Security News

Cybersecurity news aggregator

📰
INFO News

Security Evening Update - August 29, 2026

  • ## Öfugt samantekt Þýðingin er fyrir íslenska kerfisstjóra og öryggisstjóra (CISO). ## ⚠️ Þörf á áfangi á skammti
  • *ServiceNow AI Platform RCE (CVE-2026-6875)** Einn kritik, óauðkennd fjarkeyrsla kóða veikleiki í ServiceNow AI Platform er í virkri nýtingu áður en uppfærslu var útgefin.
  • *CVE:** CVE-2026-6875 (CVSS: 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Pre-Brazil EA og önnur fyrri útgáfur
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html)
  • *PaperCut NG/MF auðkenningarframhjáhlaup núll-daga veikleiki** Einn kritik núll-daga auðkenningarframhjáhlaup veikleiki (CVE-2023-27350) í PaperCut NG/MF er í virkri nýtingu, sem leiðir til óauðkenndar fjarkeyrslu kóða með sérstaklega bættum HTTP POST kerfum.
  • *CVE:** CVE-2023-27350 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Öll útgáfur af NG/MF
  • *Lagfært í:** Útgefin vinnslu 2026-08-28
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild)
  • *Citrix NetScaler ADC/Gateway minnisskrun (CVE-2026-3055)** Einn kritik veikleiki í Citrix NetScaler ADC/Gateway sem er stillt sem SAML IdP, sem leyfir óauðkenndum hættulegum að leita út á vandlega minnisskrun.
  • *CVE:** CVE-2026-3055 (CVSS: 9.3)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fjölmörg útgáfur áður en 14.1-66.59 og 13.1-62.23
  • *Lagfært í:** Útgáfur 14.1-66.59 og 13.1-62.23
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907)
  • *Veeam Backup & Replication RCE (CVE-2026-44963)** Einn kritik afraðgreiningarveikleiki í Veeam Backup & Replication leyfir kerfisnotendum að keyra fjarverðs kóða á bakendakerfinu.
  • *CVE:** CVE-2026-44963 (CVSS: Ekki tilgreint)
  • *Staða:** Birt
  • *Veikar útgáfur:** 12.x áður en 12.3.2.4465; 13.x áður en 13.0.1.2067
  • *Lagfært í:** Útgáfur 12.3.2.4465 og 13.0.1.2067
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [The Hacker News: Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code](https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html) ## 🔍 Hættu aðgerð
  • *Rússnesk APT notar Zimbra núll-daga veikleika:** Þátttakandi grúpa "Laundry Bear" (TA488) hefur notið núll-daga kross-síðu skrifa veikleika (CVE-2025-66376) í Zimbra samvinnuþjóni yfir ár með netveiðar, sem leyfir útflutning gagna frá bandarískum og úkrainskum áhætta.
  • *FBI býður út á Kína tengda QTFY spjallnet:** FBI hefur býðið út á kerfi sem notuðu Kína tengda QTFY grúpa, sem notaði sérstaklega tæki (QScan, QTRouter) til að nýta veikleika (t.d. CVE-2019-11510) og ákveða bandarískar stjórnarráðstefnur eins og NASA, DOE og senátt.
  • *AI-gerðar aðgerðir á kerfisstjórn:** Bandarískar stjórnarráðstefnur varnar fyrir hættu að nota AI-gerðar aðgerðarkóða til að ákveða sýnilegar Siemens S7 Series stjórnkerfi (PLCs) í kerfisstjórn, sérstaklega í vatn og eldri.
  • *Fleiri netveiðar á Microsoft Device Code:** Hættu aðgerðir (t.d. ShinyHunters, EvilTokens) notar Microsoft OAuth Device Code flæði til að framhjálpa MFA og sækja aðgangslykilorð, sem leyfir aðgangsáhöfn í Microsoft 365 kerfum. ## 📋 Uppfærslur og uppfærslur
  • *Microsoft Edge:** Fjölmörg kritik fjarkeyrslu kóða og upplýsingar útflutning veikleikar sem áhrifast á útgáfur áður en 146.0.7680.75. Einn (CVE-2026-3909) er staðfestur sem í virkri nýtingu. Uppfæra í nýjasta útgáfu á skammti.
  • *Redis:** Fjölmörg kritik fjarkeyrslu kóða veikleikar (t.d. CVE-2026-23479, CVE-2026-25243) áhrifast á útgáfur upp í 8.6.2. Uppfærslur eru til í útgáfu 8.6.3. Fyrirtæki (Red Hat) hafa útgefið uppfærslur.
  • *Ubiquiti UniFi OS:** Fjölmörg kritik veikleikar (CVSS upp á 10.0) sem leyfir fjarkeyrslu kóða og réttindaaukning eru lagaðir í nýjum uppfærslum fyrir UniFi Network Application, OS Server og Cloud Gateway Industrial.
  • *Microsoft SQL Server:** Fjölmörg hávægðar (CVSS 8.8) réttindaaukning og fjarkeyrslu kóða veikleikar (t.d. CVE-2026-54117, CVE-2026-54118) sem áhrifast á SQL Server 2016-2022 voru lagaðir í júlí 2026 uppfærslum. ## Daglegar áætlanir 1. **Uppfæra ServiceNow og PaperCut á skammti.** Þessar eru í virkri, óauðkenndri aðgerð og eru fyrstafar aðgerðir fyrir hvaða fyrirtæki notar þessar tæki. 2. **Athuga og uppfæra Citrix NetScaler tæki** til útgáfanna sem tilgreindar fyrir CVE-2026-3055, þar sem nýting er í gangi og fyrirtæki á Þjóðarskógráðstefnum hefur verið beðin um að uppfæra. 3. **Athuga Microsoft 365 rannsóknarlogga fyrir óþekktar auðkenningar kerfis og læra notendur um netveiðar aðgerðir til að koma í veg fyrir aukningu á MFA framhjáhlaup hættu.** 4. **Athuga uppfærslu nákvæmni fyrir Veeam Backup & Replication, Redis og Microsoft Edge** í fyrirtækinu, með fyrstafar aðgerð fyrir kerfi sem eru aðgengileg frá netinu. ## 🔗 Heimildir - [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html) - [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild) - [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907) - [The Hacker News: AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastruct](https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html) - [The Hacker News: FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organ](https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html)
Read Full Article →

## Executive Summary The threat landscape on August 29, 2026, is dominated by active exploitation of critical vulnerabilities in foundational enterprise platforms. **ServiceNow AI Platform** and **PaperCut** are under immediate attack via unauthenticated RCE flaws exploited in the wild. State-sponsored activity remains high, with Russian APTs leveraging a **Zimbra zero-day** and the **FBI's disruption of the China-linked QTFY network** underscoring persistent targeting of government infrastructure. A critical new trend involves **AI-powered attacks**, both in the form of autonomous agents breaching platforms like Hugging Face and AI-generated scripts targeting **Siemens PLCs** in critical infrastructure.

## ⚠️ Immediate Action Required

* **ServiceNow AI Platform RCE (CVE-2026-6875)** A critical, unauthenticated remote code execution vulnerability in the ServiceNow AI Platform is being actively exploited days after patch release. * **CVE:** CVE-2026-6875 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Pre-Brazil EA and other prior releases * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html)

* **PaperCut NG/MF Authentication Bypass Zero-Day** A critical zero-day authentication bypass vulnerability (CVE-2023-27350) in PaperCut NG/MF is being actively exploited, leading to pre-authentication RCE via crafted HTTP POST requests. * **CVE:** CVE-2023-27350 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** All versions of NG/MF * **Fixed:** Apply emergency patch released 2026-08-28 * **Workaround:** None mentioned in source * **Reference:** [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild)

* **Citrix NetScaler ADC/Gateway Memory Leak (CVE-2026-3055)** An actively exploited critical out-of-bounds read vulnerability in Citrix NetScaler ADC/Gateway configured as a SAML IdP allows unauthenticated attackers to leak sensitive memory data. * **CVE:** CVE-2026-3055 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Multiple versions prior to 14.1-66.59 and 13.1-62.23 * **Fixed:** Versions 14.1-66.59 and 13.1-62.23 * **Workaround:** None mentioned in source * **Reference:** [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907)

* **Veeam Backup & Replication RCE (CVE-2026-44963)** A critical deserialization vulnerability in Veeam Backup & Replication allows domain users to execute remote code on the backup server. * **CVE:** CVE-2026-44963 (CVSS: Not specified) * **Status:** Disclosed * **Vulnerable:** 12.x prior to 12.3.2.4465; 13.x prior to 13.0.1.2067 * **Fixed:** Versions 12.3.2.4465 and 13.0.1.2067 * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code](https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html)

## 🔍 Threat Activity

* **Russian APT Exploits Zimbra Zero-Day:** The state-sponsored group "Laundry Bear" (TA488) has been exploiting a zero-day cross-site scripting vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite for over a year via phishing emails, enabling data exfiltration from US and Ukrainian targets. * **FBI Disrupts China-Linked QTFY Espionage Network:** The FBI has dismantled infrastructure used by the China-linked QTFY group, which employed custom tools (QScan, QTRouter) to exploit vulnerabilities (including CVE-2019-11510) and target U.S. federal agencies like NASA, the DOE, and the Senate. * **AI-Powered Attacks on Critical Infrastructure:** U.S. agencies warn of threat actors using AI-generated exploit scripts to target exposed Siemens S7 Series Programmable Logic Controllers (PLCs) in critical infrastructure sectors, particularly water and energy. * **Microsoft Device Code Phishing Surge:** Threat actors (e.g., ShinyHunters, EvilTokens) are increasingly exploiting the Microsoft OAuth device code flow to bypass MFA and steal access tokens, enabling persistent account takeover in Microsoft 365 environments.

## 📋 Patches & Updates

* **Microsoft Edge:** Multiple critical RCE and information disclosure vulnerabilities affecting versions prior to 146.0.7680.75. One (CVE-2026-3909) is confirmed as actively exploited. Update to the latest version immediately. * **Redis:** Multiple critical RCE vulnerabilities (e.g., CVE-2026-23479, CVE-2026-25243) affect versions up to 8.6.2. Patches are available in version 8.6.3. Enterprise distributions (Red Hat) have released updates. * **Ubiquiti UniFi OS:** Multiple critical vulnerabilities (CVSS up to 10.0) allowing RCE and privilege escalation have been patched in recent updates for UniFi Network Application, OS Server, and Cloud Gateway Industrial. * **Microsoft SQL Server:** Multiple high-severity (CVSS 8.8) privilege escalation and RCE vulnerabilities (e.g., CVE-2026-54117, CVE-2026-54118) affecting SQL Server 2016-2022 were patched in July 2026 updates.

## Today's Priorities 1. **Patch ServiceNow and PaperCut immediately.** These are under active, unauthenticated attack and are top-priority actions for any organization using these platforms. 2. **Review and update Citrix NetScaler appliances** to the patched versions specified for CVE-2026-3055, as exploitation is ongoing and federal agencies have been mandated to patch. 3. **Audit Microsoft 365 audit logs for suspicious device code authorizations** and educate users on device code phishing tactics to counter the rising MFA-bypass threat. 4. **Verify patch levels for Veeam Backup & Replication, Redis, and Microsoft Edge** across the enterprise, prioritizing systems accessible from the network.

## 🔗 References

  • [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html)
  • [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild)
  • [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907)
  • [The Hacker News: AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastruct](https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html)
  • [The Hacker News: FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organ](https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html)

Share this article