Daily Briefing

Cybersecurity & Geopolitics Briefing — Saturday, August 29, 2026

Geopolitical cyber intelligence in 5 minutes
Saturday, August 29, 2026 · 11 stories

This briefing covers 11 cybersecurity and geopolitics stories published around Saturday, August 29, 2026, and 5 disclosed vulnerabilities (CVE-2026-18527, CVE-2026-75118, CVE-2026-82278, CVE-2026-82279 and others). Each entry links to the original reporting.

Share this digest:

Microsoft Exposes TerminalFix ClickFix Campaign Using Reverse Tunnels (1 minute read)

Microsoft Threat Intelligence detailed TerminalFix, a multistage intrusion campaign using fake CAPTCHA prompts, DLL sideloading, and reverse tunnels to establish persistent access.

Microsoft Threat Intelligence · 9h ago · Read full article →

Russian Exile Publishers Smuggle Contraband Books Past Kremlin Censors (1 minute read)

Publishers operating outside Russia are covertly distributing banned literature inside the country to circumvent state censorship. The underground book trade reflects a widening information battleground as Moscow tightens ideological control ahead of prolonged wartime mobilization.

Foreign Policy · 18h ago · Read full article →

Qilin Ransomware Hits ATF System Holding Active Investigation Targets (1 minute read)

Qilin ransomware compromised a standalone ATF system containing data on the bureau's active investigation targets. A federal law enforcement target list in criminal hands creates direct operational security risk for ongoing investigations and exposed informants.

CyberScoop · 16h ago · Read full article →

Hasbro Cyberattack Leaks Employee Personal Data in Undisclosed Breach (1 minute read)

Hasbro confirmed a data breach exposing employee personal information following a cyberattack earlier this year. The delayed disclosure timeline raises questions about breach notification obligations and vendor-chain exposure across the consumer goods sector.

SecurityWeek · 1h ago · Read full article →

Berlin Refuses Ransom After Hackers Breach City-State Administrative Network (1 minute read)

Berlin's state government confirmed an August breach of its administrative network and additional data exfiltration from the Senate Department for Mobility, Transport, and Climate Protection, rejecting extortion demands.

The Hacker News · 15h ago · Read full article →

CVE-2026-18527: IBM i Runtime Expert Allows Unauthenticated Privilege Escalation (2 minute read)

IBM Administration Runtime Expert for i 1R1M0 carries a CVSS 9.9 flaw letting unauthenticated remote attackers execute actions under authenticated user profiles. Unauthenticated privilege escalation on IBM i systems running enterprise workloads is a critical exposure for government and financial sector operators.

CVE Feed (High Severity) · 14h ago · Read full article →

CVE-2026-75118: TP-Link TL-MR100 Login Endpoint Hit by Stack Buffer Overflow (3 minute read)

A pre-authentication stack-based buffer overflow in TL-MR100 V3.20's http_gdpr_decrypt function enables adjacent unauthenticated attackers to achieve arbitrary code execution via the /cgi/login endpoint.

CVE Feed (High Severity) · 14h ago · Read full article →

CVE-2026-82285: BISHENG Unauthenticated SSRF Exposes Internal Networks and Cloud Metadata (2 minute read)

BISHENG through 2.6.0-fix2 exposes an unauthenticated SSRF endpoint at POST /api/v1/workflow/report/callback with no URL scheme or host restrictions, enabling internal network enumeration and cloud metadata theft.

CVE Feed (High Severity) · 16h ago · Read full article →

CVE-2026-82279: HyperDX Missing RBAC Lets Any Member Seize Team Admin Control (2 minute read)

HyperDX through 1.10.1 enforces no role-based access controls on team management endpoints, allowing any member to delete owners, rotate API keys, and rename teams.

CVE Feed (High Severity) · 16h ago · Read full article →

CVE-2026-82278: BISHENG Authenticated RCE via Unsandboxed Python exec() in Workflows (2 minute read)

BISHENG before 2.6.0 executes arbitrary Python code submitted to POST /api/v1/workflow/run_once via exec() without sandboxing, granting authenticated attackers filesystem and credential access. RCE in AI orchestration platforms threatens downstream data pipelines, model integrity, and connected enterprise services.

CVE Feed (High Severity) · 16h ago · Read full article →

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was (1 minute read)

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains betw...

The Hacker News · 16h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now