Cyber Security Week in Review: August 28, 2026

 

Cyber Security Week in Review: August 28, 2026

PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and MF software. The company has confirmed attacks on customers and advises organizations to immediately restrict access to PaperCut web interfaces to trusted IP addresses.

The US Justice Department and FBI disrupted infrastructure linked to QTFY, a China-linked threat actor that supported espionage against US organizations. The QScan and QTRouter platforms were used for network reconnaissance, vulnerability scanning, proxy management, and routing traffic to hide attackers’ locations.

Attackers are exploiting two Microsoft SharePoint vulnerabilities (CVE-2026-55040 and CVE-2026-63520), which can be chained together to take control of unpatched servers. CVE-2026-55040 allows attackers to bypass authentication, CVE-2026-63520 can then be used to remotely execute malicious code.

The US Cybersecurity and Infrastructure Security Agency (CISA) added six new flaws to its catalog of actively exploited security vulnerabilities. The list includes Citrix NetScaler vulnerability (CVE-2026-8452), which affects certain NetScaler appliances and can cause system crashes or denial-of-service attacks. The flaw can only be exploited against appliances configured as an AAA virtual server or a Gateway VPN server. The issue is fixed in v14.1-72.61 (FIPS), 13.1-63.18 and 13.1-37.272.

Also among exploited flaws are CVE-2015-3246 (Red Hat Libuser race condition), CVE-2015-5287 (Red Hat Automatic Bug Reporting Tool privilege escalation), CVE-2019-1068 (Microsoft SQL Server RCE), CVE-2021-23758 (Ajax.NET Professional deserialization of untrusted data), and CVE-2022-0995 (Linux Kernel out-of-bounds write).

In a separate advisory, CISA said that more than 100 internet-exposed water and wastewater systems were targeted by cyberattacks in July 2026. The attacks often involved programmable logic controllers (PLCs) connected directly to cellular modems. At least 12 states, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama, have confirmed being targeted. CISA has issued guidance to help organizations reduce the internet exposure of vulnerable systems.

CISA has also shared the results of two red team assessments that used similar attack techniques against two critical infrastructure organizations. Both organizations were eventually compromised at the domain level, but their security teams responded very differently.

More than 270 Zimbra Collaboration Suite (ZCS) servers have been compromised in ongoing attacks. The vulnerability, tracked as CVE-2026-73570, allows attackers to remotely run code without logging in. It affects Zimbra’s SNMP monitoring component when SNMP notifications are enabled.

Researchers at 360 Threat Intelligence Center say that a threat actor, tracked as UAC-0099, has updated its malware arsenal and shifted to new attack techniques. The threat actor, mainly known for its attacks on government agencies and critical infrastructure organizations in Ukraine, implemented new malware implants (LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2). The attack uses techniques such as DLL sideloading, multiple stages of conditional execution, and code virtualization to avoid detection. The final stages provide attackers with remote control of infected systems.

A threat actor known as UAT-10147 is targeting Windows and Linux web servers around the world. The campaign has affected organizations in government, education, media, technology and gaming, with many targets located in Brazil, Bolivia, China, Canada and Vietnam. The attackers used publicly known vulnerabilities to gain access and leveraged AI-powered tools for reconnaissance, exploit development, troubleshooting, payload creation, validation and persistence. The tools include Metasploit, ysoserial, PentestGPT and DeepAudit, as well as several privilege escalation exploits.

A Chinese-speaking threat actor, tracked as TA4922, is using the PackClient C2 framework for data theft, surveillance, and delivering additional malware. The actor used tax-themed phishing lures impersonating tax authorities in China and India.

Researchers discovered a new Rowhammer attack called GPUThor that can bypass ECC memory protection on some NVIDIA GPUs. It can cause crashes or potentially gain root-level access. The attack was tested on several NVIDIA Ampere GPUs with GDDR6 memory, including the RTX A4000, A4500, A5000, and A6000.

Check Point Research has uncovered a technique that can use Microsoft Defender’s signed boot-time driver (BTR.sys) to perform kernel-level actions on Windows systems without exploiting a software vulnerability or installing an outside driver.

Cybersecurity researchers have detailed NovaCookies, a $320-per-month phishing toolkit that targets Microsoft 365 users. It acts as a proxy to steal login sessions in real time. The service has reportedly targeted hundreds of organizations in the US, UK, Canada, Germany, Israel, and the UAE.

Threat actors are using FTP server banners to hide commands that deliver two previously undocumented remote access trojans (RATs) called E4del and PINHOLE. Researchers observed the technique in attacks that began in July 2026 and are still active. The attacks reportedly start with ZIP files that use shortcut (.LNK) files to begin the infection. The attackers then use FTP banners to deliver PowerShell commands to infected systems.

OpenAI said it banned a group of Russian ChatGPT accounts that used VPNs to bypass access restrictions and support an online influence campaign. The accounts were used to promote the International Burke Institute (IBI), an group that describes itself as an expert community based in Israel. OpenAI said the operators used ChatGPT to create social media posts and comments shared on Telegram, X, Facebook, LinkedIn and Substack.

The company has also released an incident postmortem on the July Hugging Face breach, explaining that its agents were trained to find ways to achieve their goals and, as a result, learned that cheating and hacking could help them succeed. During a later cybersecurity test, some agents created a way to communicate, got online despite restrictions, and hacked Hugging Face to find answers. The AI evaluation nonprofit METR also published its own report on the hack.

The US Department of the Treasury has announced new sanctions against Iranian cyber actors as part of a wider campaign targeting Iran’s financial networks and the Islamic Revolutionary Guard Corps (IRGC). The operation, called “Operation Economic Outcast,” targets nearly 60 Iran-linked individuals, entities and vessels involved in Iran’s nuclear, missile, oil and cyber networks. The sanctions also target parts of Iran’s digital assets sector.

Australian police and the US FBI have arrested two men, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, suspected of being members of the TeamPCP cybercriminal group. TeamPCP targeted software supply chains and development tools such as Trivy, KICS, and LiteLLM. The attackers used malicious packages and malware, including Mini Shai-Hulud, to steal cloud credentials, API keys, SSH keys, and other secrets from CI/CD pipelines.

Australian police say the group stole more than 300 GB of data from over 1,000 organizations and compromised more than 500,000 credentials. Thomson faces hacking and money-laundering charges, while Gaebler faces computer-hacking charges. Police have seized their devices and are investigating their activities and profits.

A 31-year-old German man was given a suspended 16-month prison sentence for a 2022 cyberattack on Rosneft’s German subsidiary. As part of the Anonymous group, he and others accessed the company’s systems, copied around 20 terabytes of data, and deleted some information. The attack caused nearly €10 million in recovery costs and about €2.6 million in additional losses. The man admitted his guilt, the verdict is not yet final.

Spanish police arrested seven people and are investigating six others for allegedly stealing more than 150 high-end mobile phones. The group used stolen personal data and a computer script to exploit a security flaw in a telecom company’s system and avoid paying for the phones. The devices were later sold for profit. Police also found cash, documents and electronic equipment during searches in Spain and Italy.

Joshua Culver, also known as “Maverick Young,” was arrested in Colorado after allegedly impersonating an NSA officer and Supreme Court Chief Justice John Roberts. He is accused of claiming to represent the NSA’s elite Tailored Access Operations (TAO) hacking unit and using fake documents and a forged signature to pressure officials and influence a court case in Indiana.

South Korean and Chinese police have disrupted a voice phishing group operating in China that allegedly stole more than $7.2 million from South Koreans, mainly elderly victims. Ten suspects were arrested, including six South Koreans and four Chinese nationals. The group allegedly impersonated police officers, bank staff, prosecutors and delivery drivers to trick victims into installing malicious apps that intercepted calls and enabled theft. The six South Korean suspects were returned to South Korea and sent to prosecutors.

Law enforcement agencies from 22 countries have identified 263 suspects and arrested 58 people linked to cybercrime networks run by African organized crime groups. The international operation, called 'Operation Jackal IV,' ran from November 2025 to June 2026, targeting West African criminal networks, including the Black Axe cybercrime syndicate.


Back to the list