Rosetta Daily · Aug 30, 2026
Scanned 739 items across 10 active sources in the last 36 hours; selected 20 for this edition.
Actively Exploited (KEV)
ownCloud path traversal exploited against nuclear research body (CVE-2023-49105, CVSS 9.8)
CISA added this ownCloud flaw to its KEV catalog after reports that a Chinese-speaking threat actor used it to steal records from a Philippine nuclear research institute. The bug allows disclosure of admin credentials via a PHP environment variable, letting an attacker fully compromise the instance.
Sources: The Hacker News
Gitea code injection under active exploitation, 8,300+ servers still exposed (CVE-2026-60004)
Shadowserver reports over 8,300 internet-facing Gitea instances remain unpatched against a critical code-execution flaw now listed in CISA's KEV catalog and under ongoing attack.
Sources: Bleeping Computer
Critical Vulnerabilities
PaperCut NG/MF zero-day chain actively exploited, second emergency patch issued
Two chained flaws in PaperCut's print management software let an unauthenticated attacker seize the application's trusted configuration and execute arbitrary Java code. PaperCut confirmed "customer incidents" and shipped a second emergency fix after researchers found ways to bypass the first patch.
Sources: The Hacker News · Bleeping Computer
ServiceNow AI Platform — three CVSS 10.0 flaws allow unauthenticated code and SQL execution
ServiceNow patched four AI Platform vulnerabilities, three scoring a maximum 10.0 and exploitable by an unauthenticated attacker for code injection, SQL injection, and privilege escalation. Hosted instances are already patched; self-hosted customers must apply the update themselves.
Sources: The Hacker News · Bleeping Computer
WPMU DEV Dashboard plugin authentication bypass (CVE-2026-76581, CVSS 9.8)
All versions up to 5.0.1 of the WordPress management plugin mishandle HMAC message construction, letting an unauthenticated attacker bypass authentication entirely.
Sources: NVD
SOY CMS deserialization of untrusted data (CVE-2026-78032, CVSS 9.3)
Deserializing untrusted input can lead to arbitrary code execution at web-server privilege.
Sources: NVD
NUMail OS command injection (CVE-2026-82082, CVSS 9.3)
Green-Computing's NUMail lets an unauthenticated remote attacker inject and execute arbitrary OS commands.
Sources: NVD
"Save to Pocket" browser extension XSS (CVE-2026-82090, CVSS 9.2)
The extension injects external HTML into the page DOM, letting injected JavaScript alter application state through Pocket's native bridge methods.
Sources: NVD
cPanel & WHM root takeover via domain parking flaw (CVE-2026-65643)
cPanel patched a critical flaw in domain parking and addon domain handling that let a single hosting customer execute code as root, compromising the entire shared server. All supported cPanel & WHM versions are affected.
Sources: The Hacker News
GiveWP WordPress donation plugin — unauthenticated remote command execution
A maximum-severity flaw in the GiveWP donation/fundraising plugin lets an unauthenticated attacker execute arbitrary commands on the hosting server.
Sources: Bleeping Computer
Unitree G1 EDU humanoid robot — two root RCE chains, one over Bluetooth (CVE-2026-76639, CVE-2026-76640)
Researcher Olivier Laflamme disclosed two independent chains reaching root on the robot's Locomotion PC — one network-adjacent via chat_go/bashrunner, the other starting from a Bluetooth Low Energy connection.
Sources: The Hacker News
Web Security & Threat Research
China-made ZBT routers ship with two factory-installed root backdoors (CVE-2026-74232, CVE-2026-74233)
VulnCheck disclosed two undocumented implants — dubbed SPEAKINGSTONE and DARKLANTERN — baked into firmware for Shenzhen Zhibotong Electronics (ZBT) routers, each giving an unauthenticated remote attacker root command execution.
Sources: The Hacker News
Cosmos EVM balance-handling flaw exploited, six blockchains drained
Cosmos Labs knew the shared Cosmos EVM module was vulnerable before attackers exploited it between August 20–25 to drain funds across six blockchains. The flaw (GHSA-7g4w-cg88-2cq2) was published without a CVE identifier or CVSS score.
Sources: The Hacker News
19 Chrome/Edge extensions caught stealing crypto wallets
Socket researchers found 18 Chrome extensions and one Edge extension, published over the past six months, sharing code and tradecraft to steal wallet secrets and drain cryptocurrency.
Sources: The Hacker News
APT28-linked HOOKEDGE backdoor targets European governments
Recorded Future's Insikt Group tied a new lightweight Windows backdoor, HOOKEDGE, to campaigns against government and diplomatic targets in Romania, Spain, and Türkiye running from late September 2025 to early April 2026.
Sources: The Hacker News
AI Security
Research: LLM safety refusal lives in a "thin neural layer," fragile to perturbation
Unit 42's new diagnostic method shows that a model's safety-refusal behavior can be traced to a narrow slice of its internals, reinforcing the case for external, multi-layered guardrails rather than relying on the model's own alignment.
Sources: Unit 42 (Palo Alto)
Industry News
ShinyHunters claims 284 million McKesson patient records; company confirms breach
Healthcare distribution giant McKesson disclosed unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole 284 million patient records. (Cross-referenced: McKesson also appears as a named victim in today's ransomware-tracker data — see the Ransomware Watch edition.)
Sources: Bleeping Computer
Hasbro discloses employee data breach
The toy and game maker disclosed that attackers accessed personal and financial information belonging to an undisclosed number of employees.
Sources: Bleeping Computer
Berlin refuses to pay after state network extortion attempt
Berlin's state government confirmed an extortion attempt following the compromise of its administrative network, and said further data outflows were found in its transport and climate department. The city will not pay.
Sources: The Hacker News
Boston Scientific network disruption halts order processing, shares fall
According to 安全客, the global medical device maker suffered a network disruption that halted order fulfillment; the company's stock price fell in response. No further technical detail was available in the source item.
Sources: 安全客