CVE-2026-18431, CVE-2026-19598, CVE-2026-19632, CVE-2026-76581, CVE-2026-82222
Domains:
gitnow[.]dev, bestsocialmedianewspapper[.]com, offlineupdater[.]com, gitnow[.]dev.
IP Addresses:
4.16.7.2
Get tomorrow's brief in your inbox
Today: A new ClickFix variant called TerminalFix is deploying reverse-tunnel backdoors through fake Cloudflare CAPTCHAs. Five critical WordPress plugin vulnerabilities enable complete site takeover. Ransomware groups Falcon, Zawoo, and dysphor1a claimed 9 victims including medical device maker Globus Medical.
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft disclosed a new ClickFix variant that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages on compromised websites. The attack deploys a multi-stage payload through DLL sideloading, establishes persistence via Registry and scheduled tasks, performs extensive Active Directory reconnaissance, and installs a Python-based reverse-tunnel implant that provides network-level proxy access through infected machines. The backdoor connects to gitnow[.]dev:443 via encrypted WebSocket and enables attackers to reach any host visible from the victim's network.
9 claims tracked across 3 groups in the last 48 hours. These are unverified claims from ransomware leak sites.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Falcon | Globus Medical | Medical Devices | US (NYSE: GMED) |
| Falcon | DistributionNOW | Energy/Industrial Distribution | US (NYSE: DNOW) |
| Zawoo | vectorsoft.de | Software Development | Germany |
| Zawoo | Winterdienst Berlin | Municipal Services | Germany |
| Zawoo | HD Werkstätten | Social Services | Germany |
| Zawoo | NG Engineering | Engineering Services | Germany |
| Zawoo | Multiple German entities | Real Estate, Hospitality, Manufacturing | Germany, Czech Republic |
| dysphor1a | Yoma Fleet | Vehicle Leasing | Myanmar |
| dysphor1a | AYUDHYA TH Insurance | Insurance | Thailand |
Berlin Government Faces 30 Bitcoin Ransom Demand
Hackers who breached Berlin's administrative data network two weeks ago are demanding 30 bitcoin. The city government declined to comment on the demands, withheld information about which data was accessed, and will not confirm who is behind the attack. The investigation remains ongoing.
PEAR Ransomware Claims 1.4 TB Exfiltration from Texas Healthcare Provider
The PEAR ransomware group claims to have exfiltrated 1.4 TB of data from South Plains Rural Health Services (SPRHS), a nonprofit healthcare organization serving rural West Texas communities. SPRHS has not publicly acknowledged the incident or issued breach notifications.
Two Ransomware Groups Target Interim HealthCare Franchises
Two different threat groups recently attacked separate Interim HealthCare franchise locations. Interim HealthCare of West Texas (Lubbock, Amarillo, Pampa) reported 2,071 affected patients in April, while the Amarillo franchise reported 666 affected patients. The pattern raises questions about whether franchise business models create systemic vulnerabilities that other franchisees should address.
Hasbro Data Breach Exposed Employee Personal Information
Toy and game manufacturer Hasbro is notifying employees that their personal information was compromised in a data breach, likely connected to the March 2026 cyberattack that cost the company $11 million in cleanup expenses and delayed $25 million in product sales. Exposed information includes names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information. At least 436 Massachusetts residents are affected; total impact likely in the hundreds to low thousands given Hasbro's 4,600 employee count. No ransomware group has claimed responsibility.
Click2Mail Website Actively Hijacked, Customer Payment Cards Sold to Fraudsters
Click2Mail.com customers who checked out with debit cards have had their card details stolen and sold to fraudsters. At least two confirmed incidents occurred on June 2 and later in August. The website checkout process is actively compromised. Click2Mail customers should be receiving data security incident notifications soon.
US Officials Backpedal on Claims Government Agencies Were Hacked by China
The Justice Department revised its statement Friday, now saying the U.S. Senate, Federal Reserve, NASA, and other agencies were "among the targets" of Chinese hackers rather than confirmed victims. The backpedaling suggests initial breach claims were overstated or based on incomplete information.
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Five critical vulnerabilities (CVSS 9.8-10.0) were disclosed in popular WordPress plugins and themes, affecting WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. CVE-2026-76581 (WPMU DEV Dashboard, CVSS 9.8, EPSS 0.003/27th percentile) allows authentication bypass when Hub SSO is enabled and mapped to an administrator account. CVE-2026-18431 (Avada theme, CVSS 9.8, EPSS 0.006/48th percentile) enables arbitrary file write leading to RCE when Fusion Builder is active. CVE-2026-19632 (TranslatePress, CVSS 9.8, EPSS 0.008/53rd percentile) exposes administrator password-reset URLs when automatic string saving is enabled and admin locale is set to a secondary language. CVE-2026-19598 (Pods, CVSS 9.8, EPSS 0.028/85th percentile) allows privilege escalation to Administrator for unauthenticated attackers. CVE-2026-82222 (GiveWP, CVSS 10.0, EPSS 0.004/35th percentile) chains broken deserialization helper, donation flow data handling, and gadget chain to achieve remote code execution on sites with one published donation form and one active payment gateway.
ClickFix attacks continue evolving with TerminalFix now targeting Windows Terminal and PowerShell instead of the Run dialog, increasing execution reliability for complex multi-line scripts. WordPress plugin vulnerabilities remain a consistent attack surface with five critical flaws disclosed today enabling complete site takeover. Ransomware groups maintain pressure on healthcare, manufacturing, and critical services with 9 claims in 48 hours spanning medical devices, insurance, and municipal infrastructure.