Cyber Security Brief — 2026-08-28
Today's brief: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable (The Hacker News) — Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability,…
- PaperCut releases second emergency patch for exploited flaws (BleepingComputer) — PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to by…
- GiveWP WordPress donation plugin flaw lets hackers execute server commands (BleepingComputer) — A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication (The Hacker News) — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional ha…
- 68-year-old imprisoned after making $1.3 million by pirating IPTV services (BleepingComputer) — A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three yea…
Newly published, high-severity CVEs
- CVE-2026-69658 (CVSS 9.8, CRITICAL) — MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.
- CVE-2026-71187 (CVSS 9.8, CRITICAL) — The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative ac…
- CVE-2026-73125 (CVSS 9.8, CRITICAL) — Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration inform…
- CVE-2026-75337 (CVSS 9.8, CRITICAL) — The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 3 Security Score scans across our customers in the past 7 days.
- medium: 4
- info: 19
- high: 7
- low: 9
Most common issues:
- Cross-origin stylesheet loaded without Subresource Integrity (seen 6x)
- DKIM not detected at common selectors (seen 3x)
- No DMARC record (seen 3x)
- DNSSEC not detected (seen 3x)
- Missing recommended headers (1) (seen 2x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan