DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 28, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 28, 2026


📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. ServiceNow Patches Critical Unauthenticated RCE Flaws

ServiceNow has issued urgent patches for three critical, unauthenticated vulnerabilities in its AI and Now Platforms, each rated with a CVSS score of 10.0. The flaws, identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, could allow a remote attacker to execute arbitrary code, escalate privileges to gain full control, and run malicious SQL commands against the instance database. These vulnerabilities affect the enterprise-grade PaaS used by 85% of Fortune 500 companies and require no user interaction to exploit. ServiceNow has deployed fixes to its hosted environments and released patches for self-hosted customers, who are urged to apply the updates immediately. A fourth high-severity sandbox escape flaw was also addressed. Currently, there is no evidence of these vulnerabilities being exploited in the wild.

📖 Read full report →


2. cPanel Flaw Grants Full Root Access on Servers

A critical vulnerability, CVE-2026-65643, has been discovered in the widely used cPanel & WHM web hosting control panel. The flaw allows any authenticated user with domain parking permissions to create arbitrary files on the server, leading to code execution as the root user. This presents a severe risk in shared hosting environments, where a single compromised low-privilege account could take over an entire server, compromising all other hosted websites and data. cPanel has released patches for all supported versions (11.110.0.141, 11.134.0.53, 11.136.0.37, and 11.138.0.2 or later). Administrators of servers that do not update automatically are urged to apply the patches manually to prevent server takeover.

📖 Read full report →


3. Citrix NetScaler RCE Flaw Actively Exploited

A high-severity memory overflow vulnerability in Citrix NetScaler ADC and Gateway (CVE-2026-8452) is being actively exploited in the wild. Initially rated for Denial of Service, researchers found it could lead to unauthenticated remote code execution. Attackers are now deploying web shells on compromised appliances. In response, CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies patch by August 29, 2026. With over 23,000 devices exposed online, all organizations using the affected Citrix products are urged to patch immediately and hunt for signs of compromise.

📖 Read full report →


4. Identity Attacks Drive Ransomware in Education

A new report from Sophos, "State of Ransomware in Education 2026," reveals that 85% of ransomware attacks against educational institutions begin with identity-based vectors like phishing and compromised credentials. This rate is higher than the cross-sector average. The report highlights a concerning trend in lower education (K-12), where the rate of successful data encryption more than doubled to 61% compared to the previous year. While median ransom demands have fallen, recovery costs have risen to an average of $2.26 million. The findings underscore the critical need for educational institutions to bolster identity security controls and user awareness training to defend against modern ransomware threats.

📖 Read full report →


5. ATF Confirms Breach by Qilin Ransomware

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed it is responding to a 'major' cybersecurity incident after the Qilin ransomware group claimed responsibility for an attack. The breach compromised a standalone computer system containing information about targets of ATF investigations. The agency stated that its core mission-critical systems and the main ATF network were not affected. The Justice Department has classified the event as a 'major incident' under FISMA, triggering congressional reporting requirements. This attack is the latest in a series of cyberattacks targeting U.S. federal law enforcement agencies.

📖 Read full report →


6. New Backdoors Found in Zbtlink Routers

Security firm VulnCheck has discovered two new backdoors, dubbed 'Darklantern' and 'Speakingstone,' in over a dozen models of Chinese-made Zbtlink routers. These routers are sold globally under various white-label brand names. The backdoors, which appear to be earlier versions of the previously discovered 'EndlessDoors' implant, provide invasive remote access and could be used for surveillance and network traffic redirection. Unlike 'EndlessDoors,' one of the new backdoors acts as a passive listener, making it harder to detect. The findings raise serious concerns about supply chain security and the potential for state-sponsored surveillance built into networking hardware.

📖 Read full report →


7. Meta Dismantles Iranian AI Influence Network

Meta has taken down an Iran-linked influence operation that used AI-generated content and fake personas to impersonate U.S. activists on Facebook and Instagram. The network, which consisted of 23 Facebook and 11 Instagram accounts, amassed nearly 80,000 followers before being dismantled. The operators pushed anti-Republican and anti-Israel messaging, attempting to engage with U.S. politicians and journalists to amplify their content. The campaign used sophisticated techniques to hide its origin, including creating detailed fake profiles and routing traffic through North American proxy services. Meta has shared its findings with U.S. law enforcement.

📖 Read full report →


8. AI-Generated Attacks Target Siemens PLCs

A joint advisory from U.S. agencies like the NSA and CISA warns of an ongoing campaign where threat actors are using AI-generated scripts to target Siemens S7 Series Programmable Logic Controllers (PLCs) in U.S. critical infrastructure. The attackers are using scanning tools to find exposed PLCs and then deploying malicious scripts, created with the help of AI and open-source libraries, to conduct reconnaissance. This activity suggests a pre-positioning for future disruptive attacks. The campaign affects a wide range of Siemens PLCs across sectors like energy, water, and manufacturing. Agencies urge asset owners to isolate these devices from the internet and apply patches.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)