Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Thu 27 Aug

WatchGuard Fireware OS and Dimension: five criticals including unauth iked RCE (CVSS 9.3)

WatchGuard PSIRT published a cluster of advisories on 27 August 2026 covering Fireware OS (iked / epm) and WatchGuard Dimension. Five issues are rated 9.3 on the vendor page: iked heap overflow CVE-2026-19313, iked stack overflow CVE-2026-19318 and iked type confusion CVE-2026-19315 (unauthenticated remote code execution via crafted traffic); epm stack overflow CVE-2026-13086 in the deprecated Mobile Security feature; and Dimension CVE-2026-78174, session-ID and CSRF token exposure that can let a low-privileged administrator take over a super-admin session. SecurityWeek (Ionut Arghire, 1 September) matches those five at CVSS 9.3. Patch to Fireware OS 2026.2.2, 12.12.2 or 12.5.20 and Dimension 2.3.1. WatchGuard also shipped additional high- and medium-severity fixes in the same wave (iked denial-of-service and Dimension SQL injection, CSRF, SSRF and related issues among them); this card does not list every CVE. The vendor is not aware of exploitation of these defects.

WatchGuard PSIRT advisories (27 Aug 2026)

vulnerabilities network

Incidents

Thu 27 Aug

NSW Police charge a Sydney telco employee over alleged sale of customer data

iTnews (28 August 2026), citing an NSW Police statement, reports that a 30-year-old telecommunications employee was arrested at a police station in Sydney's west and charged over allegedly accessing customer data through his employment and selling it to criminal groups. Police allege the information was then used to commit fraud against multiple victims. Charges listed in that report are 12 counts of deal with identity info to commit an indictable offence, 12 counts of unauthorised function with intent to commit a serious offence, and 10 counts of agent corruptly receive benefit (34 offences). The arrest followed a Queensland Police referral. iTnews does not name the employer. The National Tribune reprint of the police release dates the arrest about 9.30am on Thursday 27 August 2026, refused bail to Liverpool Local Court the same day. These are allegations before a court.

iTnews (28 Aug 2026; quotes NSW Police)

australia identity

Vulnerabilities

Thu 27 Aug

Palo Alto GlobalProtect local privilege escalation (CVE-2026-0251)

Palo Alto Networks advisory CVE-2026-0251 (published 13 May 2026, updated 27 August 2026 after a public PoC): multiple local privilege-escalation bugs in the GlobalProtect app (CWE-426 untrusted search path) let a local user reach NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, then run commands with administrative privileges. iOS, Android, Chrome OS and the GlobalProtect UWP app are not affected. No special configuration is required. Vendor CVSS-BT is 7.1 (CVSS 4.0); the same advisory lists CVSS-B 8.5. Exploit maturity is POC. Palo Alto Networks says it is not aware of malicious exploitation. Distinct from CVE-2026-0299 already on this desk.

Palo Alto Networks PSIRT (CVE-2026-0251)

vulnerabilities network

Incidents

Thu 27 Aug

Manchester Airports Group: FulcrumSec leaks ~550GB / HIBP ~8.8M emails and phones after ransom refusal

MAG’s 27 August 2026 statement said an unauthorised third party obtained customer data from car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at Manchester, London Stansted and East Midlands airports (emails, phones, vehicle registrations, postcodes; no bank details; operations unaffected). SecurityWeek (3 September 2026) reports the FulcrumSec extortion group published roughly 550GB of uncompressed data after MAG reportedly refused a ransom, claiming access via exposed admin keys. Have I Been Pwned, which ingested the dump, put the scale at about 8.8 million email addresses and phone numbers, with names, browser agents, purchases and vehicle plates also present. FulcrumSec claimed on the order of 2.48 million purchases in the set. MAG’s original mediacentre statement remains the operator notice; treat FulcrumSec/HIBP figures as leak-site and breach-notification telemetry refining scope.

MAG statement (27 Aug 2026)

breaches identity

Advisories

Thu 27 Aug

Chrome and Edge extensions delivering wallet-drainer malware (Superior)

Socket Threat Research (published 27 August 2026) identified 18 Chrome Web Store extensions and one Microsoft Edge add-on that deliver an extensible malware framework Socket tracks as Superior. Five of the extensions had been acquired from original creators and later pushed malicious updates to existing users; one right-click utility had around 70,000 Chrome users (and about 10,000 on Edge) when malicious functionality appeared. Modules establish encrypted WebSocket C2, strip Content Security Policy headers, and inject payloads that drain crypto wallets, steal credentials and browser history, harvest social accounts, and show ClickFix-style fake update prompts. Google removed the Chrome listings; Socket reported the Edge variant was still live when it published (Edge C2 rotated on 14 August 2026). Users who installed any listed extension should treat credentials as compromised and move crypto to a fresh wallet. Primary: Socket. Secondary: BleepingComputer 30 August.

Socket Threat Research

tech identity cloud

Vulnerabilities

Thu 27 Aug

ServiceNow Now Platform sandbox escape (CVE-2026-6876)

ServiceNow's 27 August 2026 CVE record (CNA title: Sandbox Escape in Now Platform) says it remediated a sandbox-escape issue that could allow an unauthenticated user to execute arbitrary code within the Now Platform and gain more access than intended. ServiceNow scored it 8.7 (CVSS 4.0; vector uses PR:L). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation against ServiceNow instances. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). CNA-listed affected rows span Xanadu, Yokohama, Zurich and Australia patch families (including builds before Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b / Patch 13 Hot Fix 4, Zurich Patch 7b–12 hotfixes as listed, and Australia Patch 2–5 hotfixes as listed). Same-day desk cards cover the three CVSS 4.0 10.0 AI Platform issues (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820).

CVE-2026-6876 (ServiceNow CNA)

vulnerabilities cloud

Incidents

Thu 27 Aug

Alliance Distribution Services (Hachette Australia): systems disruption after unauthorised activity

Hachette Australia told ABC News that unauthorised activity on the computer systems of its distribution subsidiary Alliance Distribution Services (ADS) was believed to have occurred on 18 July 2026. As of the 27 August 2026 ABC report, Hachette said it was still restoring systems and services, could not yet confirm a timeline for a full return to normal operations, and that restoring full operations securely remained its top priority. The disruption has hit book supply to Australian bookshops and authors ahead of the busy trading period. Hachette has not publicly confirmed whether the incident involved ransomware, data theft, or another form of attack. Secondary commentary that labels the event ransomware remains unverified by the company.

ABC News (quotes Hachette)

australia supply chain

Vulnerabilities

Thu 27 Aug

ServiceNow AI Platform unauthenticated privilege escalation (CVE-2026-18886)

ServiceNow's 27 August 2026 CVE record (CNA title: Unauthenticated Privilege Escalation via System Configuration Image Upload Processor) says it remediated an improper access control flaw in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of exploitation against ServiceNow instances. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record. Distinct from CVE-2026-74820 (SQL injection) and CVE-2026-18885 (code injection) on this desk.

CVE-2026-18886 (ServiceNow CNA)

vulnerabilities cloud ai

Vulnerabilities

Thu 27 Aug

ServiceNow AI Platform unauthenticated code injection (CVE-2026-18885)

ServiceNow's 27 August 2026 CVE record (CNA title: Unauthenticated Remote Code Execution in GraphQL Composite Data API) says it remediated a code-injection flaw in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user run arbitrary code and gain access to or change instance data beyond what was intended. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record. Distinct from CVE-2026-74820 (SQL injection) and CVE-2026-18886 (privilege escalation) on this desk.

CVE-2026-18885 (ServiceNow CNA)

vulnerabilities cloud ai

Vulnerabilities

Thu 27 Aug

PaperCut NG/MF: MR 26.0.5/25.0.13/24.1.10 replace EPR; AI-agent wave; KEV (CVE-2026-82078/81578)

PaperCut Software's 27 August 2026 (AEST) security bulletin, last updated 10 September 2026, published Security Maintenance Releases on 10 Sep 2:00pm AEST: NG/MF 26.0.5, 25.0.13 and 24.1.10 are Regular Maintenance Releases that completed full QA, include all fixes from Emergency Patch Releases 1–3 plus extra hardening, and replace the emergency patches as the recommended builds. Earlier context: says its response team is investigating active exploitation of PaperCut NG and PaperCut MF, with confirmed customer incidents. The advisory applies to all versions of both products. Immediate action: if the Application Server is reachable from the public internet, restrict web access to trusted addresses now. Emergency Patch Release 2 went out for NG/MF v24, v25 and v26 (Windows, Linux and macOS) with extra hardening after work with Huntress and watchTowr. Versions before v24 should upgrade to the latest. The bulletin lists CVE-2026-82078 (unsafe dynamic class loading in the database connector, CVSS 4.0 9.4 Critical) and CVE-2026-81578 (authentication bypass that can let an unauthenticated remote attacker modify certain system configurations, CVSS 4.0 8.8 High). Site Servers and secondary/print servers should be updated, not only the primary Application Server. Print Deploy and Mobility Print are not affected. Vendor-listed possible indicators include suspicious post-exploitation from pc-app.exe; missing, truncated or deleted server.log files; and server.log lines "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST". Absence of those lines is not proof the server is clean. On 29 August 4:35pm AEST PaperCut added that some sites report the external-database Card/ID number lookup feature and SAML are not working as expected after the patch. Card/ID lookup from an external database is off by default after Release 2; sites that still need it must set security.card-number-lookup.enabled=Y in server/security.properties and restart the Application Server. On 30 August 10:34am AEST the vendor said customers using SQL Server for external card lookups with the legacy SourceForge jTDS driver should move to the latest supported Microsoft SQL JDBC driver; engineering is still working toward an official release and support remains available. On 30 August 3:35pm AEST PaperCut added further indicators of compromise: server.log strings such as DB URL jdbc:derby:memory:pwn;create=true, Database error looking up cardID: VALUES CAST(X'cafebabe, Database error looking up cardID: VALUES CAST(', and DB URL jdbc:no:x with a 5-character random DB Driver name; files under install/server/lib/<5-char-name>.class and install/server/data/content/<5-char-name>.cmd or .out (attackers may remove those files). Observed post-compromise behaviour includes pc-app.exe or pc-app spawning cmd.exe for whoami and ver, then reconnaissance and downloads of remote-access tooling (including a Windows service named Remote Access Service running SimpleService.exe from a JWrapper-Remote Access path, and unexpected AnyDesk under C:/ProgramData). Absence of those indicators is not proof a server is clean. On 31 August 2026 4:21pm AEST PaperCut posted a status update with no new technical information. On 1 September 2026 11:18am AEST it added FAQ clarifications, and at 2:10pm AEST it added build numbers to download links. PaperCut published Emergency Patch (Release 3) on 1 September 2026 at 6:22pm AEST. It supersedes Release 2, is an accumulation of all emergency releases, addresses two known regressions (broken SAML login flows; restored support for legacy Microsoft SQL Server drivers for external card lookup), and adds additional hardening and mitigation against potential attack chains. Customers with internet-facing Application Servers should install Release 3 even if they already applied Release 2 or an earlier emergency release. Download tables now show R3 builds (MF v26 76531, v25 76532, v24 76534; NG v26 76530, v25 76533, v24 76535). BleepingComputer (1 September) reported that Defused observed CVE-2026-81578 / CVE-2026-82078 honeypot activity since late 29 August UTC; an actor abused the auth bypass to hijack PaperCut's external user-lookup and dump database tables via Derby (a data-theft path, distinct from the public RCE writeups). SecurityWeek (1 September) quoted WatchTowr's Jake Knott: activity has shifted from exploratory probes to hands-on-keyboard exploitation, with attackers keying in-memory payloads so only they can reuse the host; WatchTowr says that looks like initial-access-broker or other aggressive-outcome operators. CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 31 August 2026. WA SOC advisory 20260901001 (1 September, TLP:CLEAR) points operators at the same vendor bulletin, lists the two CVEs (CVSS 9.4 and 8.8), and says it has not received reports of exploitation on Western Australian Government networks at the time of writing. On 2 September 2026 at 4:38pm AEST PaperCut added an 'Updates from the field' note to Current Status: it says a second wave of attacks is hitting servers that are not fully patched and remain publicly available, and that this wave appears to involve more sophisticated post-compromise behaviour than the first days of the incident. The vendor again stresses installing Emergency Patch Release 3 or keeping the Application Server off the public internet. Bulletin page header last-updated date moved to 5 September 2026; Current Status at 5 September 2026 10:30am AEST reported no new vendor technical information (work continues toward the official release); EPR3 remains the current emergency build (no EPR4 in this update). The Hacker News (5 September 2026) summarises Arctic Wolf Adversary Research Team observations: attackers exploiting CVE-2026-81578 and CVE-2026-82078 against education-sector PaperCut servers in the United States and Europe (K-12 through universities) for command execution, reconnaissance and privileged-account creation, with post-exploitation including Windows registry hive collection tools (including lsa_collect.exe used to reconstruct BootKey/SAM access paths), Metasploit/Meterpreter-related Java payloads, and host/user/process enumeration. Arctic Wolf published related pack alerts at github.com/rtkwlf/wolf-tools (202609-papercut-cve-exploitation). Still: keep Application Servers off the public internet or on EPR3; monitor pc-app.exe spawning cmd.exe/powershell and the vendor IoCs already on this card. NEW 10 September 2026 (BleepingComputer citing GreyNoise; The Hacker News also citing Blackpoint Cyber): a likely Russian-speaking actor used hundreds of AI agents (OpenAI Codex and DeepSeek plus commodity tools) to build and refine exploits for CVE-2026-81578 and CVE-2026-82078, generating target lists via Netlas. GreyNoise reports at least 440 PaperCut instances at 395 organisations across 48 countries compromised; credentials from 280 victims, OS/domain secrets from 147, and administrator privileges at 12 organisations; roughly half of victims in education; top countries US, UK, France, Spain, Canada. First RCE under four hours from an empty workspace; domain admin about two hours later. Still: EPR3 or take Application Servers off the public internet; monitor the vendor IoCs already on this card.

PaperCut security bulletin (27 Aug 2026)

vulnerabilities australia

Vulnerabilities

Thu 27 Aug

ServiceNow AI Platform unauthenticated SQL injection (CVE-2026-74820)

ServiceNow's 27 August 2026 CVE record says it remediated an unauthenticated SQL injection in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user run arbitrary SQL against the instance database and read or change data beyond what was intended. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation. The same 27 August CNA batch includes CVE-2026-18885 (unauthenticated code injection in the GraphQL Composite Data API, CVSS 4.0 10.0; own card on this desk), CVE-2026-18886 (unauthenticated privilege escalation via image-upload processor, CVSS 4.0 10.0; own card on this desk) and CVE-2026-6876 (Now Platform sandbox escape, CVSS 4.0 8.7). Self-hosted operators should apply the August 2026 CVE advisory updates. Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record.

CVE-2026-74820 (ServiceNow CNA)

vulnerabilities cloud ai

Vulnerabilities

Thu 27 Aug

JFrog Artifactory Docker cache path traversal (CVE-2026-66384)

Authenticated path-limitation flaw in JFrog Artifactory: under specific remote-repository conditions a user may write outside the intended Docker cache path. NVD affected builds end before 7.146.35, and 7.161.0 through builds before 7.161.16. CVSS 5.3. Patch to 7.146.35 or 7.161.16 (or later). Treat artifact caches as part of the software supply chain, not a side appliance.

JFrog security advisories

vulnerabilities supply chain