Threat Brief — 2026-08-31 — Zero-days published, vishing evolves
Multiple zero-day exploits and proof-of-concept code surfaced today, including a Kaspersky Endpoint Security flaw with a working GitHub exploit and three new NightmareEclipse PoCs targeting Avast and NVIDIA. A coordinated voice-phishing campaign abusing Microsoft Teams is actively targeting enterprise domain controllers. Ransomware actors confirmed data theft from Berlin's city administration, while ShinyHunters claims 284 million medical records stolen from McKesson with a $55.2 million ransom demand.
Top items
- Kaspersky Endpoint Security 0-day published on GitHub — A published exploit demonstrates that an unprivileged user can write files to the System32 directory via a flaw in Kaspersky Endpoint Security. The exploit is publicly available on GitHub, lowering the barrier to local privilege escalation on affected systems. No patch timeline has been stated. (src: SecurityLab)
- NightmareEclipse releases three PoCs targeting Avast and NVIDIA — Following the Kaspersky 0-day publication, the same actor released three additional proof-of-concept exploits targeting Avast and NVIDIA software, raising questions for vendors about unaddressed local privilege escalation paths. This expands the actor's target set beyond Windows and Kaspersky products. (src: SecurityLab)
- Spring Ring voice-phishing campaign abuses Microsoft Teams for domain controller access — Unit 42 detailed a campaign that combines Microsoft Teams abuse with voice phishing to deploy malware and ultimately target enterprise domain controllers. The campaign demonstrates how trusted collaboration platforms can be leveraged as an initial access vector. (src: Unit 42)
- ShinyHunters claims 284 million medical records from McKesson, $55.2M ransom — ShinyHunters claims to have stolen 1 TB of data from pharmaceutical giant McKesson, which has confirmed intrusion into its systems. The ransom demand is $55.2 million. First reported 2026-08-28; McKesson has now confirmed the breach. (src: SecurityLab)
- Berlin confirms data theft after Rhysida ransomware attack — Berlin's city administration confirmed that attackers stole data after Rhysida listed the city on its leak site. The city is facing extortion attempts. First reported 2026-08-28; confirmation of data theft is a new development. (src: BleepingComputer)
- Poisoned llms.txt files force AI agents to run third-party code — Researchers found that llms.txt and llms-full.txt files on 120 sites contained links to unregistered packages and domains. AI agents including Claude, OpenAI Codex, and Hermes treat instructions in these files as trusted documentation, creating a supply-chain attack vector against agentic AI workflows. (src: Xakep)
- Fake CAPTCHA pages prompt users to run PowerShell backdoor — Attackers are using convincing Cloudflare-branded CAPTCHA pages that instruct victims to open PowerShell and paste commands, resulting in backdoor installation. This is a social engineering pattern that bypasses traditional email-based phishing controls. (src: SecurityLab)
- Cronos network halted after Tectonic protocol hack drains lending protocol — Validators halted the Cronos blockchain after an attacker artificially inflated the TONIC token price to drain the Tectonic lending protocol. The incident highlights persistent price-manipulation vulnerabilities in DeFi lending architectures. (src: Xakep)
- Rain crypto card vulnerability leads to $1.1M theft on Solana — A vulnerability in a legacy contract in the Rain crypto card payment infrastructure allowed an attacker to steal approximately $1.1 million across several Solana programs, with neobank Avici losing over $500,000 and its token dropping 49%. (src: Xakep)
Themes
AI-agent attack surface is expanding rapidly. Poisoned llms.txt files tricking AI agents into executing untrusted code, AI safety refusals being weaponised to hide malicious code (UAC-0099), and AI services abused as exploit-development testbeds all point to a growing set of vectors specific to agentic AI workflows. Organisations deploying AI coding or automation agents should treat agent-readable documentation as untrusted input.
Ransomware data-theft confirmation cycle accelerates. Both Berlin (Rhysida) and McKesson (ShinyHunters) moved from initial breach claims to confirmed data theft within days, with extortion demands in the tens of millions. The pattern reflects actors prioritising data exfiltration over encryption for leverage.
Local privilege escalation PoCs are flooding public channels. NightmareEclipse has now published exploits targeting Kaspersky, Avast, and NVIDIA products in quick succession. Endpoint security and graphics driver software are both high-value targets for LPE, and public PoC availability shortens the window for exploitation before patches ship.
