Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Monday, August 31, 2026

Here are today’s top cybersecurity stories for Monday, August 31, 2026.

China-Linked Fire Ant Group Hijacks Cisco Routers to Steal Credentials
Security firm Sygnia disclosed an expansion of Fire Ant, a China-nexus espionage campaign previously focused on VMware hypervisors, into Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Compromised routers capture network traffic and harvest credentials, while a newly documented toolset called TacTap injects a malicious library into the authentication process on breached TACACS servers to suppress logging. The group used compromised systems as a path toward higher-value networks, including critical infrastructure, though confirmed compromise beyond scanning and connection attempts wasn’t reported. The Hacker News | BleepingComputer

Berlin Confirms Data Theft After Rhysida Ransomware Claims
Berlin’s state government confirmed cybercriminals stole data from its network after the Rhysida ransomware group listed the city on its leak site and claimed roughly 5.79 terabytes of files, including judicial documents, emergency response plans, and personal data tied to more than 12,000 individuals. Rhysida demanded 30 bitcoin, worth about $2.3 million, with a one-week deadline before threatening publication. Berlin’s Governing Mayor said the city won’t pay the ransom, aligning with EU and US law enforcement guidance. BleepingComputer | The Hacker News

Critical Elementor Pro Flaw Enables Unauthenticated Code Execution on WordPress Sites
Security researchers disclosed CVE-2026-32475, a critical flaw in the Elementor Pro WordPress plugin rated 9.0 on the CVSS scale, affecting versions up to 4.2.1. The bug stems from inconsistent handling of file uploads between validation and processing steps in the File Upload form module, letting an unauthenticated attacker submit two file parts in a single field to bypass the extension blocklist and write a PHP file to a public directory. Exploitation requires only a published Elementor form containing a File Upload field. Elementor patched the flaw in version 4.2.2, released August 19. The Hacker News | BleepingComputer

Chinese-Speaking Operator Steals Data From Philippine Nuclear and Naval Targets
Researchers at Hunt.io identified a suspected Chinese-speaking operator exploiting known flaws in ownCloud and a WordPress plugin to steal data from a Philippine nuclear research body and a naval engineering and shipbuilding contractor. The attacker used custom Python scripts to impersonate valid ownCloud users through an authentication bypass and downloaded files via the WebDAV interface without needing account passwords. Stolen material reportedly includes reactor-related records, staff data, encrypted credential stores, and a full archive of the contractor’s WordPress site. Code comments and folder naming in simplified Chinese point to the attacker’s likely origin. Hunt.io | Security Affairs

Nigerian Men Extradited to US Over Sextortion Scheme Tied to Teen Deaths
The Justice Department charged two Nigerian nationals extradited to the United States in connection with a sextortion scheme prosecutors link to the deaths of two teenage victims in Mississippi and North Carolina. The defendants allegedly posed online as young women to trick minors into sending explicit images, then threatened to release the material unless victims paid. The case forms part of a broader federal push against financially motivated sextortion networks targeting minors. BleepingComputer

Direwolf Ransomware Group Claims THQ Nordic Breach, 335GB of Data
The Direwolf ransomware group listed video game publisher THQ Nordic on its extortion leak site, claiming to hold 335GB of data including user and credential information. THQ Nordic, a subsidiary of Embracer Group, hasn’t issued a public statement confirming the scope of the claimed breach. Direwolf, documented since 2025, runs a double-extortion model combining data theft with encryption and threatens publication through a dark web leak site when negotiations fail. TechNadu

Unit 42 Finds Most AI-Linked Malware Never Reaches Production Endpoints
Palo Alto Networks’ Unit 42 analyzed 405 malware samples tied to artificial intelligence, drawn from WildFire reports, VirusTotal Intelligence, and open source research, and found only 12 reached production endpoints or customer networks. The remaining samples stayed confined to research repositories, sandbox environments, and security validation platforms. Existing detection methods, including sandbox detonation and behavior-based analysis, caught every AI-linked sample without needing new tooling, since AI use changes how code gets written rather than how it executes. Unit 42 | SecurityWeek

Seller Claims 877,000 Driver Records From UK EV Salary Sacrifice Broker
A threat actor operating under the name “seraphims” advertised a database allegedly belonging to Love Electric, an Edinburgh-based broker administering electric vehicle salary sacrifice schemes for UK employers, offering 877,000 driver records for $600 in cryptocurrency. Researchers examined a 999-row sample published alongside the listing and found evidence consistent with a genuine production database, though the full record count remains unverified. Love Electric hasn’t confirmed the breach publicly. Security Affairs

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.