF breach confirmed, APT28 resurfaces, five new CISA KEV entries.

tldr.txt
  • PaperCut NG/MF zero-day actively exploited Aug 28; second advisory Aug 29 for CVE-2026-81578 and CVE-2026-82078 after initial patch proved bypassable. Patch to 25.1.1 immediately.
  • ServiceNow patched three CVSS 10.0 flaws in AI-platform components. No public exploitation confirmed; high-value enterprise attack surface.
  • ATF confirmed a major Qilin ransomware breach. Scope of data exfiltration unconfirmed as of reporting.
  • ShinyHunters claimed 284M McKesson patient records. Unconfirmed by McKesson as of Aug 29. Treat figure as unverified.
  • Five new CISA KEV entries: Citrix NetScaler CVE-2026-8452, Oracle WebLogic CVE-2026-21962, ownCloud CVE-2023-49105, Gitea RCE. Active exploitation confirmed on all four.
  • APT28 HOOKEDGE backdoor targeting European governments in Romania, Spain, and Türkiye. Active campaign as of Aug 29.

36 articles. Seven days. The dominant theme: active exploitation outpaced patch deployment across enterprise platforms, with two separate federal-level breaches confirmed before the week closed.

PaperCut NG/MF: Zero-Day, Then a Second Patch

Two CVEs. Two patches in 48 hours.

PaperCut NG/MF was hit with an actively exploited zero-day on Aug 28: remote code execution, no authentication required. Vendor and independent researchers confirmed active exploitation within hours of disclosure. A patch shipped the same day.

Aug 29: a second advisory. CVE-2026-81578 and CVE-2026-82078 disclosed after researchers identified that the original patch was bypassable. Both CVEs confirmed against NVD. The patched release is 25.1.1.

Confidence breakdown:

  • Confirmed: Both CVEs, vendor advisories, active exploitation of the initial zero-day.
  • Confirmed: Bypass path for first patch. Second patch required.
  • Unknown: Whether active exploitation continued after second patch release.

PaperCut Zero-Day Under Active Exploitation | Second Patch Issued for Bypass CVEs.

ServiceNow: Three CVSS 10.0 Flaws in AI Platform

Maximum severity. Three vulnerabilities in ServiceNow’s AI-platform components each scored 10.0 on the CVSS scale.

Confidence:

  • Confirmed: CVSS 10.0 per ServiceNow advisories. Patches available in the Aug 29 release.
  • Unknown: Public exploitation as of reporting date.

High-value enterprise attack surface. No CVE IDs confirmed at time of publication. Watch NVD for assignments: that is when patch-management tooling catches up.

Full coverage.

ATF Breach: Qilin Ransomware

Confirmed. The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major ransomware breach following a Qilin group claim on Aug 28.

Confidence:

  • Confirmed: ATF acknowledged the breach and classified it as a major incident.
  • Confirmed: Qilin is the named threat actor per ATF statement.
  • Unconfirmed: Full scope of data accessed or operational systems affected as of reporting.

Track CISA and DOJ for official scope updates.

Full coverage.

McKesson: 284M Patient Records Claimed, Unconfirmed

ShinyHunters claimed on Aug 29 to have exfiltrated 284 million patient records from McKesson.

Confidence:

  • Confirmed: ShinyHunters published the claim with sample data.
  • Unconfirmed: McKesson had not confirmed a breach as of reporting.
  • Context: ShinyHunters has a documented history of overstating breach scope. Do not treat the 284M figure as verified until McKesson issues a statement.

Full coverage.

CISA KEV Additions This Week

Five new entries across four CVEs:

  • CVE-2026-8452 (Citrix NetScaler, Aug 27): Active exploitation confirmed. CISA federal patch deadline in effect. Coverage.
  • CVE-2026-21962 (Oracle WebLogic, Aug 25): KEV-listed. Confidence: CISA-confirmed. Coverage.
  • CVE-2023-49105 (ownCloud, Aug 29): KEV listing followed confirmed data exfiltration at a nuclear records operator. Coverage.
  • Gitea RCE (Aug 26): Active cryptominer campaign confirmed against unpatched instances. Coverage.
  • CVE-2026-18431 (Avada WordPress theme, Aug 27): Zero-click RCE. Patched. No KEV listing confirmed at time of writing; monitor. Coverage.

Round-Up

  • APT28 HOOKEDGE: Active backdoor campaign targeting European government networks in Romania, Spain, and Türkiye, per Aug 29 threat intel. Attribution confirmed by researchers. Coverage.
  • ZBT routers, factory implants: CVE-2026-74232 and CVE-2026-74233 confirmed factory-embedded backdoor functionality in ZBT WE3000 and related models. Coverage.
  • TerminalFix ClickFix: New campaign drops reverse-tunnel backdoor via Windows Terminal configuration lure. No CVE. Social engineering vector. Coverage.
  • CVE-2026-75759 (OIDCC): OIDC signature bypass allowing attacker-controlled tokens to be accepted as valid. Patched. Coverage.
  • CVE-2026-82329 (JFrog Artifactory): Default authentication bypass giving unauthenticated admin access. Patched. Coverage.
  • Microsoft Edge: Eight type-confusion RCE flaws patched in a single advisory. Coverage.
  • Berlin state network breach: Rhysida ransomware group claimed 5TB exfiltration from Berlin government infrastructure. City confirmed the breach and declined to pay. Coverage.
  • Manchester Airports Group: FulcrumSec extortion group claimed 80 GB exfiltration. Airport group statement not confirmed as of writing. Coverage.
  • Next.js critical RCEs: Two critical remote code execution flaws patched. Confidence: CVE confirmed via Next.js advisory. Coverage.
  • Treasury sanctions, IRGC hackers: Named individuals sanctioned for ICS breach activity against critical infrastructure. Coverage.
  • Zimbra: 270 servers breached as the KEV patch deadline expired. Exploitation window continues for unpatched instances. Coverage.
  • FBI/DOJ: QTFY China espionage disruption: Law enforcement action confirmed. Coverage.
  • Ubiquiti UniFi Protect: Max-severity CVEs in OS/Talk components patched. Coverage.
  • OpenAI Agents SDK CVE-2026-53362: Linux kernel KEV intersection flagged in coverage. Coverage.
  • What Is EPSS? Evergreen explainer shipped Aug 25. Coverage.

Looking Ahead

Key items to track this week:

  1. PaperCut KEV status. CVE-2026-81578 and CVE-2026-82078 are bypass CVEs for an actively exploited zero-day. KEV listing probable if exploitation of bypass paths is confirmed.
  2. McKesson breach confirmation. A breach this size carries mandatory notification requirements. Official McKesson statement and/or regulatory filing expected.
  3. ServiceNow CVE assignments. Three CVSS 10.0 flaws without assigned CVE IDs at time of writing. NVD assignment triggers patch-management tooling. Watch the catalog.
  4. ATF breach scope. Federal law enforcement systems, Qilin ransomware. Full operational impact still unconfirmed. Track DOJ and CISA.
  5. APT28 HOOKEDGE expansion. European government targeting rarely stops at three countries. Watch for additional attribution from CERT-EU and national CERTs.
  • airgap
Sources