Cybersecurity News | Daily Recap [29 Aug 2026]

Daily Recap, Browser and privacy updates highlighted Brave adding email aliases to reduce tracking and Android 17 rolling out OS-wide ECH to better conceal browsing activity from network providers. In other headlines, Hasbro and McKesson disclosed separate data breaches, Berlin refused a ransomware demand, and PaperCut released additional emergency patches after printer-management exploitation reports involving chained flaws. #Brave #EmailAliases #Android17 #OSWideECH #Hasbro #McKesson #ShinyHunters #Berlin #Qilin #PaperCut #CosmosEVM #CosmosLabs #GiveWP #Log4j #Minimus #ATF #WhiteHouse

Read More
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical flaws in WordPress plugins and themes including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP can enable authentication bypass, administrator account takeover, arbitrary file write, and remote code execution. Patchstack and Wordfence say the GiveWP issue chains unsafe unserialization with attacker-controlled data and a gadget chain to achieve command…

Read More
Hasbro Data Breach Exposed Employee Personal Information

Hasbro is notifying employees and former employees that their personal information may have been exposed in a security incident involving its network earlier this year. The compromised data may include names, contact details, national ID numbers, and financial information, and Hasbro is offering identity protection services while its investigation continues. #Hasbro…

Read More
White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Trump administration issued an executive order banning the acquisition of foreign-made bulk-power system technology to reduce risks of backdoors, remote access, and supply-chain disruption in U.S. critical infrastructure. The move comes amid rising attacks on water, power, and other essential sectors, with officials and experts warning that AI-enabled threats and…

Read More
Cybersecurity News | Daily Recap [29 Aug 2026]

Daily Recap, AI security coverage highlighted how agentic and generative AI is being used to speed up vulnerability discovery and coordinate attacks, while defenders and major tech firms also push expanded AI-driven cyber defense pledges. Separately, OpenAI-linked activity, Hugging Face’s reported rogue agent coordination, multiple high-impact software flaws (including Gitea, Next.js, and ServiceNow), and several confirmed breach and enforcement cases (Hasbro, Manchester Airports Group, ATF, and TeamPCP) underscored the fast-moving threat landscape.
#AgenticAI #OpenAI #HuggingFace #RogueAgents #LinuxKernel #Gitea #Nextjs #AVIF #Windows #ServiceNow #PaperCut #NG #MF #ATF #Hasbro #ManchesterAirportsGroup #TeamPCP #PowerGrid #Grokk #XAI #Grok #TrumpOrder

Read More
PaperCut warns of hackers using printer management software flaw in attacks

PaperCut warned that vulnerabilities in PaperCut NG and PaperCut MF, tracked as CVE-2026-82078 and CVE-2026-81578, are being actively exploited and have already led to confirmed customer incidents. The company has issued emergency patches and urged organizations to remove servers from the public internet while restricting access to trusted IP addresses. #PaperCut…

Read More
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs said a critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The issue affected multiple Cosmos EVM versions, was patched in v0.6.2 and v0.7.2, and required coordinated network upgrades or chain halts to mitigate. #CosmosLabs…

Read More
Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

Berlin’s state government says it is being extorted after the August compromise of its state administrative network and will not pay, while forensic work also found additional data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment. Manchester Airports Group also confirmed unauthorized access to customer data tied…

Read More
McKesson discloses breach after ShinyHunters claims patient data theft

McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while ShinyHunters claimed it stole 284 million patient data records. The attackers reportedly used vishing to compromise Okta accounts and access McKesson’s Salesforce and Snowflake environments. #McKesson #ShinyHunters #Okta #Salesforce #Snowflake

Read More
68-year-old imprisoned after making .3 million by pirating IPTV services

A 68-year-old man in the U.K. was sentenced to more than six years in prison for running an illegal IPTV service that generated nearly £981,000 over three years. Police seized 80 servers used in the operation, which streamed pirated content from major rights holders including the BBC, ITV, Sky, the Premier League, and the Motion Picture Association. #PIPCU #CityofLondonPolice #BBC #ITV #Sky #PremierLeague #MotionPictureAssociation

Read More
GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity flaw in the GiveWP WordPress plugin, tracked as CVE-2026-82222, can let an unauthenticated attacker achieve arbitrary command execution on the hosting server by chaining multiple vulnerabilities. GiveWP fixed the issue in version 4.16.7.2, and site administrators should update immediately to protect affected installations through 4.16.7.1. #GiveWP #CVE-2026-82222

Read More
PaperCut releases second emergency patch for exploited flaws

PaperCut has released Emergency Patch Release 2 for PaperCut NG and MF after researchers found ways to bypass the original fix for two actively exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078. The flaws can be chained to bypass authentication and achieve remote code execution, and PaperCut is urging customers to upgrade and restrict access to trusted IPs while it continues investigating the attacks. #PaperCut #CVE-2026-81578 #CVE-2026-82078

Read More
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google announced new network security protections in Android 17 to improve connection privacy, including support for Encrypted Client Hello (ECH), which helps hide the websites and apps users access from network observers. The update also strengthens local network permissions, enables Certificate Transparency by default, and lets carriers disable 2G to reduce…

Read More