Cybersecurity Brief - August 31, 2026
-
Fire Ant (China-linked) compromises Cisco routers and TACACS servers to steal credentials and blind security logs. The China-nexus actor expanded its campaign from VMware hypervisors to target Cisco IOS XR routers and Linux management hosts, using the compromised devices as collection platforms to harvest network traffic and suppress logging. (Source: The Hacker News)
-
Australian authorities arrest two individuals linked to the 'TeamPCP' cybercrime syndicate. The arrests in Western Australia involve members of a group responsible for large-scale software supply chain attacks using the Shai-Hulud worm to compromise open-source tools and extort victims. (Source: Krebs on Security)
-
CISA adds three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. The updates include critical vulnerabilities in ownCloud (CVE-2023-49105), the Linux Kernel (CVE-2026-53362), and JFrog Artifactory (CVE-2026-66384), all based on evidence of active exploitation. (Source: CISA)
-
US Department of Justice corrects statement regarding Chinese hacking targets. The DoJ clarified that several US agencies, including NASA and the Federal Reserve, were among those targeted by the state-sponsored group QTFY, rather than being confirmed victims of successful intrusion in the initial announcement. (Source: The Hacker News)
-
A 0-day vulnerability in PaperCut print management software is causing significant impact. Attackers are utilizing an unvalidated vulnerability that forces customers to either apply unofficial emergency patches or take servers offline to prevent exploitation. (Source: The Register)