Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 27, 2026·5m

Cyber Security News for August 27 2026 - Daily DefSec Brief

Show notes

1. PaperCut NG/MF under active exploitation, no patch yet — Help Net Security — https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/
2. GPUThor Rowhammer defeats ECC on NVIDIA workstation GPUs for root — The Hacker News — https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html
3. Veeam ONE coerces SMB auth from service account — CVE-2026-65641 — Cyber Security News — https://cybersecuritynews.com/veeam-backup-replication-flaw-exposes/
4. Three 10.0 flaws patched across Ubiquiti UniFi — CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 — CyberScoop — https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/
5. Attackers targeting exposed AI gateways to steal keys and mine crypto — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/
6. Spark RAT campaign abuses OPSWAT driver to kill security tools — CVE-2026-36425 — The Hacker News — https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html
7. AI-agent llms.txt files push unowned code into corporate networks — Ars Technica — https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
8. Claude Code Opus 5 Auto Mode falls to website-summary prompt injection — Embrace The Red — https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
9. Chinese-speaking operator loots Philippine nuclear and naval data via old flaws — Cyber Security News — https://cybersecuritynews.com/hackers-exploit-owncloud/
10. Aurora ransomware affiliate used an AI coding assistant across 20+ intrusions — Cyber Security News — https://cybersecuritynews.com/ransomware-hacker-uses-ai/
11. GoCaracal malware fetches C2 from an Ethereum smart contract — The Hacker News — https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html
12. AWS details how stolen cloud credentials escalate into full breaches — Cyber Security News — https://cybersecuritynews.com/aws-shows-how-hackers/
13. Nimbus Manticore adds TWOSTROKE-like backdoor and SSH tunneler — SC World — https://www.scworld.com/brief/nimbus-manticore-expands-infrastructure-and-malware-arsenal
14. Ajax.NET Professional deserialization flaw added to CISA KEV — CVE-2021-23758 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
15. Microsoft SQL Server RCE added to CISA KEV — CVE-2019-1068 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog