InfoSec News 20260828
Publicada em: 28/08/2026
TOP NEWS
Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search.
KB5120998 is a preview update that lets IT administrators test Windows bug fixes, improvements, and new features before they roll out to all users during next month's Patch Tuesday release.
Link
TLP1: Green
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks.
TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code.
Link
TLP1: Green
ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.
The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies.
Link
TLP1: Green
Cybersecurity State: Surveillance, Cyberwarfare, Cybercriminality and Hacktivism
Manchester Airports Group says hackers stole travelers' data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.
The intruder did not access customer payment details, and the attack had no impact on airport operations, the company said.
Link
TLP1: Green
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.
Link
TLP1: Green
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees.
Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble, Magic: The Gathering, Dungeons & Dragons, and many others.
Link
TLP1: Green
Breaches: Data Breaches and Hacks
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.
Link
TLP1: Green
Vulnerabilities: Vulnerability Advisories, Zero-Days, Patches and Exploits
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
Link
TLP1: Green
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.
The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.
Link
TLP1: Green
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.
The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint.
Link
TLP1: Green
Incident Response: Infrastructure, Training, SIEM and Incident Handling
What the Data Says About AI in Security Operations in 2026
AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it.
Link
TLP1: Green
Technical Articles: Forensics, Reverse Engineering, Malware, Phishing, Pentesting, Software Security and Cryptography
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI’s internal IM1 model coordinated the compromise through an unauthorized message board.
Last month, Hugging Face disclosed that autonomous AI agents exploited two vulnerabilities in its dataset-processing pipeline to execute code, steal cloud and cluster credentials, and move laterally across its production infrastructure.
Link
TLP1: Green
1Traffic Light Protocol (TLP) [1] for information sharing:
- Red: Not for disclosure, restricted to participants only.
- Amber: Limited disclosure, restricted to participants organizations.
- Green: Limited disclosure, restricted to the community.
[1]https://www.first.org/tlp