☀️ Good morning. Here's everything that happened in cybersecurity yesterday, in under 5 minutes.
Saturday was a day about disclosure rather than exploitation. CISA added a three-year-old ownCloud flaw to its Known Exploited Vulnerabilities catalog only after a Chinese-speaking actor used it to take nuclear records from a Philippine research body; Cosmos Labs confirmed that a balance-handling flaw in its shared EVM module drained roughly $5.72 million from six blockchains, after a quiet patch tipped off attackers before downstream chains had updated; the ATF confirmed a cyberattack on a system holding information about its investigation targets, with the Qilin ransomware group claiming it and the agency declining to verify that; Berlin's state government said it will not pay its extortionists and disclosed in the same breath that forensics had found new data outflows; and Wordfence and Patchstack dropped five critical WordPress plugin and theme flaws, one of them a CVSS 9.8 authentication bypass. In four of those five, the bug was known before the damage was.
🔥 Top Stories
01 — CISA Adds ownCloud Flaw CVE-2023-49105 to KEV After Philippine Nuclear Records Theft
Vulnerabilities & Patching
CISA added CVE-2023-49105, a critical authentication bypass in ownCloud rated CVSS 9.8, to its Known Exploited Vulnerabilities catalog after reports that a Chinese-speaking threat actor used it to steal nuclear records from a research body in the Philippines. The flaw was disclosed in 2023 and patched then. What changed is not the vulnerability, it is the confirmation that someone is using it against high-value targets.
If you run ownCloud, verify the patch level rather than assuming a three-year-old advisory was handled by whoever ran the environment then. Federal agencies now have a KEV remediation clock, but the more useful signal for everyone else is what got hit: a research institution, not a bank. Legacy file-sync deployments in universities, labs and agencies are where unpatched 2023 flaws survive, because nobody currently owns them.
02 — Cosmos EVM Flaw Drained Six Blockchains After a Silent Patch Tipped Off Attackers
Cryptocurrency
Cosmos Labs confirmed that a critical balance-handling flaw in the shared Cosmos EVM module, tracked as GHSA-7g4w-cg88-2cq2, was exploited to drain roughly $5.72 million from six blockchains between August 20 and 25, 2026. The advisory carries no CVE identifier, no weakness classification and no CVSS score. The fix shipped quietly first, which gave attackers a diff to study while downstream chains had not yet updated.
This is the silent-patch failure mode in its purest form. A shared module means every chain that imports it inherits the bug, and a patch without an advisory means none of them know to hurry. If you operate anything built on a shared upstream module, the operational lesson is that your patch clock starts when the commit lands publicly, not when the advisory is published, because that is when the attacker's clock starts.
03 — ATF Confirms Qilin-Claimed Breach Hit System Holding Investigation Targets
Data Breaches
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack against a system holding information on its investigation targets. The Qilin ransomware group claimed responsibility, though the ATF has not verified that attribution. The agency says the incident was limited to a standalone system and has not affected critical operations, and it is investigating alongside the Department of Justice.
Read the containment claim carefully. "Standalone system" is a statement about network architecture, not about the sensitivity of what was on it, and a database of investigation targets is about as sensitive as federal law enforcement data gets. Early containment statements are made with incomplete forensics and they are the claims most likely to be revised, which is exactly what happened in Berlin over the same weekend.
04 — Berlin Refuses to Pay Extortionists as State-Network Breach Widens
Ransomware
Berlin's state government confirmed it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the demands. In the same statement, officials disclosed that continuing forensic work had identified further data outflows, specifically in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment.
The refusal is the defensible call: a government that pays cannot credibly promise the data stays private anyway. The second half of the statement is the operationally important part, and it points the other direction. Scope is still expanding weeks after the initial compromise. If you are a contractor, supplier or partner agency downstream of Berlin's administrative network, do not treat the original scoping statement as final, and check whether your data sat in the mobility and transport portfolio.
05 — Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Vulnerabilities & Patching
Wordfence and Patchstack disclosed critical flaws in five widely used WordPress components: WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. The most severe is CVE-2026-76581, an authentication bypass rated CVSS 9.8. Across the set, the reported outcomes are authentication bypass, account takeover and arbitrary code execution, which on a WordPress install means full site control rather than a contained bug.
Update all five today if you run them, and treat this as a fleet problem rather than a site problem. Avada and TranslatePress in particular ship on large numbers of agency-built and client-managed sites, which are exactly the installs where nobody is on call over a weekend. If you manage sites for other people, inventory first and patch second, because the version you think is deployed is often not the version that is running.
📊 By The Numbers
$5.72 million — drained from six blockchains through the Cosmos EVM balance-handling flaw between August 20 and 25, 2026.
Zero CVE identifiers — assigned to that Cosmos flaw, which shipped as GHSA-7g4w-cg88-2cq2 with no weakness classification and no CVSS score.
CVE-2023-49105 — a 2023 ownCloud flaw, rated CVSS 9.8, newly added to CISA's KEV catalog after a Chinese-speaking actor used it against a Philippine nuclear research body.
CVSS 9.8 — the score on CVE-2026-76581, the WPMU DEV Dashboard authentication bypass and the most severe of Saturday's five WordPress disclosures.
5 WordPress components — WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP, all with critical flaws disclosed the same day.
⚡ The Signal
Nothing that happened Saturday required a novel exploit. The ownCloud flaw was disclosed and patched in 2023. The Cosmos EVM bug had a fix committed before it was ever announced. The WordPress issues were reported by two research firms who do this every week. In each case the vulnerability was known, and what failed was the communication around it.
The Cosmos case is the sharpest version. A shared module, a quiet commit, no CVE, no weakness class, no severity score, and roughly $5.72 million gone across six chains that were all running the same inherited bug. The patch itself became the attack instructions, because a public fix on an unannounced flaw is a free diff for anyone watching the repository. That is not an exotic technique. It is the predictable outcome of shipping a fix ahead of an advisory, and it happens because disclosure feels like it increases risk when it is actually the only thing that lets downstream operators move at the same speed as the attacker.
The ownCloud story is the same problem on a longer timeline. A flaw sits patched-but-unpatched-everywhere for three years, invisible in the priority stack, until a nuclear research body loses records and it earns a KEV listing. KEV is a good mechanism, but it is a lagging one. By construction, a vulnerability qualifies after someone has already been hit with it. If your patch prioritization runs entirely off KEV, you are choosing to be in the second cohort every time.
Berlin and the ATF round out the pattern from the institutional side, and they make an instructive pair. Both had to say something over the weekend about a breach they did not fully understand yet. Berlin took a firm position on the extortion and admitted openly that the scope was still growing. The ATF offered a containment claim, "limited to a standalone system," while declining to verify who did it. One of those statements can survive new forensics and one cannot. Watch which one gets revised.
🔍 What You May Have Missed
All four of yesterday's CyberSignal articles are in the Top Stories above, so these are from the wire.
Microsoft Details TerminalFix, a ClickFix Campaign That Opens a Reverse Tunnel — Fake CAPTCHA prompt, then DLL sideloading, then a reverse tunnel for persistent access. Microsoft published detection and hunting guidance. The entire chain starts with a person pasting a command they were told to paste.
Hasbro Data Breach Exposed Employee Personal Information — The toy company confirmed that the attack that disrupted operations earlier this year also exposed employee data. HR and payroll systems routinely fall outside the first pass of incident response, which is why these disclosures land months late.
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign — Over 26,000 malicious messages reached 5,527 organizations using SVG attachments disguised as voicemail notifications. Too many gateways still treat SVG as an image rather than as executable markup.
📅 What to Watch
The Cybersecurity Apocalypse Is Coming in 'Months,' AI Giants Warn — WIRED's roundup pairs the industry warning with reporting that hackers targeted more than 100 US water systems. Watch whether the water-sector activity draws a CISA advisory this week.
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations — Aurora ransomware operators are using an AI coding agent for reconnaissance and exploitation. This is the near-term version of the AI-enabled attack everyone is forecasting, and it is already in production.
Perturbation Probing Shows LLM Safety Refusal Lives in a Thin Layer — Unit 42 research indicates model refusal behavior is shallower than assumed, strengthening the case for external guardrails over model-internal safety. Relevant to anyone pointing agents at production systems.
Android 17 Adds OS-Wide Encrypted Client Hello — ECH hides which sites a device visits from network operators. Expect friction with enterprise network monitoring and DNS-based filtering as the rollout reaches managed fleets.
Stay sharp. Stay ahead.
Till next time,
The CyberSignal Team

