Here are today’s top cybersecurity stories for Thursday, August 27, 2026.
Oracle WebLogic Flaw Rated CVSS 10.0 Exploited for Months Before Reaching CISA’s List
CISA added CVE-2026-21962, a maximum-severity flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 24. The flaw lets an unauthenticated attacker with network access compromise affected instances and read or modify critical data. Oracle shipped a fix in its January 2026 patch update, but a China-linked actor used the flaw against government targets starting in July, months ahead of the KEV listing. Federal agencies face an August 27 remediation deadline. The Hacker News | SecurityWeek
CISA Adds Six Flaws to Exploited Vulnerabilities Catalog, Including Active Citrix NetScaler Bug
CISA added six vulnerabilities to its KEV catalog on August 26, led by CVE-2026-8452, a memory overflow in Citrix NetScaler ADC and Gateway rated 8.8. Citrix disclosed the bug in June and initially described denial-of-service impact only, but research from watchTowr published this month showed exploitation also achieves remote code execution as root. Telemetry recorded 36 exploitation attempts over 12 days from attacker infrastructure spanning ten countries. Federal agencies have until August 29 to patch. Help Net Security | BleepingComputer
Australian Police Charge Two Men Over TeamPCP Supply Chain Attacks
The Australian Federal Police charged two Western Australia men, aged 21 and 23, with a combined 14 offences tied to TeamPCP, the group blamed for the March 2026 compromise of the open source Trivy and Checkmarx KICS scanners and the LiteLLM AI gateway. Officers executed search warrants at three properties on August 26 and seized devices for forensic review. The original attack chain reached more than 2,100 organizations and roughly 434,000 CI/CD pipelines. Krebs on Security | The Hacker News
Manchester Airports Group Breach Exposes Data on 8.7 Million Customers
Manchester Airports Group, operator of Manchester, Stansted, and East Midlands airports, confirmed attackers accessed data belonging to about 8.7 million customers. Exposed information spans public Wi-Fi sign-ups, car parking, lounge, and fast-track bookings, including email addresses, phone numbers, vehicle registrations, and postcodes. The company said it holds no payment card or bank details, and reported airport operations and passenger safety remain unaffected. Cybernews | The Register
ShinyHunters Leaks Nearly 13 Million Carhartt Customer Records
The extortion group ShinyHunters published data tied to roughly 12.9 million Carhartt customer accounts after the clothing retailer declined to pay a $3.3 million demand. Independent analysis by Have I Been Pwned confirmed the unique email address count after researchers found the original leak padded with synthetic records. Exposed fields include email addresses, names, phone numbers, and physical addresses. Carhartt has not issued a public statement. BleepingComputer
Next.js Patches Critical Flaws Enabling Unauthenticated Remote Code Execution
The Next.js team shipped fixes in versions 15.5.24 and 16.3.3 addressing critical vulnerabilities tied to AVIF image processing and Windows-specific handling, both reachable without authentication. The advisory did not report exploitation in the wild ahead of the patch release on August 25. Site operators running affected versions should update without delay given the framework’s broad deployment across production web applications. The Hacker News
Spark RAT Campaign Targets Cambodia Using Vulnerable Security Driver
A multi-stage campaign delivering the open source Spark remote access trojan is targeting individuals and organizations in Cambodia. The attack chain abuses a vulnerable OPSWAT driver to terminate endpoint security processes before deploying the RAT, granting attackers persistent remote control over infected systems. Researchers have not attributed the campaign to a specific threat group. The Hacker News
Russian State-Linked Actors Spearphish EU Officials Over WhatsApp and Signal
The European Union’s Joint Cyber Unit disclosed eight significant spearphishing incidents against senior officials in 2026 conducted through WhatsApp and Signal rather than malware. Attackers impersonated Signal’s official support team, sending urgent security alerts designed to trick targets into surrendering account PINs. Dutch and Portuguese authorities have pointed to Russian involvement in related account takeover campaigns targeting officials, diplomats, and journalists. Dark Reading | Euronews
Stay tuned for today’s in-depth analysis posts.






