Week in Review: Aug 24-30, 2026
36 articles, seven days: PaperCut patched twice, ServiceNow CVSS 10.0 triple, ATF breach confirmed, APT28 resurfaces, five new CISA KEV entries.
- PaperCut NG/MF zero-day actively exploited Aug 28; second advisory Aug 29 for CVE-2026-81578 and CVE-2026-82078 after initial patch proved bypassable. Patch to 25.1.1 immediately.
- ServiceNow patched three CVSS 10.0 flaws in AI-platform components. No public exploitation confirmed; high-value enterprise attack surface.
- ATF confirmed a major Qilin ransomware breach. Scope of data exfiltration unconfirmed as of reporting.
- ShinyHunters claimed 284M McKesson patient records. Unconfirmed by McKesson as of Aug 29. Treat figure as unverified.
- Five new CISA KEV entries: Citrix NetScaler CVE-2026-8452, Oracle WebLogic CVE-2026-21962, ownCloud CVE-2023-49105, Gitea RCE. Active exploitation confirmed on all four.
- APT28 HOOKEDGE backdoor targeting European governments in Romania, Spain, and Türkiye. Active campaign as of Aug 29.
36 articles. Seven days. The dominant theme: active exploitation outpaced patch deployment across enterprise platforms, with two separate federal-level breaches confirmed before the week closed.
PaperCut NG/MF: Zero-Day, Then a Second Patch
Two CVEs. Two patches in 48 hours.
PaperCut NG/MF was hit with an actively exploited zero-day on Aug 28: remote code execution, no authentication required. Vendor and independent researchers confirmed active exploitation within hours of disclosure. A patch shipped the same day.
Aug 29: a second advisory. CVE-2026-81578 and CVE-2026-82078 disclosed after researchers identified that the original patch was bypassable. Both CVEs confirmed against NVD. The patched release is 25.1.1.
Confidence breakdown:
- Confirmed: Both CVEs, vendor advisories, active exploitation of the initial zero-day.
- Confirmed: Bypass path for first patch. Second patch required.
- Unknown: Whether active exploitation continued after second patch release.
PaperCut Zero-Day Under Active Exploitation | Second Patch Issued for Bypass CVEs.
ServiceNow: Three CVSS 10.0 Flaws in AI Platform
Maximum severity. Three vulnerabilities in ServiceNow’s AI-platform components each scored 10.0 on the CVSS scale.
Confidence:
- Confirmed: CVSS 10.0 per ServiceNow advisories. Patches available in the Aug 29 release.
- Unknown: Public exploitation as of reporting date.
High-value enterprise attack surface. No CVE IDs confirmed at time of publication. Watch NVD for assignments: that is when patch-management tooling catches up.
ATF Breach: Qilin Ransomware
Confirmed. The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major ransomware breach following a Qilin group claim on Aug 28.
Confidence:
- Confirmed: ATF acknowledged the breach and classified it as a major incident.
- Confirmed: Qilin is the named threat actor per ATF statement.
- Unconfirmed: Full scope of data accessed or operational systems affected as of reporting.
Track CISA and DOJ for official scope updates.
McKesson: 284M Patient Records Claimed, Unconfirmed
ShinyHunters claimed on Aug 29 to have exfiltrated 284 million patient records from McKesson.
Confidence:
- Confirmed: ShinyHunters published the claim with sample data.
- Unconfirmed: McKesson had not confirmed a breach as of reporting.
- Context: ShinyHunters has a documented history of overstating breach scope. Do not treat the 284M figure as verified until McKesson issues a statement.
CISA KEV Additions This Week
Five new entries across four CVEs:
- CVE-2026-8452 (Citrix NetScaler, Aug 27): Active exploitation confirmed. CISA federal patch deadline in effect. Coverage.
- CVE-2026-21962 (Oracle WebLogic, Aug 25): KEV-listed. Confidence: CISA-confirmed. Coverage.
- CVE-2023-49105 (ownCloud, Aug 29): KEV listing followed confirmed data exfiltration at a nuclear records operator. Coverage.
- Gitea RCE (Aug 26): Active cryptominer campaign confirmed against unpatched instances. Coverage.
- CVE-2026-18431 (Avada WordPress theme, Aug 27): Zero-click RCE. Patched. No KEV listing confirmed at time of writing; monitor. Coverage.
Round-Up
- APT28 HOOKEDGE: Active backdoor campaign targeting European government networks in Romania, Spain, and Türkiye, per Aug 29 threat intel. Attribution confirmed by researchers. Coverage.
- ZBT routers, factory implants: CVE-2026-74232 and CVE-2026-74233 confirmed factory-embedded backdoor functionality in ZBT WE3000 and related models. Coverage.
- TerminalFix ClickFix: New campaign drops reverse-tunnel backdoor via Windows Terminal configuration lure. No CVE. Social engineering vector. Coverage.
- CVE-2026-75759 (OIDCC): OIDC signature bypass allowing attacker-controlled tokens to be accepted as valid. Patched. Coverage.
- CVE-2026-82329 (JFrog Artifactory): Default authentication bypass giving unauthenticated admin access. Patched. Coverage.
- Microsoft Edge: Eight type-confusion RCE flaws patched in a single advisory. Coverage.
- Berlin state network breach: Rhysida ransomware group claimed 5TB exfiltration from Berlin government infrastructure. City confirmed the breach and declined to pay. Coverage.
- Manchester Airports Group: FulcrumSec extortion group claimed 80 GB exfiltration. Airport group statement not confirmed as of writing. Coverage.
- Next.js critical RCEs: Two critical remote code execution flaws patched. Confidence: CVE confirmed via Next.js advisory. Coverage.
- Treasury sanctions, IRGC hackers: Named individuals sanctioned for ICS breach activity against critical infrastructure. Coverage.
- Zimbra: 270 servers breached as the KEV patch deadline expired. Exploitation window continues for unpatched instances. Coverage.
- FBI/DOJ: QTFY China espionage disruption: Law enforcement action confirmed. Coverage.
- Ubiquiti UniFi Protect: Max-severity CVEs in OS/Talk components patched. Coverage.
- OpenAI Agents SDK CVE-2026-53362: Linux kernel KEV intersection flagged in coverage. Coverage.
- What Is EPSS? Evergreen explainer shipped Aug 25. Coverage.
Looking Ahead
Key items to track this week:
- PaperCut KEV status. CVE-2026-81578 and CVE-2026-82078 are bypass CVEs for an actively exploited zero-day. KEV listing probable if exploitation of bypass paths is confirmed.
- McKesson breach confirmation. A breach this size carries mandatory notification requirements. Official McKesson statement and/or regulatory filing expected.
- ServiceNow CVE assignments. Three CVSS 10.0 flaws without assigned CVE IDs at time of writing. NVD assignment triggers patch-management tooling. Watch the catalog.
- ATF breach scope. Federal law enforcement systems, Qilin ransomware. Full operational impact still unconfirmed. Track DOJ and CISA.
- APT28 HOOKEDGE expansion. European government targeting rarely stops at three countries. Watch for additional attribution from CERT-EU and national CERTs.
- airgap