During the 24-hour period of August 30-31, 2026, the threat landscape saw significant activity across multiple domains. Twenty-nine organizations were targeted by ransomware groups, with notable attacks against Glassdoor (job platform with millions of user reviews), medical device manufacturer Globus Medical, and energy distributor DistributionNOW. The Gentlemen ransomware group demonstrated particularly aggressive activity with 17 confirmed victims across manufacturing, healthcare, retail, and infrastructure sectors.
Critical vulnerabilities dominated the CVE landscape, including three CRITICAL-severity flaws (WordPress MyHome Core plugin authentication bypass CVE-2026-15980, Tenda router buffer overflows, TOTOLINK memory corruption) enabling remote code execution and authentication bypass. Chrome Web Store extensions were caught deploying infostealer malware targeting cryptocurrency and browser data, while Anthropic warned that Claude AI sessions are being hijacked through session-stealing malware. IoT botnets Mozi and Mirai continued widespread propagation with 50 malware distribution URLs identified, primarily targeting vulnerable routers and network devices across Asian and European IP spaces.
29 organizations across healthcare, manufacturing, technology, and government sectors were compromised by ransomware groups, with The Gentlemen group leading activity
The Gentlemen group compromised Glassdoor (glassdoor.com), a major U.S. job review platform owned by Recruit Holdings/Indeed with millions of company reviews for ~600,000 organizations. Platform hosts sensitive employee reviews, salary data, and company culture information across its user base.
Falcon ransomware group extracted 2.96 TB from NYSE-listed medical device company including entire Microsoft PowerBI database with 51,000+ customer records, FDA feedback, 510(k) submissions, PMA approval letters, TGA suspension proposals, product complaint logs, serious adverse event narratives, and financial data.
Falcon group exfiltrated 344 GB from NYSE-listed energy/industrial distributor including corporate bank statements, vendor payment instructions, detailed payroll records, employee compensation, tax documents, operational secrets, proprietary SCADA gateway backups, and PLC logic programs.
Direwolf ransomware group compromised THQ Nordic (thqnordic.com), a major multimedia and gaming company, potentially exposing game development assets, intellectual property, and corporate data.
Direwolf group targeted Erdem Hospital (Turkey) and Hospital Clínico Universidad de Chile, compromising patient data and medical systems across international healthcare infrastructure.
The Gentlemen group exfiltrated NDA files, HR data, employee data, technical drawings, models, bank statements, tax and legal documents, confidential files, work photographs, screenshots, passport scans, and VIP client data from major Indian infrastructure company.
ZaWoo ransomware group compromised Vectorsoft AG, a German software development company based in Heusenstamm, Hesse, potentially exposing source code, client data, and intellectual property.
Multiple critical authentication bypass and remote code execution vulnerabilities discovered across network devices, web applications, and enterprise software
Critical authentication bypass in MyHome Core plugin (all versions ≤4.4.5) due to missing authorization in send_link() AJAX handler and improper token validation in activate() function. Allows unauthenticated attackers to gain unauthorized access.
Critical buffer overflow in Tenda HG10 300001138 formIPv6Routing function (/boaform/admin/formIPv6Routing) in Boa Web Server component. Manipulation of destNet argument enables remote code execution.
Critical memory corruption vulnerability in TOTOLINK A720R 4.1.5cu.630_B20250509 setMacFilterRules function (cstecgi.cgi). Remote attackers can trigger memory corruption via desc argument manipulation. Public exploit available.
Critical stack-based buffer overflow in D-Link DIR-825M 1.1.8 affecting sub_46725C function in /boafrm/formDiskFormat. Partition parameter manipulation enables remote code execution with high impact on confidentiality, integrity, and availability.
AVideo (commit e01e41ecc and earlier) exposes stream credentials through getLiveKey.json.php endpoint. Token parameter bypasses both Live::canRestream() access control and restream ownership checks, returning complete stream credentials to unauthenticated attackers.
Blind SQL injection in Admidio <5.0.12 via relation_type_list parameter in lists_show.php. Unauthenticated attackers can execute arbitrary SQL queries by bypassing authentication with dummy UUID in role_list and injecting SQL through relation_type_list.
SiYuan <v3.8.1 fails to escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering. Attackers can inject HTML/script tags in block names that execute when other users view documents referencing those blocks.
Qubes OS <4.3.22 allows OS command injection during qvm-copy-to-vm from dom0 to attacker-controlled qube. System library function processes error messages containing shell metacharacters without sanitization in core-admin-linux/file-copy-vm/qfile-dom0-unpacker.
NextChat 2.15.8-2.16.1 contains improper URL validation in proxy endpoint allowing attackers to obtain server's OpenAI API key. x-base-url header validated using substring matching instead of hostname parsing, accepting any URL containing 'api.openai.com' substring.
Widespread IoT botnet activity with 50 malware distribution URLs identified, plus emerging threats targeting AI platforms and browser extensions
Multiple Chrome Web Store and Microsoft Edge extensions caught distributing malware framework deploying modules to steal cryptocurrency, sensitive data, browser history, and inject ClickFix social engineering lures. Highlights ongoing supply-chain risks in browser extension ecosystems.
Anthropic warns infostealer malware on user PCs is stealing active Claude login sessions, allowing attackers to access accounts and consume usage quotas. Demonstrates expansion of credential theft targeting AI platform sessions beyond traditional web services.
36+ Mozi botnet malware distribution URLs identified across compromised IoT devices, primarily in Asian IP ranges (China, South Korea). Mozi continues targeting vulnerable routers and network devices for DDoS and proxy botnet operations.
14 Mirai variant distribution URLs detected targeting IoT devices through bin.sh shell scripts. Infrastructure spans Asian and European networks, indicating continued exploitation of default credentials and unpatched vulnerabilities in consumer routers.
Ransomware groups demonstrated coordinated campaigns with The Gentlemen group showing highest activity levels
The Gentlemen group executed 17 confirmed attacks in 24 hours targeting diverse sectors including technology (Glassdoor), manufacturing (Thai Film Industries, Nutrypollo), industrial distribution (ESB Puerto Rico), healthcare (multiple facilities), and infrastructure. Group demonstrates capability for simultaneous multi-target operations with detailed reconnaissance.
Falcon group targeted high-value organizations including medical device manufacturer Globus Medical (2.96 TB extraction) and energy distributor DistributionNOW (344 GB), focusing on FDA-regulated data, SCADA systems, PLC logic, and financial records. Demonstrates targeting of operational technology environments.
Qilin group compromised government entity AFSARD (ipardpa.gov.mk), pharmaceutical company Crystalpharmatech, UK consultancy Absolute Consultancy Services, and Qatar-based Black Cat Engineering Construction. Focus on high-sensitivity sectors.
Observed attack techniques span authentication bypass, SSRF, SQL injection, and supply-chain compromise vectors
CVE-2026-82648: WWBN AVideo SSRF filter bypass in isSSRFSafeURL function fails to normalize NAT64 addresses in hexadecimal form. Attackers bypass protections using hex-encoded NAT64 addresses (64:ff9b::a9fe:a9fe) to reach cloud metadata endpoints and internal services.
CVE-2026-82644: WWBN AVideo rate limiting bypass in enforceRateLimit() protecting login.json.php and 13+ endpoints. Cache layer (ObjectYPT::setCacheGlobal) silently discards writes for certain client identifiers, enabling unlimited brute-force attempts.
CVE-2026-82635: Pake <3.13.1 joins JavaScript-supplied filename for download_file Tauri command with no sanitization. Filenames with path traversal (../Library/LaunchAgents/com.evil.plist) or absolute paths resolve outside ~/Downloads, enabling arbitrary file write for persistence.
Cybercriminals creating thousands of education-themed fake websites and phishing campaigns targeting students, parents, and educators as academic year begins. Education sector confirmed as world's most attacked vertical with record-high attack volumes.
Insider threat case and data breach notifications from government agencies
Nathan Vilas Laatsch, former Defense Intelligence Agency IT specialist, pleaded guilty to attempting to pass secret and top-secret information to foreign spies following successful FBI sting operation. Arrested May 2025, case highlights insider threat risks in intelligence community.
FulcrumSec claims 86 GB data theft from Manchester Airports Group with validated traveler records. Samples reveal detailed customer, booking, and travel information beyond MAG's initial disclosure, indicating comprehensive passenger data exposure.
U.S. Department of Veterans Affairs disclosed unintentional data breach affecting veterans receiving services through White River Junction, VT healthcare system. Multiple unencrypted communications sent during summer exposed personal information of service recipients.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.