-
Hasbro is notifying employees of exposed personal data, and its own public account of the March breach has not moved since April
Breach notification letters from Hasbro to its employees became public on August 28, 2026, filed with the Massachusetts attorney general’s office and reported by SecurityWeek and BleepingComputer. The…
-
GiveWP patched an unauthenticated CVSS 10.0 remote code execution flaw and called it additional hardening
GiveWP, a donation plugin installed on more than 100,000 WordPress sites, released version 4.16.7.2 on August 27, 2026. The plugin’s own changelog describes the release in one line:…
-
A Log4j deserialization report was deleted and its author erased. Apache says it is a known non-finding; the exploit lab is still up.
On August 24, 2026 a researcher posting as U-Sec opened issue #4255 on the Apache Logging Services repository, describing a way to defeat Log4j’s allowlist-based deserialization filter. By…
-
ATF confirms a breach of a standalone system, and the Justice Department has already called it a major incident
The Bureau of Alcohol, Tobacco, Firearms and Explosives published a statement on August 26, 2026 confirming a cybersecurity incident, and in the same three-sentence paragraph confirmed something considerably…
-
Berlin confirms it is being extorted, eleven days after announcing a network compromise without mentioning it
The State of Berlin acknowledged a compromise of its administrative network on 17 August without mentioning extortion. On 28 August it confirmed the extortion and rejected the ultimatum…
-
Gitea’s federal deadline expired with 8,393 servers still vulnerable, and the exploitation record is one CPU alert
CISA gave federal agencies three days to fix a critical Gitea remote code execution flaw. The clock ran out on 28 August; the day before, Shadowserver counted 8,393…
-
ServiceNow scored three of its own AI Platform flaws at a flat 10.0, and a fourth record contradicts itself on authentication
ServiceNow’s PSIRT published four CVEs on 27 August and scored three of them at a flat CVSS v4.0 10.0 with byte-identical vectors — while the fourth record describes…
-
PaperCut’s zero-day is now two chained CVEs, and the first emergency patch does not stop the chain
PaperCut’s unnamed zero-day now has two CVE numbers, a confirmed chain, and a second emergency patch — because researchers bypassed the first one. Anyone who patched on 27…
-
The vendor record understated the day, and a federal clock runs out tomorrow
Citrix still calls CVE-2026-8452 a denial of service. It is a pre-auth root shell with a federal deadline of Saturday, and it outranks the two breaches that sound…
-
UI-TARS-desktop’s MCP servers listened on every interface with no authentication, and the fix is a commit, not a release
CVE-2026-81735 scores 10.0 because the MCP command server had no authentication and listened on every interface — and the remediation is identified by a commit hash, not a…
-
Langflow 1.11.2 fixes three code-execution flaws, one of them unauthenticated, with no workaround offered
Three code-execution CVEs against Langflow OSS 1.0.0 through 1.11.1 reached NVD late Friday; one needs no credentials, IBM lists no workaround, and the fix is 1.11.2. What happened…
-
McKesson confirms a cybersecurity incident and files it under Item 7.01, not the SEC’s cybersecurity item
McKesson told the SEC on Friday that it discovered a cybersecurity incident on 25 August. The filing does not say whether any data left the company — the…
-
A 2019 SQL Server bug is on a federal clock that runs out Saturday, and it needs a login to work
CVE-2019-1068 was published in July 2019 and patched the same month; CISA added it to the Known Exploited Vulnerabilities catalog on 26 August 2026 with a 29 August…
-
CISA gave two of this week’s KEV additions three days and four of them fourteen. The required-action text is identical on all of them
Across the nine CVEs CISA added to the Known Exploited Vulnerabilities catalog on 26 and 27 August, the “required action” text is the same on a three-day deadline…
-
A 2023 ownCloud auth bypass is on a three-day federal clock ending Sunday, and the evidence is the attacker’s own open directory
CVE-2023-49105 went into the federal Known Exploited Vulnerabilities catalog on 27 August with a 30 August due date — and the exploitation record behind it comes from one…