← All threat briefs

Cybersecurity Brief - August 29, 2026

SECURITY // 2026-08-29

Cybersecurity Brief - August 29, 2026

  • Berlin State Government Refuses Ransomware Payment: Following an extortion attempt involving the theft of approximately 5.79 TB of data from Berlin's state administrative network, authorities in Berlin have confirmed they will not meet the attackers' demands. Forensic investigations revealed unauthorized data exfiltration occurred between August 7 and August 12, 2026, potentially affecting personal information. (Source: The Hacker News)
  • Critical Cosmos EVM Vulnerability Exploited: A major flaw in the shared Cosmos EVM module was used to drain funds from six different blockchains between August 20 and August 25, 2026. The vulnerability, which handles balances incorrectly, has been patched in versions v0.6.2 and v0.7.2. (Source: The Hacker News)
  • Unauthenticated Code Execution Flaw in PaperCut: Attackers are actively exploiting a chain of two vulnerabilities in Papercut NG and MF to achieve remote code execution without authentication. The company has released an emergency fix and hardening measures to mitigate the threat. (Source: The Hacker News)
  • Two Alleged 'TeamPCP' Hackers Arrested: Australian authorities have arrested two individuals believed to be part of the TeamPCP cybercrime syndicate, a group notorious for large-scale software supply chain attacks involving malicious open-source code. The arrests are linked to an investigation into sophisticated campaigns that compromised thousands of businesses globally. (Source: Krebs on Security)