CyberSecBrief


Daily Cybersecurity Briefing (27 August 2026)

Published: Loading…

At a Glance

  • CISA confirmed active exploitation of CVE-2026-60004, a critical Gitea code injection flaw, adding it to its KEV catalog.
  • Boston Scientific disclosed a cyberattack causing global operational disruption, limiting order processing and shipment systems since 25 August.
  • The FBI disrupted Chinese state-backed proxy infrastructure, QScan and QTRouter, used to target the Federal Reserve, DOJ and Senate.
  • AnonyMousKIT, an AI-powered phishing platform, used rented voice agents to steal Apple credentials from stolen iPhone owners.
  • NovaCookies, a $320/month AitM phishing service, abused Docusign notifications to steal Microsoft 365 authenticated sessions at scale.
  • CISA reported Iran-linked attackers targeted over 100 internet-exposed water systems via cellular-connected PLCs in July.

Editorial Analysis

Nation-state activity featured prominently today. The FBI dismantled Chinese proxy infrastructure, including QScan and QTRouter, that had been used to target the Federal Reserve, DOJ and Senate, while Group-IB documented an expanded toolset and infrastructure operated by Iranian-linked Tortoiseshell across Europe and the Middle East. Both cases involve infrastructure designed to support persistent access and operations across multiple targets.

Commercial phishing infrastructure also continued to expand through AI and legitimate-service abuse. AnonyMousKIT rents AI voice agents to trick owners of stolen devices into surrendering Apple credentials, while NovaCookies, offered for $320 a month, relays DocuSign notifications to steal Microsoft 365 sessions from hundreds of organisations. The campaigns show how credential-theft operations are increasingly packaged as services that can be used without developing the underlying infrastructure.

Highlights of the Day

Boston Scientific Confirms Cyberattack Disrupted Global Operations

Boston Scientific identified a cybersecurity incident on 25 August 2026 affecting its information technology systems, causing a global operational disruption. The attack limited access to business applications, including systems used to process and ship customer orders. The company activated incident response protocols and engaged third-party experts, though a full restoration timeline remains unknown.

CISA Flags Actively Exploited Gitea Code Injection Flaw

CISA added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities Catalog. The addition follows confirmed evidence of active exploitation in the wild. Under Binding Operational Directive 26-04, federal civilian agencies must prioritise remediation of such flaws on publicly exposed assets.

Source: CISA

AI-Powered Phishing Kit Targets Stolen iPhones for Resale

SOCRadar exposed AnonyMousKIT, a Phishing-as-a-Service platform using AI voice agents to trick stolen iPhone owners into revealing Apple ID credentials. The service, linked to 506 domains and 168 storefronts since 2024, combines email, SMS, WhatsApp and vishing to steal passcodes and 2FA codes. Coding flaws exposed operator logs, revealing over 6,000 phishing attempts and calls costing under $20 total.

Source: SOCRadar

Iranian APT Tortoiseshell Expands Toolset and Infrastructure

Group-IB identified new Tortoiseshell activity, an Iranian-linked group tied to the IRGC, following prior Kaspersky research. Researchers uncovered a reverse SSH tunnelling tool and a new TWOSTROKE backdoor sample, both disguised as a Windows Terminal Server DLL. Infrastructure pivoting revealed dozens of servers with subdomains suggesting expanded targeting across Middle Eastern and European countries.

Source: Group-IB

$320 Phishing Service Steals Microsoft 365 Sessions at Scale

Researchers detailed NovaCookies, a subscription phishing service sold for $320 monthly that relays Microsoft 365 logins in real time to steal session cookies. The service, active since late 2025, expanded sharply from May 2026 and has targeted hundreds of organisations globally. Nearly 90% of identified targets involved lures hosted on .vu domains, with 755 malicious domains catalogued.

Source: Island

Chrome 152 Ships With Fixes for 327 Security Vulnerabilities

Google promoted Chrome 152 to the stable channel, addressing 327 security fixes across Windows, Mac and Linux. The update resolves multiple critical use-after-free flaws, including CVE-2026-79282 in ANGLE and several in Chromecast and Aura components. Researchers earned bounties up to $25,000, with high and medium severity issues also patched across V8, WebRTC and networking components.

Daily Coverage

Developments
Gitea Rce ExploitedBoston Scientific AttackQtfy Infrastructure DisruptedAnonymouskit Phaas
Vulnerabilities
CVE-2026-60004Gitea 1.17 (Critical)CVE-2026-19913Kaltura Html5 Video Player, Html5Lib LibraryCVE-2026-19912Kaltura Html5 Video Player, Html5 LibraryCVE-2026-79282Chrome 152.0.7977.65 (Critical)CVE-2026-8451Adc 14.1 (High)CVE-2026-8452Adc 14.1 (High)CVE-2026-8655Adc 14.1 (High)
Threat Groups
Dark CaracalDark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.