Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 30, 2026

Shadowserver confirmed 8,393 internet-exposed Gitea servers remain unpatched against CVE-2026-60004, a diffpatch code-injection flaw now on CISA's KEV list with a three-day federal deadline, and the vulnerability is exploitable without prior credentials because Gitea enables self-registration by default. watchTowr separately confirmed active exploitation of a chained PaperCut NG/MF authentication bypass (CVE-2026-81578) and unsafe dynamic class-loading flaw (CVE-2026-82078) on two customer environments, and identified new bypasses in the second emergency patch that leave the attack chain partially open on the latest release.

Compiled by the Slugnet Editorial System. Published Aug 30, 2026, 8:23 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    BleepingComputer

    Over 8,300 Gitea servers vulnerable to code execution attacks

    What happened

    Shadowserver identified 8,393 internet-exposed Gitea instances remaining vulnerable to CVE-2026-60004, a code injection flaw that allows attackers to execute arbitrary shell commands via the diffpatch API. The vulnerability is currently being exploited in the wild to deploy cryptocurrency mining malware, prompting CISA to mandate that federal agencies patch their servers by August 28.

    Why it ranks #1

    Shadowserver identified 8,393 internet-exposed Gitea instances vulnerable to CVE-2026-60004, a code injection flaw in the diffpatch API that allows arbitrary shell command execution and is currently being exploited in the wild to deploy cryptocurrency mining malware.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    "With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

    What happened

    Microsoft disclosed TerminalFix, a ClickFix campaign that uses fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands in Windows Terminal. The attack chain leverages DLL sideloading and steganography to deploy a Python-based reverse-tunnel implant, granting attackers persistent, network-level proxy access to the victim's internal infrastructure.

    Why it ranks #2

    Microsoft disclosed TerminalFix, a ClickFix campaign using fake Cloudflare CAPTCHAs to execute PowerShell commands, deploying a Python reverse-tunnel implant for persistent network proxy access.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    What happened

    Wordfence and Patchstack disclosed five critical flaws in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These vulnerabilities, which carry CVSS scores up to 10.0, allow unauthenticated attackers to bypass authentication, escalate privileges, or execute arbitrary code to achieve full site takeover.

    Why it ranks #3

    Wordfence and Patchstack disclosed five critical flaws in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, which allow unauthenticated attackers to bypass authentication, escalate privileges, or execute arbitrary code to achieve full site takeover.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

    What happened

    Huntress and watchTowr confirmed active exploitation of a chained authentication bypass and unsafe dynamic class loading flaw in PaperCut NG and MF, allowing unauthenticated attackers to execute arbitrary code. The observed post-exploitation activity involved Base64-encoded commands and a Java .class file used to fingerprint the victim's operating system and list running processes. PaperCut released a second emergency patch to address the initial fix's bypasses, while watchTowr noted that new patch bypasses affecting the latest version have already been identified.

    Why it ranks #4

    Huntress and watchTowr confirmed active exploitation of a chained authentication bypass and unsafe dynamic class loading flaw in PaperCut NG and MF, allowing unauthenticated attackers to execute arbitrary code and perform post-exploitation reconnaissance.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    North Korean remote workers are broadening their job hunt beyond IT

    What happened

    Huntress identified suspected North Korean remote workers operating in sales, marketing, and medical roles, noting that these individuals use stolen identity documents and proxy services to mask their location. In one case, investigators found a PiKVM device connected to a new hire's laptop, indicating the machine was part of a remote-controlled laptop farm.

    Why it ranks #5

    Huntress identified suspected North Korean remote workers in non-IT roles using stolen identities and proxy services, with one case revealing a PiKVM device controlling a new hire's laptop.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Brave browser adds email aliases to help users evade tracking

    What happened

    Brave browser version 1.94 introduces an Email Aliases feature that generates disposable addresses to mask users' primary email during service registration. The system forwards messages to the user's real address while storing both the primary and alias addresses in an encrypted state to prevent cross-site identity matching.

    Why it ranks #6

    Brave browser version 1.94 introduced an Email Aliases feature that generates disposable addresses to mask users' primary email during service registration, forwarding messages to the real address while storing both in an encrypted state to prevent cross-site identity matching.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Register your primary email address with a free Brave Account to generate and use email aliases.

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Key Reasons Why Identity Fabric Matters in 2026

    What happened

    The provided source text does not contain any information regarding Huntress, North Korean remote workers, or fraudulent job searches. The source text does not contain any information regarding DPRK employees, stolen identity documents, VPNs, proxy services, or PiKVM devices.

    Why it ranks #7

    The provided source text does not contain any information regarding Huntress, North Korean remote workers, or fraudulent job searches.

    Who should care

    Cloud security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    medium
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

    What happened

    Google announced that Android 17 will enable Encrypted Client Hello (ECH) and ECH GREASE by default, extending domain name encryption from individual browsers to the entire operating system. This change prevents network providers from observing which websites users visit by encrypting the destination domain name in the initial connection handshake.

    Why it ranks #8

    Android 17 enables OS-wide Encrypted Client Hello by default, preventing network providers from observing destination domain names during the initial connection handshake.

    Who should care

    Individual users

    Impact
    low
    Urgency
    monitor
    Confidence
    high
    Scope
    consumer
    Status
    monitoring
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    BleepingComputer

    68-year-old imprisoned after making $1.3 million by pirating IPTV services

    What happened

    The City of London Police announced that Milan Ibrahim was sentenced to more than six years in prison for operating an illegal IPTV service that generated £980,812 over three years. The Police Intellectual Property Crime Unit seized and shut down 80 servers in Chorley, disrupting the distribution of unauthorized broadcasts from rights holders including the BBC, ITV, and Sky.

    Why it ranks #9

    The City of London Police imprisoned Milan Ibrahim for operating an illegal IPTV service that generated over £980,000, leading to the seizure of 80 servers distributing unauthorized broadcasts.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Dark Reading

    [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

    What happened

    Dark Reading is promoting a full-day virtual event focused on securing cloud assets and managing security risks in multi-cloud environments. The session aims to provide enterprises with tools and best practices for gaining comprehensive visibility into their cloud infrastructure.

    Why it ranks #10

    Dark Reading is promoting a full-day virtual event focused on securing cloud assets and managing security risks in multi-cloud environments.

    Who should care

    Cloud security teams

    Impact
    low
    Urgency
    monitor
    Confidence
    low
    Scope
    enterprise
    Status
    monitoring
    Read the original source Link to this ranking Share on Bluesky Share by email