Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 29, 2026

PaperCut has confirmed active zero-day exploitation across all NG and MF versions, released emergency patches for v25 and v26, and directed internet-exposed servers to immediately restrict access to trusted IP addresses while its investigation continues. Separately, McKesson disclosed a breach it detected on August 25, while ShinyHunters alleges it used vishing to compromise Okta accounts and exfiltrate roughly 1 TB of patient data over four days—claims McKesson has not independently confirmed as its investigation remains in early stages.

Compiled by the Slugnet Editorial System. Published Aug 29, 2026, 7:28 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

    What happened

    PaperCut has confirmed that attackers are actively exploiting a zero-day vulnerability in all versions of its NG and MF print management software, prompting the release of emergency patches for v25 and v26. The vendor advises administrators to immediately restrict internet access to the Application Server using firewall rules or network access controls, even in the absence of observed suspicious activity.

    Why it ranks #1

    PaperCut confirmed that attackers are actively exploiting a zero-day vulnerability in all versions of its NG and MF print management software, prompting the release of emergency patches for v25 and v26.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Restrict internet access to trusted IP addresses for exposed PaperCut NG/MF Application Servers immediately.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    What happened

    Patchstack researchers identified CVE-2026-82222, a maximum-severity vulnerability in the GiveWP WordPress plugin that allows an attacker to execute arbitrary server commands after creating an account via an exposed unauthenticated registration action. The flaw chains an unsafe PHP deserialization helper with a donation-processing flow that stores attacker-controlled serialized objects, enabling code execution through a gadget chain in the plugin's bundled libraries. GiveWP released version 4.16.7.2 on August 27 to block serialized data during donation processing and restrict object creation at deserialization points.

    Why it ranks #2

    Patchstack researchers identified CVE-2026-82222, a maximum-severity vulnerability in the GiveWP WordPress plugin that allows an attacker to execute arbitrary server commands after creating an account via an exposed unauthenticated registration action.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Apply GiveWP security updates immediately to prevent malicious exploitation of CVE-2026-82222.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    McKesson discloses breach after ShinyHunters claims patient data theft

    What happened

    McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, which the ShinyHunters extortion group claims resulted in the theft of 284 million patient data records. ShinyHunters alleges it gained access by compromising employee Okta single sign-on accounts through voice phishing, then used those credentials to access Salesforce and Snowflake environments. McKesson confirmed the breach in an SEC filing but has not independently verified the specific data types or the total volume of records claimed by the threat actor.

    Why it ranks #3

    McKesson disclosed an incident involving unauthorized access to third-party applications and data exfiltration, which the ShinyHunters extortion group claims resulted in the theft of 284 million patient records by compromising employee Okta single sign-on accounts via voice phishing to access Salesforce and Snowflake environments.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    What happened

    Socket researchers identified 19 Chrome and Edge extensions containing code that steals wallet secrets and drains cryptocurrency, with the most impacted tool holding 80,000 users. The malicious updates, which have been active since February 2024, establish persistent WebSocket connections to command-and-control servers to execute credential theft and inject fake browser updates.

    Why it ranks #4

    Socket researchers identified 19 Chrome and Edge extensions containing code that steals wallet secrets and drains cryptocurrency, with the most impacted tool holding 80,000 users.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

    What happened

    Berlin's state government confirmed an extortion attempt following the August compromise of its administrative network, disclosing that forensic analysis identified data exfiltration from the Senate Department for Mobility between August 7 and August 12. The city stated it will not meet the attackers' demands, while Rhysida claimed responsibility on its leak site, asserting it stole 5.79 terabytes of data and personal information on 12,076 individuals.

    Why it ranks #5

    Berlin's state government confirmed an extortion attempt following the August compromise of its administrative network, disclosing that forensic analysis identified data exfiltration from the Senate Department for Mobility between August 7 and August 12.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

    What happened

    Security researcher Olivier Laflamme disclosed two independent root remote code execution chains, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. The first flaw leverages a path-traversal condition in the chat_go service to reach bashrunner, while the second initiates from an unpaired Bluetooth Low Energy write path that leads to a buffer overflow in Wi-Fi provisioning code. Unitree patched the associated cloud authorization gap in July 2026, but no fixed firmware release has been confirmed for the device-side vulnerabilities.

    Why it ranks #6

    Olivier Laflamme disclosed two root RCE chains in the Unitree G1 EDU robot, involving path traversal and Bluetooth buffer overflow, with no confirmed firmware fix for the device-side flaws.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    sector
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

    What happened

    VulnCheck disclosed two factory implants, SPEAKINGSTONE and DARKLANTERN, in Shenzhen Zhibotong Electronics router firmware that grant unauthenticated remote attackers root access. The implants enable arbitrary command execution, credential exfiltration, and reverse SSH tunneling, with 203 internet-facing instances identified across 22 countries.

    Why it ranks #7

    VulnCheck disclosed two factory implants, SPEAKINGSTONE and DARKLANTERN, in Shenzhen Zhibotong Electronics router firmware that grant unauthenticated remote attackers root access, enabling arbitrary command execution, credential exfiltration, and reverse SSH tunneling across 203 identified internet-facing instances in 22 countries.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    Rapid7 Blog

    Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

    What happened

    Rapid7 released a new Metasploit Framework update adding scanner and exploit modules for vulnerabilities in Drupal, WordPress, Tenable Security Center, and Check Point SmartConsole. The release includes specific modules for unauthenticated SQL injection in Drupal and WordPress, as well as remote code execution exploits for Tenable, Flowise, and Langflow.

    Why it ranks #8

    Rapid7 released a Metasploit Framework update adding scanner and exploit modules for vulnerabilities in Drupal, WordPress, Tenable Security Center, and Check Point SmartConsole.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    BleepingComputer

    AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

    What happened

    NIST reclassified approximately 30,000 pre-March 2026 vulnerabilities as "Not Scheduled" to manage a backlog that has outpaced its current enrichment model. This operational shift leaves security teams without standardized metadata for a significant portion of known flaws, forcing them to synthesize fragmented data from vendor advisories and third-party intelligence to prioritize remediation.

    Why it ranks #9

    NIST reclassified approximately 30,000 pre-March 2026 vulnerabilities as "Not Scheduled" to manage a backlog that has outpaced its current enrichment model.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    Toy-making giant Hasbro disclose data breach affecting employees

    What happened

    Hasbro disclosed that attackers accessed the personal and financial data of 436 employees in Massachusetts, including Social Security numbers, credit card details, and driver's license information. The company stated it contained the incident by disabling the compromised account and terminating unauthorized access, though it did not specify the total number of affected individuals or link this breach to a separate March cyberattack that caused a $25 million revenue loss.

    Why it ranks #10

    Hasbro disclosed that attackers accessed the personal and financial data of 436 employees in Massachusetts, including Social Security numbers, credit card details, and driver's license information.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email