Week of 24 to 30 August 2026
173 qualifying stories tracked from Monday-Sunday calendar week, August 24 to August 30, 2026; change from the prior 7 days: +29 vs prior period; 11 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) entries added from Monday-Sunday calendar week, August 24 to August 30, 2026; 207 leak-site claims observed by tracked feeds from Monday-Sunday calendar week, August 24 to August 30, 2026
Monday to Sunday, UTC. Permalink label: 2026-W35.
- vulnerabilities2 sourcesCISA Adds One Known Exploited Vulnerability to CatalogSource ↗
CISA added CVE-2026-21962, an Oracle HTTP Server and Weblogic Server proxy plug-in improper access control vulnerability, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. The vulnerability poses significant risk because it can grant total control of affected assets after exploitation. Federal agencies are required under Binding Operational Directive 26-04 to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed systems.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-21962).
- vulnerabilities24th August - Threat Intelligence ReportSource ↗
A weekly threat intelligence bulletin reports major breaches at Latvia's Road Traffic Safety Directorate affecting 1.2 million people, Sakura Internet with up to 1.36 million exposed accounts, and Canada's Hospital for Sick Children via a third-party application. The report also covers active artificial intelligence (AI)-assisted attacks on Siemens industrial controllers, critical vulnerabilities in GitLab (CVE-2026-19478), Cisco Crosswork, Citrix NetScaler (CVE-2026-19489 and CVE-2026-19490), and NASA/JPL's AMMOS Instrument Toolkit, along with research into the StopAndProtect ransomware campaign exploiting WordPress sites and a Cl0p extortion campaign targeting product lifecycle management software.
- vulnerabilitiesAll-Line Equipment Company Fuel-BossSource ↗
All-Line Equipment Company Fuel-Boss V1 versions running PHP 7.1.5 contain two critical vulnerabilities: CVE-2018-19518 (argument injection and buffer overflow in IMAP handling) and CVE-2019-11043 (buffer overflow in FPM configuration), both allowing remote code execution. Fixes are available for Standard and Portal versions; Master/Slave versions have no fix date, and Backflush Systems versions will not be patched. All-Line Equipment Company recommends taking unfixed systems offline or restricting network access at the router level.
- vulnerabilitiesCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server BugsSource ↗
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, including a high-severity flaw affecting Citrix NetScaler ADC and NetScaler Gateway. The additions reflect evidence of active exploitation in the wild.
- vulnerabilitiesEdge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterSource ↗
A joint Tenable-SentinelOne analysis of 93 CVE-actor pairs from two independent datasets shows that state-sponsored and criminal threat actors independently target the same edge infrastructure vendors, particularly Fortinet, Citrix, Ivanti, and Palo Alto Networks. Twelve confirmed vulnerabilities have multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware groups, indicating a shared attack surface rather than isolated vendor problems. High-priority edge device CVEs take longer to remediate (146 days median) due to operational constraints like change management and firmware update requirements, leaving extended exploitation windows.
- vulnerabilitiesCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like PayloadSource ↗
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned on August 26, 2026 of active attacks exploiting CVE-2026-60004, a critical remote code execution (RCE) flaw in Gitea with a CVSS score of 9.8. The vulnerability permits attackers with repository write access to execute arbitrary shell commands, and confirmed attacks have deployed miner-like payloads.
- vulnerabilitiesActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataSource ↗
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The flaw in Oracle HTTP Server and Oracle WebLogic Server has a maximum severity score of 10.0 and permits unauthenticated HTTP access to critical data.
- vulnerabilitiesownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research BodySource ↗
CISA added CVE-2023-49105, a critical ownCloud vulnerability with a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor exploited it to target a nuclear research organization in the Philippines. The flaw enabled theft of nuclear records from the affected institution.
- vulnerabilitiesWeek in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploitedSource ↗
At least 274 internet-facing Zimbra servers have been compromised via CVE-2026-73570, according to the Shadowserver Foundation. The vulnerability, which has a CVSS score of 8.9 and is under active exploitation, affects unpatched Zimbra instances. The article also notes emerging artificial intelligence (AI) supply chain risks appearing in developer workflows.
- vulnerabilitiesUnpatched Zimbra servers are falling to CVE-2026-73570 attacksSource ↗
The Shadowserver Foundation reported that at least 274 internet-facing Zimbra Collaboration Suite instances have been compromised through exploitation of CVE-2026-73570, a code injection vulnerability. Synacor released a patch for this flaw in Zimbra Collaboration Suite version 10.1.20 on July 20, 2026.
| Qilin | 42 claims | +10 vs prior week |
| The Gentlemen | 21 claims | -7 vs prior week |
| KryBit | 13 claims | +8 vs prior week |
| Akira | 12 claims | +7 vs prior week |
| Silentransomgroup | 10 claims | +7 vs prior week |
| Chaos | 6 claims | +6 vs prior week |
| Dark Project | 6 claims | +6 vs prior week |
| LockBit | 6 claims | +4 vs prior week |
| Direwolf | 5 claims | -16 vs prior week |
| INC Ransom | 5 claims | -6 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- ATF confirms cyberattack hit system containing info on its investigation targetsSanction · Takedown · CyberScoop
The Bureau of Alcohol, Tobacco, Firearms and Explosives disclosed a cyberattack targeting a standalone system containing information on investigation targets. The financially-motivated ransomware group Qilin claimed responsibility, though the agency has not independently confirmed the claim or provided details on when the breach occurred. ATF stated the affected system was isolated from other agency infrastructure and that operational capabilities remain unimpaired.
- ATF Confirms Cyber Incident After Ransomware Group Claims AttackSanction · SecurityWeek
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyber incident it has designated as major, with a ransomware group claiming responsibility for the attack. The Department of Justice is assisting ATF in investigating the incident.
- “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friendArrest · Seizure · Disruption · Cisco Talos
A Cisco Talos newsletter explores how poorly designed artificial intelligence (AI) guardrails in security operations can inadvertently assist attackers by slowing or halting threat investigations. The author advocates for operational sovereignty, where organizations control and customize their own guardrails rather than relying on inflexible third-party provider restrictions. Talos also evaluated 66 large language model (LLM) combinations for security operations and found that selecting the right model requires balancing efficacy, speed, cost, and consistency against actual workflows, not generic leaderboard rankings.
- Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNsSeizure · Sanction · Takedown · Disruption · Rapid7 Blog
Rapid7 researchers identified 476 instances of compromised Social Security Numbers (SSNs) belonging to corporate executives traded across three dark web marketplaces (Xilo, Bankomat, and PeopleFinder) since early 2026, with 73% targeting top-level leadership. SSNs retain permanent value for identity fraud, synthetic identity creation, and executive impersonation attacks, unlike payment cards that can be cancelled. The report documents how these marketplaces operate as searchable storefronts, pricing SSN records between $0.25 and $4 per record, and recommends organizations monitor executive exposure on dark web channels and pursue takedown options where available.
- Australia arrests alleged TeamPCP hackers behind supply-chain attacksArrest · Indictment · BleepingComputer
Australian authorities arrested and charged two individuals allegedly linked to TeamPCP, a hacking group responsible for developer supply chain attacks. The operation targeted the software development ecosystem to gain broad access to downstream users and systems.
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. OrganizationsDisruption · The Hacker News
The U.S. Department of Justice announced the disruption of two hacking platforms, QScan and QTRouter, used by Chinese state-sponsored threat actors to target critical infrastructure and other sensitive networks. The activity has been attributed to QTFY, a group employed by Nanjing Xinjiuwei Network Technology Company.
- US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateDisruption · The Record
The Department of Justice disrupted Chinese state-backed hacking tools designed to scan, infect, and exploit IoT devices. The tools targeted federal agencies including the Federal Reserve and Department of Justice, as well as multiple private sector organizations.
- FBI disrupts proxy network enabling Chinese espionage operationsDisruption · BleepingComputer
The FBI dismantled infrastructure operated by a Chinese technical support asset that supplied reconnaissance, proxy management, and operational routing for espionage activities. The operation targeted systems used to enable and obscure Chinese cyber espionage campaigns.
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical InfrastructureSeizure · U.S. Department of Justice
SAN DIEGO - The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical InfrastructureSeizure · U.S. Department of Justice
The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.
- Interpol's Jackal IV Disrupts West African Crime InfrastructureDisruption · Dark Reading
Interpol's Jackal IV operation disrupted crime-as-a-service networks and infrastructure supporting criminal groups active in West Africa, including Black Axe. The initiative targeted the underlying systems enabling organized cybercrime rather than individual threat actors.
- The GTA VI leaks are breaking the internet. Security researchers have seen this before.Indictment · CyberScoop
A cybercriminal persona known as CyberLeek published leaked Grand Theft Auto VI gameplay footage prior to Rockstar Games' planned reveal, prompting Take-Two Interactive to file subpoenas against Discord, Google, Microsoft, and X under the Digital Millennium Copyright Act seeking to identify those responsible. Security researchers identify the incident as a hybrid data extortion attack combining financial monetization through cryptocurrency channels with stated anti-corporate messaging, following a pattern similar to previous entertainment industry breaches such as the 2014 Sony Pictures and 2017 HBO attacks.
6 more qualifying actions on the full feed.
- CVE-2019-1068Microsoft SQL Serverdue
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-indue
- CVE-2026-60004Gitea Giteadue
- CVE-2023-49105ownCloud ownClouddue
- CVE-2021-23758Ajax.NET Professional Ajax.NET Professionaldue
- CVE-2026-8452Citrix NetScaler ADC and NetScaler Gatewaydue
- CVE-2022-0995Linux Kerneldue
- CVE-2015-3246Red Hat Libuserdue
- CVE-2015-5287Red Hat Automatic Bug Reporting Tooldue
- CVE-2026-53362Linux Kerneldue
- CVE-2019-1068Microsoft SQL ServerAdded to CISA KEV 2026-08-26; Added to ENISA EUVD 2026-08-26
- CVE-2026-48710encode starletteAdded to VulnCheck KEV 2026-08-26
- CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)EPSS up 19 points in about a week
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inAdded to CISA KEV 2026-08-24; Added to ENISA EUVD 2026-08-24
- CVE-2026-18577N-able N-centralEPSS up 48 points in about a week
- claimAFSARDUnverified claim. Claimed by Qilin.
- claimCrystalpharmatechUnverified claim. Claimed by Qilin.
- claimAbsolute Consultancy ServicesUnverified claim. Claimed by Qilin.
- claimBlack Cat Engineering Construction WllUnverified claim. Claimed by Qilin.
- claimBandit IndustriesUnverified claim. Claimed by Qilin.
- claimLAPoco ArchitectsUnverified claim. Claimed by Qilin.
- claimNeumaticos Corral S.A.Unverified claim. Claimed by Qilin.
- claimThe Frame GroupUnverified claim. Claimed by Qilin.
- claimGlassdoorUnverified claim. Claimed by The Gentlemen.
- claimG R InfraprojectsUnverified claim. Claimed by The Gentlemen.
- claimNorthwest TrophyUnverified claim. Claimed by The Gentlemen.
- claimGeneral GruppoUnverified claim. Claimed by The Gentlemen.
- claimIxa SystemsUnverified claim. Claimed by The Gentlemen.
- claimTecno AccionUnverified claim. Claimed by The Gentlemen.
- claimProbe Test SystemUnverified claim. Claimed by The Gentlemen.
- claimSUNSEAUnverified claim. Claimed by The Gentlemen.
- claimfinodayacapital.comUnverified claim. Claimed by KryBit.
- claimcgcgabon.comUnverified claim. Claimed by KryBit.
- claimkarkinos.inUnverified claim. Claimed by KryBit.
- claimferretornillos.gtUnverified claim. Claimed by KryBit.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.