← All threat briefs

Cybersecurity Brief - August 30, 2026

SECURITY // 2026-08-30

Cybersecurity Brief - August 30, 2026

  • TerminalFix ClickFix Variant Targets Windows Users A new variant of the ClickFix campaign, dubbed "TerminalFix," uses fake Cloudflare CAPTCHA verifications on compromised websites to trick users into executing malicious PowerShell commands. Unlike previous versions that targeted the Windows Run dialog, this iteration specifically targets Windows Terminal and PowerShell to facilitate more complex, multi-line script execution through DLL sideloading and steganographic payloads. (Source: The Hacker News)

  • Critical Vulnerabilities Discovered in Popular WordPress Plugins/Themes Multiple critical flaws affecting WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP have been disclosed. These vulnerabilities, identified by Wordfence and Patchstack, allow for authentication bypass, account takeover, and remote code execution (RCE), including a high-severity CVE-2026-76581 flaw in WPMU DEV Dashboard with a CVSS score of 9.8. (Source: The Hacker News)

  • Berlin State Government Refuses Ransomware Payment Following Network Breach The Berlin Senate Chancellery has confirmed that its state administrative network was compromised, leading to an extortion attempt. While the city refuses to pay the ransom, forensic investigations revealed substantial data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and August 12, 2026. (Source: The Hacker News)

  • PaperCut Print Management Under 0-Day Attack The PaperCut print management software is currently facing a zero-day exploit that presents a significant risk to users. Currently, the only available mitigations are applying an unvalidated emergency patch or taking vulnerable servers offline to prevent exploitation. (Source: The Register)

  • FBI Seizes Chinese Hacking Tools Used Against US Critical Infrastructure The FBI has announced the seizure of hacking tools used by Chinese-linked actors to target highly sensitive US networks, including NASA, the Department of Energy, and the US Senate. The operation aims to disrupt botnets used for large-scale espionage and infrastructure targeting. (Source: The Register)

  • CISA Criticizes Systemic Failures in "Secure by Design" Implementation The Cybersecurity and Infrastructure Security Agency (CISA) has issued a sharp critique of modern vulnerability management, stating that many currently exploited vulnerabilities should have been eliminated decades ago. The agency cited deep-seated organizational culture issues and systemic gaps as primary obstacles to adopting a "Secure by Design" methodology. (Source: The Register)

  • Law Enforcement Dismantles TeamPCP Hacking Cell In a significant blow to supply chain attackers, Australian police, with assistance from the FBI, have arrested alleged masterminds of the TeamPCP group. The crew is believed to be responsible for the development and deployment of the Shai-Hulud worm and various other highly impactful supply chain attacks. (Source: The Register)

  • Manchester Airports Group Confirms Major Data Breach The UK's largest airport operator, Manchester Airports Group, has reported a significant data breach where cybercriminals successfully exfiltrated customer information. Preliminary estimates suggest that the personal data of approximately 8.7 million customers may have been compromised. (Source: The Register)