Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 31, 2026·5m

Cyber Security News for August 31 2026 - Daily DefSec Brief

Show notes

1. PaperCut ships a second emergency patch after attackers chain two zero-days — CVE-2026-82078, CVE-2026-81578 — SecurityWeek — https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/
2. Ruby on Rails file-read flaw is being exploited for remote code execution — CVE-2026-66066 — SecurityWeek — https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/
3. Self-spreading worm planted in an npm package with 150,000 weekly downloads — Cyber Security News — https://cybersecuritynews.com/popular-npm-package/
4. China-linked Fire Ant moves into Cisco routers and TACACS servers to blind logging — The Hacker News — https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
5. AWS Systems Manager agent path traversal lets a limited user write files as root — CVE-2026-81849 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-091-aws/
6. TerminalFix pastes a fake CAPTCHA command into Windows Terminal and opens a reverse tunnel — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
7. Fake IT help desk calls over external Teams accounts end in NTLM relay to the domain controller — Unit 42 — https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
8. Infostealers are lifting live Claude sessions and walking past two-factor — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/
9. Nineteen Chrome and Edge extensions were backdoored through automatic updates — The Hacker News — https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
10. Russian operators embed a nuclear-weapons prompt in malware to make AI analysis tools refuse — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/
11. A file that passes as an MP4 carries 6.5 MB of encrypted NetSupport RAT — Censys — https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
12. Voicemail-themed SVG attachments smuggled JavaScript past email filters at 5,527 organizations — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/
13. ValleyRAT ships as signed adware so users add it to their own exclusion lists — Securelist — https://securelist.com/valleyrat-backdoor-adware/121175/
14. Metasploit ships modules for Forgejo file read and a batch of other recent flaws — CVE-2026-59774, CVE-2026-3576 — Rapid7 — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
15. Composer flaw lets a malicious package change permissions on files it does not own — CVE-2026-59944 — Cyber Security News — https://cybersecuritynews.com/composer-flaw-expose-ssh-keys/
16. UK NCSC warns of rising OT targeting through internet-exposed systems and edge devices — Industrial Cyber — https://industrialcyber.co/control-device-security/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices/
17. CISA red team walked one network to domain admin and struggled badly in the other — Cybersecurity Dive — https://www.cybersecuritydive.com/news/cisa-red-team-exercises-lessons-cloud-soc/828733/
18. Microsoft tells everyone to ignore Defender alerts saying antivirus is off — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/