← Carolina Clear Tech

Cyber Threat Brief

2026-08-30

Listen to this brief (8:37)

Download MP3
Show Notes

Show Notes - 2026-08-30

Stories Covered

CVEs Referenced

CVE-2026-18431, CVE-2026-19598, CVE-2026-19632, CVE-2026-76581, CVE-2026-82222

Indicators of Compromise

Domains: gitnow[.]dev, bestsocialmedianewspapper[.]com, offlineupdater[.]com, gitnow[.]dev.

IP Addresses: 4.16.7.2

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

IT Security Brief - 2026-08-30

Today: A new ClickFix variant called TerminalFix is deploying reverse-tunnel backdoors through fake Cloudflare CAPTCHAs. Five critical WordPress plugin vulnerabilities enable complete site takeover. Ransomware groups Falcon, Zawoo, and dysphor1a claimed 9 victims including medical device maker Globus Medical.

Critical Alerts

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft disclosed a new ClickFix variant that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages on compromised websites. The attack deploys a multi-stage payload through DLL sideloading, establishes persistence via Registry and scheduled tasks, performs extensive Active Directory reconnaissance, and installs a Python-based reverse-tunnel implant that provides network-level proxy access through infected machines. The backdoor connects to gitnow[.]dev:443 via encrypted WebSocket and enables attackers to reach any host visible from the victim's network.

Ransomware Claims (Last 48h)

9 claims tracked across 3 groups in the last 48 hours. These are unverified claims from ransomware leak sites.

Group Victim Sector Country
Falcon Globus Medical Medical Devices US (NYSE: GMED)
Falcon DistributionNOW Energy/Industrial Distribution US (NYSE: DNOW)
Zawoo vectorsoft.de Software Development Germany
Zawoo Winterdienst Berlin Municipal Services Germany
Zawoo HD Werkstätten Social Services Germany
Zawoo NG Engineering Engineering Services Germany
Zawoo Multiple German entities Real Estate, Hospitality, Manufacturing Germany, Czech Republic
dysphor1a Yoma Fleet Vehicle Leasing Myanmar
dysphor1a AYUDHYA TH Insurance Insurance Thailand

Ransomware & Extortion

Berlin Government Faces 30 Bitcoin Ransom Demand

Hackers who breached Berlin's administrative data network two weeks ago are demanding 30 bitcoin. The city government declined to comment on the demands, withheld information about which data was accessed, and will not confirm who is behind the attack. The investigation remains ongoing.

PEAR Ransomware Claims 1.4 TB Exfiltration from Texas Healthcare Provider

The PEAR ransomware group claims to have exfiltrated 1.4 TB of data from South Plains Rural Health Services (SPRHS), a nonprofit healthcare organization serving rural West Texas communities. SPRHS has not publicly acknowledged the incident or issued breach notifications.

Two Ransomware Groups Target Interim HealthCare Franchises

Two different threat groups recently attacked separate Interim HealthCare franchise locations. Interim HealthCare of West Texas (Lubbock, Amarillo, Pampa) reported 2,071 affected patients in April, while the Amarillo franchise reported 666 affected patients. The pattern raises questions about whether franchise business models create systemic vulnerabilities that other franchisees should address.

Business & Infrastructure Threats

Hasbro Data Breach Exposed Employee Personal Information

Toy and game manufacturer Hasbro is notifying employees that their personal information was compromised in a data breach, likely connected to the March 2026 cyberattack that cost the company $11 million in cleanup expenses and delayed $25 million in product sales. Exposed information includes names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information. At least 436 Massachusetts residents are affected; total impact likely in the hundreds to low thousands given Hasbro's 4,600 employee count. No ransomware group has claimed responsibility.

Click2Mail Website Actively Hijacked, Customer Payment Cards Sold to Fraudsters

Click2Mail.com customers who checked out with debit cards have had their card details stolen and sold to fraudsters. At least two confirmed incidents occurred on June 2 and later in August. The website checkout process is actively compromised. Click2Mail customers should be receiving data security incident notifications soon.

US Officials Backpedal on Claims Government Agencies Were Hacked by China

The Justice Department revised its statement Friday, now saying the U.S. Senate, Federal Reserve, NASA, and other agencies were "among the targets" of Chinese hackers rather than confirmed victims. The backpedaling suggests initial breach claims were overstated or based on incomplete information.

Patch Priority

Vulnerability Disclosures

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Five critical vulnerabilities (CVSS 9.8-10.0) were disclosed in popular WordPress plugins and themes, affecting WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. CVE-2026-76581 (WPMU DEV Dashboard, CVSS 9.8, EPSS 0.003/27th percentile) allows authentication bypass when Hub SSO is enabled and mapped to an administrator account. CVE-2026-18431 (Avada theme, CVSS 9.8, EPSS 0.006/48th percentile) enables arbitrary file write leading to RCE when Fusion Builder is active. CVE-2026-19632 (TranslatePress, CVSS 9.8, EPSS 0.008/53rd percentile) exposes administrator password-reset URLs when automatic string saving is enabled and admin locale is set to a secondary language. CVE-2026-19598 (Pods, CVSS 9.8, EPSS 0.028/85th percentile) allows privilege escalation to Administrator for unauthenticated attackers. CVE-2026-82222 (GiveWP, CVSS 10.0, EPSS 0.004/35th percentile) chains broken deserialization helper, donation flow data handling, and gadget chain to achieve remote code execution on sites with one published donation form and one active payment gateway.

Trends & Context

ClickFix attacks continue evolving with TerminalFix now targeting Windows Terminal and PowerShell instead of the Run dialog, increasing execution reliability for complex multi-line scripts. WordPress plugin vulnerabilities remain a consistent attack surface with five critical flaws disclosed today enabling complete site takeover. Ransomware groups maintain pressure on healthcare, manufacturing, and critical services with 9 claims in 48 hours spanning medical devices, insurance, and municipal infrastructure.