DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 29, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 29, 2026


πŸ“Š 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. McKesson Data Breach Claimed by ShinyHunters Extortion Group

U.S. healthcare giant McKesson has confirmed a cybersecurity incident involving unauthorized network access and data exfiltration. The ShinyHunters extortion group has claimed responsibility, alleging the theft of approximately one terabyte of data, including 284 million patient-related records, from a Snowflake environment. The breach was discovered on August 25, 2026, with the data exfiltration reportedly occurring over the preceding four days. McKesson has acknowledged the incident in an SEC filing but has not yet determined its full material impact. The investigation is ongoing, and the company has warned customers of potential service degradation.

πŸ“– Read full report β†’


2. Berlin Government Defies Rhysida Ransomware After 5.79TB Data Theft

The state government of Berlin, Germany, has publicly refused to pay a ransom demand from the Rhysida ransomware group. The threat actors claim to have exfiltrated 5.79 terabytes of data, including 1.44 million files, from the city's administrative network. The stolen data, which allegedly includes contracts, personal information, and classified documents, is being auctioned on the group's darknet leak site with a starting price of 30 bitcoin. The breach primarily affected the Senate Department for Mobility, Transport, Climate Protection and Environment, with data exfiltration occurring between August 7 and August 12, 2026. An investigation by German authorities is underway.

πŸ“– Read full report β†’


3. Data of 8.7M Customers Exposed in Manchester Airports Group Breach

Manchester Airports Group (MAG), operator of Manchester, Stansted, and East Midlands airports in the UK, has suffered a data breach affecting approximately 8.7 million customers. An unauthorized third party accessed a system containing customer information related to bookings for services like car parking and airport lounges. The exposed data includes names, email addresses, phone numbers, vehicle registrations, and postcodes. MAG has stated that no payment card details were compromised and that airport operations and security were not affected. The 'Manage My Booking' portal has been taken offline, and affected customers are being notified.

πŸ“– Read full report β†’


4. ATF Confirms Major Cyberattack; Qilin Ransomware Claims Credit

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed it is responding to a 'major' cybersecurity incident. The acknowledgment follows a claim by the Russian-speaking Qilin ransomware group that it had breached the federal agency. According to the ATF, the breach was contained to a 'standalone computer system' with information about targets of ATF investigations and was not connected to other core agency networks. The Qilin group, a prolific ransomware-as-a-service operation, is known for its double-extortion tactics and recently exploited a zero-day in Check Point VPNs.

πŸ“– Read full report β†’


5. PaperCut Urges Patch for Actively Exploited Zero-Day RCE Flaws

Print management software provider PaperCut has issued an urgent security warning about a vulnerability chain being actively exploited in the wild. The flaws, affecting all versions of PaperCut NG and MF, can be chained to achieve pre-authentication remote code execution (RCE). The attack combines an authentication bypass (CVE-2026-81578, CVSS 8.8) with an unsafe dynamic class-loading issue (CVE-2026-82078, CVSS 9.4). PaperCut has released emergency patches and strongly advises customers with internet-facing servers to apply them immediately or restrict access via firewall rules. Security firm Huntress has confirmed observing exploitation in customer environments.

πŸ“– Read full report β†’


6. ServiceNow Fixes Three 10.0 CVSS Flaws Enabling RCE and SQLi

ServiceNow has addressed three critical vulnerabilities in its Now Platform and AI platform, each assigned a maximum CVSS score of 10.0. The flaws could allow an unauthenticated attacker to achieve remote code execution, SQL injection, and privilege escalation. The vulnerabilities are tracked as CVE-2026-74944 (file upload RCE), CVE-2026-18886 (access control), and CVE-2026-74820 (SQL injection). Exploitation requires no user interaction or privileges. ServiceNow is not aware of any active exploitation but urges customers to apply the available patches, particularly for versions before 'Australia Patch 5'.

πŸ“– Read full report β†’


7. BlueDelta (APT28) Uses HOOKEDGE Backdoor in Espionage Campaign

The Russian GRU-linked threat group BlueDelta, also known as APT28, has been observed in a recent espionage campaign targeting European government and diplomatic organizations in Romania, Spain, and TΓΌrkiye. The campaign, detailed by Recorded Future, uses a new lightweight backdoor called HOOKEDGE. This backdoor is delivered via macro-enabled Word documents with diplomatic lures. In a novel technique, HOOKEDGE uses the legitimate developer service 'webhook.site' for its command and control (C2) communications, allowing it to blend in with normal web traffic and evade detection.

πŸ“– Read full report β†’


8. Baylor Genetics Data Breach Affects 2.8 Million Individuals

Houston-based genetics testing firm Baylor Genetics has disclosed a massive data breach affecting 2,810,878 individuals. According to its report to the U.S. Department of Health and Human Services, an unauthorized party accessed its network for nearly a week, from June 11 to June 17, 2026. The compromised data is highly sensitive, potentially including names, Social Security numbers, addresses, medical diagnoses, lab results, and other genetic testing information. The company discovered the intrusion on June 15 and has since secured its systems and begun notifying the large number of affected individuals across the United States.

πŸ“– Read full report β†’


πŸ“Œ Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)