As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.
Weekly Cybersecurity Report | Week 35, 2026
Information security updates and events from the past week
1. Law Enforcement Arrests Key Operators of TeamPCP Supply-Chain Syndicate
Summary: On August 28, 2026, the U.S. Department of Justice and the Australian Federal Police announced the arrest and indictment of key members linked to TeamPCP, including Ruben Ian Thomson and Louis Michael Gaebler. The cybercrime group orchestrated widespread supply-chain attacks by compromising popular developer tools and open-source packages, including Aqua Security’s Trivy scanner GitHub Actions, LiteLLM on PyPI, and Checkmarx’s KICS. Investigators confirmed the malware infected more than 1,000 organizations globally, leading to the exfiltration of over 300 GB of data and the theft of more than 500,000 credentials.
Impact / Significance: Systemic software supply-chain poisoning. By weaponizing trusted CI/CD security scanners and developer libraries, the attackers turned routine automation workflows into mass credential-harvesting conduits, causing hundreds of millions of dollars in downstream damages.
Recommendations:
- Immediately audit and rotate all API keys, access tokens, and cloud secrets utilized in CI/CD pipelines.
- Pin software dependencies to strict cryptographic hashes rather than mutable version tags.
- Implement network isolation for CI/CD runners to prevent unauthenticated outbound data exfiltration.
Source: SecurityBoulevard — Arrests Hinder TeamPCP, But the Threat is Still Out There
2. Critical Cosmos EVM Flaw Exploited Across Six Live Blockchains (GHSA-7g4w-cg88-2cq2)
Summary: On August 28, 2026, Cosmos Labs published a post-mortem confirming that a critical balance-handling vulnerability in the shared Cosmos EVM module was exploited in the wild between August 20 and August 25 to drain digital assets across six independent blockchain networks. The flaw, designated GHSA-7g4w-cg88-2cq2, allowed attackers to manipulate balance states. Although reported via a bug bounty program in April, it was initially misjudged as unexploitable before active exploitation began.
Impact / Significance: Cross-chain systemic risk in decentralized finance (DeFi). Shared core modules create single points of failure where a logic vulnerability can compromise multiple sovereign blockchains simultaneously, requiring emergency state-breaking hard forks and chain halts.
Recommendations:
- Blockchain validators and node operators running Cosmos EVM must immediately upgrade to v0.6.2, v0.7.2, or later.
- Chain operators unable to patch immediately should halt chain block production to prevent asset drainage.
- Web3 engineering teams should implement formal verification and continuous fuzzing on state-transition and balance-accounting logic.
3. Berlin State Government Refuses Ransom Following 5.79 TB Data Theft by Rhysida Gang
Summary: On August 29, 2026, the state government of Berlin confirmed it is facing an extortion campaign after attackers infiltrated the city’s administrative network and exfiltrated 5.79 terabytes of data (approx. 1.44 million files) from the Senate Department for Mobility, Transport, Climate Protection and Environment. The Rhysida ransomware group listed the city on its darknet leak site, exposing sensitive geographic mapping datasets and personal records belonging to 12,076 individuals. The Berlin Senate formally declared that it will not pay the extortionists.
Impact / Significance: Major public sector disruption and sensitive data compromise. The breach highlights how attackers leverage valid VPN accounts lacking multi-factor authentication (MFA) and known directory elevation flaws (such as Zerologon) to infiltrate municipal infrastructure.
Recommendations:
- Mandate phishing-resistant multi-factor authentication across all external-facing remote access portals and VPN gateways.
- Audit active directory protocols and ensure legacy vulnerabilities (e.g., Netlogon / Zerologon) are fully mitigated.
- Enforce strict network segmentation between municipal department networks and centralized government administrative cores.
Source: The Hacker News — Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network
4. Critical WordPress Plugins and Themes Expose Sites to Remote Code Execution (CVSS 9.8)
Summary: On August 29, 2026, security researchers at Wordfence and Patchstack disclosed multiple critical vulnerabilities across widely used WordPress themes and plugins. Key findings include CVE-2026-76581 (CVSS 9.8), an authentication bypass in the WPMU DEV Dashboard plugin enabling unauthenticated administrative takeover via Hub Single Sign-On (SSO), and CVE-2026-18431 (CVSS 9.8), an arbitrary file write flaw in the Avada theme that allows unauthenticated remote attackers to write and execute malicious PHP files on the underlying server.
Impact / Significance: Full website takeover and remote server compromise. Successful exploitation grants attackers complete control over content management systems, enabling malicious script injection, customer data harvesting, and deployment of secondary web shells.
Recommendations:
- Update the WPMU DEV Dashboard plugin to version 5.0.2 or later immediately.
- Apply the latest security update released for the Avada theme and audit server directories for rogue .php files.
- Inspect WordPress user registries for newly created administrator accounts with anomalous metadata.
Source: The Hacker News — Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
5. CISA Urges SharePoint Hardening and Adds 6 Exploited Flaws to KEV Catalog
Summary: On August 26, 2026, CISA issued an updated operational alert regarding ongoing active exploitation of on-premises Microsoft SharePoint Server instances, explicitly advising organizations to isolate SharePoint Central Administration from public internet access. Concurrently, CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2026-8452 (a critical memory boundary flaw in Citrix NetScaler ADC and Gateway) and active exploits targeting Linux Kernel (CVE-2022-0995) and Microsoft SQL Server (CVE-2019-1068).
Impact / Significance: Threat actors continue to aggressively target enterprise perimeter appliances (Citrix NetScaler) and internal collaboration platforms (SharePoint) to establish footholds, bypass perimeter defenses, and maintain persistence within enterprise environments.
Recommendations:
- Remove all Microsoft SharePoint on-premises instances and Central Administration portals from direct internet exposure, placing them behind authenticated VPN or ZTNA solutions.
- Apply vendor patches immediately for Citrix NetScaler ADC and Gateway deployments to mitigate CVE-2026-8452.
- Review perimeter device audit logs for abnormal memory dumps or unauthorized configuration adjustments.
Source: CISA Alerts — CISA Urges SharePoint Hardening After New Exploitations | CISA Alerts — CISA Adds Six Known Exploited Vulnerabilities to Catalog
The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.