This briefing covers 11 cybersecurity and geopolitics
stories published around Saturday, August 29, 2026,
and 5 disclosed vulnerabilities
(CVE-2026-18527, CVE-2026-75118, CVE-2026-82278, CVE-2026-82279 and others).
Each entry links to the original reporting.
Microsoft Threat Intelligence detailed TerminalFix, a multistage intrusion campaign using fake CAPTCHA prompts, DLL sideloading, and reverse tunnels to establish persistent access.
Publishers operating outside Russia are covertly distributing banned literature inside the country to circumvent state censorship. The underground book trade reflects a widening information battleground as Moscow tightens ideological control ahead of prolonged wartime mobilization.
Qilin ransomware compromised a standalone ATF system containing data on the bureau's active investigation targets. A federal law enforcement target list in criminal hands creates direct operational security risk for ongoing investigations and exposed informants.
Hasbro confirmed a data breach exposing employee personal information following a cyberattack earlier this year. The delayed disclosure timeline raises questions about breach notification obligations and vendor-chain exposure across the consumer goods sector.
Berlin's state government confirmed an August breach of its administrative network and additional data exfiltration from the Senate Department for Mobility, Transport, and Climate Protection, rejecting extortion demands.
IBM Administration Runtime Expert for i 1R1M0 carries a CVSS 9.9 flaw letting unauthenticated remote attackers execute actions under authenticated user profiles. Unauthenticated privilege escalation on IBM i systems running enterprise workloads is a critical exposure for government and financial sector operators.
A pre-authentication stack-based buffer overflow in TL-MR100 V3.20's http_gdpr_decrypt function enables adjacent unauthenticated attackers to achieve arbitrary code execution via the /cgi/login endpoint.
BISHENG through 2.6.0-fix2 exposes an unauthenticated SSRF endpoint at POST /api/v1/workflow/report/callback with no URL scheme or host restrictions, enabling internal network enumeration and cloud metadata theft.
HyperDX through 1.10.1 enforces no role-based access controls on team management endpoints, allowing any member to delete owners, rotate API keys, and rename teams.
BISHENG before 2.6.0 executes arbitrary Python code submitted to POST /api/v1/workflow/run_once via exec() without sandboxing, granting authenticated attackers filesystem and credential access. RCE in AI orchestration platforms threatens downstream data pipelines, model integrity, and connected enterprise services.