Daily Recap, Browser and privacy updates highlighted Brave adding email aliases to reduce tracking and Android 17 rolling out OS-wide ECH to better conceal browsing activity from network providers. In other headlines, Hasbro and McKesson disclosed separate data breaches, Berlin refused a ransomware demand, and PaperCut released additional emergency patches after printer-management exploitation reports involving chained flaws. #Brave #EmailAliases #Android17 #OSWideECH #Hasbro #McKesson #ShinyHunters #Berlin #Qilin #PaperCut #CosmosEVM #CosmosLabs #GiveWP #Log4j #Minimus #ATF #WhiteHouse
Category: Cyber Security News
Multiple critical flaws in WordPress plugins and themes including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP can enable authentication bypass, administrator account takeover, arbitrary file write, and remote code execution. Patchstack and Wordfence say the GiveWP issue chains unsafe unserialization with attacker-controlled data and a gadget chain to achieve command…
Brave browser 1.94 adds Email Aliases, letting users create disposable addresses that hide their real email while still forwarding messages to their inbox. The feature is designed to reduce spam, limit cross-site identity matching, and lower the risk of phishing after service breaches. #Brave #EmailAliases #OPAQUE
Hasbro is notifying employees and former employees that their personal information may have been exposed in a security incident involving its network earlier this year. The compromised data may include names, contact details, national ID numbers, and financial information, and Hasbro is offering identity protection services while its investigation continues. #Hasbro…
The Trump administration issued an executive order banning the acquisition of foreign-made bulk-power system technology to reduce risks of backdoors, remote access, and supply-chain disruption in U.S. critical infrastructure. The move comes amid rising attacks on water, power, and other essential sectors, with officials and experts warning that AI-enabled threats and…
Daily Recap, AI security coverage highlighted how agentic and generative AI is being used to speed up vulnerability discovery and coordinate attacks, while defenders and major tech firms also push expanded AI-driven cyber defense pledges. Separately, OpenAI-linked activity, Hugging Face’s reported rogue agent coordination, multiple high-impact software flaws (including Gitea, Next.js, and ServiceNow), and several confirmed breach and enforcement cases (Hasbro, Manchester Airports Group, ATF, and TeamPCP) underscored the fast-moving threat landscape.
#AgenticAI #OpenAI #HuggingFace #RogueAgents #LinuxKernel #Gitea #Nextjs #AVIF #Windows #ServiceNow #PaperCut #NG #MF #ATF #Hasbro #ManchesterAirportsGroup #TeamPCP #PowerGrid #Grokk #XAI #Grok #TrumpOrder
PaperCut warned that vulnerabilities in PaperCut NG and PaperCut MF, tracked as CVE-2026-82078 and CVE-2026-81578, are being actively exploited and have already led to confirmed customer incidents. The company has issued emergency patches and urged organizations to remove servers from the public internet while restricting access to trusted IP addresses. #PaperCut…
Cosmos Labs said a critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The issue affected multiple Cosmos EVM versions, was patched in v0.6.2 and v0.7.2, and required coordinated network upgrades or chain halts to mitigate. #CosmosLabs…
Berlin’s state government says it is being extorted after the August compromise of its state administrative network and will not pay, while forensic work also found additional data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment. Manchester Airports Group also confirmed unauthorized access to customer data tied…
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while ShinyHunters claimed it stole 284 million patient data records. The attackers reportedly used vishing to compromise Okta accounts and access McKesson’s Salesforce and Snowflake environments. #McKesson #ShinyHunters #Okta #Salesforce #Snowflake
ATF says the cyberattack it disclosed was limited to a standalone system containing investigation target information and did not affect other agency systems or mission operations. Qilin claimed responsibility, but the agency has not confirmed its involvement and says the incident remains under investigation. #ATF #Qilin
A 68-year-old man in the U.K. was sentenced to more than six years in prison for running an illegal IPTV service that generated nearly £981,000 over three years. Police seized 80 servers used in the operation, which streamed pirated content from major rights holders including the BBC, ITV, Sky, the Premier League, and the Motion Picture Association. #PIPCU #CityofLondonPolice #BBC #ITV #Sky #PremierLeague #MotionPictureAssociation
A maximum-severity flaw in the GiveWP WordPress plugin, tracked as CVE-2026-82222, can let an unauthenticated attacker achieve arbitrary command execution on the hosting server by chaining multiple vulnerabilities. GiveWP fixed the issue in version 4.16.7.2, and site administrators should update immediately to protect affected installations through 4.16.7.1. #GiveWP #CVE-2026-82222
PaperCut has released Emergency Patch Release 2 for PaperCut NG and MF after researchers found ways to bypass the original fix for two actively exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078. The flaws can be chained to bypass authentication and achieve remote code execution, and PaperCut is urging customers to upgrade and restrict access to trusted IPs while it continues investigating the attacks. #PaperCut #CVE-2026-81578 #CVE-2026-82078
Google announced new network security protections in Android 17 to improve connection privacy, including support for Encrypted Client Hello (ECH), which helps hide the websites and apps users access from network observers. The update also strengthens local network permissions, enables Certificate Transparency by default, and lets carriers disable 2G to reduce…