← Carolina Clear Tech

Cyber Threat Brief

2026-08-29

Listen to this brief (12:28)

Download MP3
Show Notes

Show Notes - 2026-08-29

Stories Covered

CVEs Referenced

CVE-2023-49105, CVE-2024-28000, CVE-2026-53362, CVE-2026-58616, CVE-2026-66384, CVE-2026-66747, CVE-2026-70331, CVE-2026-74232, CVE-2026-74233, CVE-2026-76639, CVE-2026-76640, CVE-2026-78891, CVE-2026-78899, CVE-2026-78952, CVE-2026-81578, CVE-2026-82078

Indicators of Compromise

Domains: 209[.]241, 209[.]241.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: PaperCut NG/MF is under active exploitation with a pre-auth RCE chain -- patch immediately or pull it off the network. CISA added ownCloud CVE-2023-49105 to KEV with a remediation deadline of tomorrow (Aug 30) after Chinese-speaking actors used it to steal nuclear research files from the Philippines. Qilin ransomware hit ATF, designated a "major incident" by DOJ. ZBT-manufactured routers ship with two factory backdoor implants giving unauthenticated root access.

Critical Alerts

PaperCut NG/MF Pre-Auth RCE -- Active Exploitation (CVE-2026-81578, CVE-2026-82078)

Two chained vulnerabilities in PaperCut NG and MF enable pre-authentication remote code execution. CVE-2026-81578 is an improper access control flaw in the web management interface allowing unauthenticated configuration changes. CVE-2026-82078 is an unsafe dynamic class-loading vulnerability in database connection utilities enabling arbitrary Java bytecode execution. PaperCut treats all NG and MF versions as potentially affected.

ownCloud WebDAV Auth Bypass Exploited to Steal Nuclear Records (CVE-2023-49105) -- CISA KEV Due Aug 30

CISA added CVE-2023-49105 (CVSS 9.8) to KEV after Hunt.io identified a Chinese-speaking threat actor exploiting the ownCloud WebDAV API authentication bypass to exfiltrate 176 files (372 MB) from a Philippine nuclear research body. The flaw allows unauthenticated file access when the victim has no signing-key configured (the default). The same actor exploited CVE-2024-28000 (LiteSpeed Cache for WordPress, CVSS 9.8) against a Philippine Navy contractor. Staging server at 31.58.209[.]241 contained Sliver, Metasploit, and custom Python exploit scripts.

China-Made ZBT Routers Ship With Factory Backdoor Implants (CVE-2026-66747, CVE-2026-74232, CVE-2026-74233)

VulnCheck disclosed two factory-installed implants in Shenzhen Zhibotong Electronics (ZBT) router firmware. SPEAKINGSTONE (CVE-2026-74232, CVSS 9.8) beacons to a hardcoded C2 over UDP/10000, supports root command execution, PPPoE credential exfiltration, DNS hijacking, and reverse SSH tunnels. DARKLANTERN (CVE-2026-74233, CVSS 9.8) listens on UDP/9992 with effectively broken authentication. VulnCheck found 203 internet-facing DARKLANTERN instances across 22 countries. These are supply-chain implants, not post-compromise malware. No fixed firmware exists.

Ransomware & Extortion

ATF Confirms "Major Incident" After Qilin Ransomware Claim

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident affecting a standalone system containing information about ATF investigation targets. DOJ designated it a "major incident." Qilin, a Russian-speaking ransomware group active since 2022, claimed responsibility on August 26 but has not yet posted proof or a leak timer. Qilin has listed over 2,000 victims and was among the FBI's five most-reported ransomware variants in 2025. The group has partnerships with Scattered Spider and Moonstone Sleet, and infrastructure overlap with BianLian.

Winona County Pays $128K Ransom

Winona County, Minnesota paid $128,539.57 after ransomware was detected on its network on January 22, 2026. Payment was negotiated with insurance carrier assistance.

U.S. Bancorp Responds to LockBit Claims

U.S. Bancorp states ransomware claims involving its name stem from a potential incident at a fourth-party provider. No evidence of compromise to bank systems, networks, or data repositories. LockBit has threatened to publish allegedly stolen data.

Business & Infrastructure Threats

Paylogix Breach Exposes SSNs, Medical Data, Passport Numbers

Paylogix confirmed attackers stole files over several days in November, exposing Social Security numbers, financial/health insurance information, medical data, passport numbers, and taxpayer IDs. At least 67,789 people affected across South Carolina, New Hampshire, and Vermont. Akira ransomware group claimed responsibility.

700+ Active AWS Keys Found Exposed

Truffle Security reviewed 10,616 exposed AWS keys (2022-2026) and found over 700 still-active keys granting full account control. Separately, Intruder found 28,000 exposed Git repositories across 3.5 million hosts, uncovering 400+ AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens, and 17 GitHub PATs.

Cybersecurity Firm Minimus Shuts Down

Hardened container image provider Minimus is winding down operations after raising $51M in 2025. Echo acquired the company and its technology. If you use Minimus container images, plan migration.

Windows / AD Security

Microsoft Edge and Chromium Security Updates

Microsoft published advisories for 22 Chromium-based vulnerabilities fixed in Edge, plus two Edge-specific flaws. CVE-2026-78899 is a use-after-free in V8. CVE-2026-78891 is a buffer overflow in WebRTC. CVE-2026-78952 is an out-of-bounds write in Crashpad. CVE-2026-70331 is an Edge for iOS spoofing vulnerability via LLM prompt injection. CVE-2026-58616 is a race condition information disclosure in Copilot Chat.

General Security News

Log4j RCE Scare Deemed Overblown

A Log4j 2 vulnerability raised concerns this week, but Apache developers described it as a "known security non-finding." While RCE is possible, specific circumstances are required for exploitation. Not a new Log4Shell-class event.

Mobile Banking Malware Expands

Zimperium identified 30 mobile malware families targeting 800+ banking and fintech apps across 44 EMEA countries. Attackers are using AI for localized lures, exploit scripting, and phishing overlays.

Russian Cyber Training Pipeline Exposed

Leaked Bauman University records reveal a program training ~250 students for Russian military intelligence and cyber operations, covering offensive/defensive techniques, malware analysis, and intelligence work.

Patch Priority

Vulnerability Disclosures

Unitree G1 EDU Humanoid Robot -- Two Root RCE Chains (CVE-2026-76639, CVE-2026-76640)

Two independent root RCE paths affect the Unitree G1 EDU robot. CVE-2026-76639 uses path traversal in chat_go to reach bashrunner for root execution. CVE-2026-76640 starts from BLE proximity and chains through a cloud authorization bypass and Wi-Fi provisioning buffer overflow. Unitree patched the cloud authorization check in July 2026 but no confirmed fixed firmware version has been published.

Carhartt Breach Data Partly Fake

Troy Hunt found roughly half of the 24.8M email addresses in the alleged Carhartt breach were synthetic TPC-DS benchmark data mixed with genuine customer information. ShinyHunters' claims significantly overstated the real data involved.

Trends & Context

Supply-chain compromise is the dominant theme today: factory-implanted backdoors in ZBT routers, a fourth-party breach affecting U.S. Bancorp, and nation-state exploitation of default-insecure file sharing (ownCloud). Print management software continues to be a high-value target for attackers, with PaperCut joining a growing list of enterprise tools exploited for initial access. Qilin's claim against ATF signals ransomware groups are increasingly willing to target federal law enforcement, even when payment is unlikely.