Skip to main content
news

Berlin Ransomware Theft, Eastlink Data Breach, Dark Web Exposure – Cybersecurity News [August 31, 2026]

Brad Slavin
Brad Slavin General Manager

Quick Answer

Cybersecurity news this week includes the Berlin ransomware theft, Eastlink data breach, 153 million driver’s license scans exposed, actively exploited SonicWall flaws, Chrome zero-days, malicious browser extensions, and new Lazarus and Russian-linked campaigns.

cybersecurity news update

It’s been an unusually heavy week in cybersecurity. A ransomware gang is blackmailing Berlin’s city government over a multi-terabyte data theft, while a U.S. federal law enforcement agency and one of the UK’s largest airport operators were both hit by separate extortion groups. A medical device giant was knocked offline by a disruptive cyberattack, and a Canadian telecom warned tens of thousands of customers about a breach. Elsewhere, researchers exposed a massive dark web marketplace selling over 150 million stolen driver’s license scans, a state-linked espionage campaign resurfaced, and attackers wasted no time weaponizing several newly disclosed software flaws - from school print servers to network switches to browser extensions.

Email security starts with SPF, DKIM, and DMARC, helping organisations reduce domain impersonation and protect users from phishing attempts.

Berlin city government blackmailed after 5.79 TB ransomware theft

The Rhysida ransomware gang has claimed responsibility for breaching Berlin’s city administration systems, saying it exfiltrated 5.79 terabytes of data including tens of thousands of contracts, emails, and passwords. The intrusion was first discovered in early August, though officials still haven’t confirmed the full scope of what was taken.

The attackers are reportedly demanding roughly 30 bitcoin, worth around $2.5 million, in exchange for not leaking the stolen files. City officials have not said whether they intend to pay.Kaseya

Hosted Email Server 2025

Eastlink, a telecommunications provider in Canada, is notifying roughly 75,000 customers that their account information may have been exposed after unauthorized access was detected in late August. Names, contact details, account numbers, and PINs were among the data potentially affected, though the company says banking details were not accessed.

Eastlink shut down the affected platforms on its website and app as a precaution while it investigates further. CBC

153 million driver’s license scans surface on new dark web marketplace

A dark web platform called Nexus advertised more than 153 million U.S. and Canadian driver’s license scans for sale, alongside millions of other ID cards, travel documents, and medical cards. Journalist Brian Krebs verified the data was genuine after the sellers used his own license as a free sample - and even showed him a scan of U.S. Defense Secretary Pete Hegseth’s license.

The stolen images appear to trace back to IDScan.net, a Louisiana-based identity verification company used by major brands, and the FBI has opened an investigation. Nexus has since shut itself down, though the data is presumably still circulating elsewhere. CybernewsEngadget Malwarebytes

Critical SonicWall SMA1000 flaws under active exploitation

SonicWall confirmed that two critical vulnerabilities in its SMA1000 remote access appliances are being actively exploited, and both have been added to CISA’s Known Exploited Vulnerabilities catalog. The flaws can be chained together to achieve unauthenticated remote code execution on affected devices. Rapid7

Because exploitation began before the issues were publicly disclosed, SonicWall is warning organizations not to assume they’re safe just because they’ve patched-appliances should be checked for signs of prior compromise as well. Rapid7

N-able N-central zero-day exploited despite earlier hotfixes

Security firm Huntress discovered a new exploit chain in N-able’s N-central remote monitoring platform after a fully patched customer environment was compromised. The flaw is distinct from an earlier critical vulnerability N-able patched in August, and it allows attackers to bypass access controls and create unauthorized administrator accounts.

Smtp Service 2021

On-premises customers are being urged to apply the latest hotfix immediately, since hosted versions of the platform have already been secured by the vendor. Huntress

Cisco patches critical flaws in Nexus switches and IOS XR software

Cisco disclosed a critical, maximum-severity-adjacent flaw (CVSS 9.8) in Nexus 9000 switches built on its Silicon One chips, which can let an unauthenticated attacker execute code with root privileges the kind of hardware increasingly used to power AI data centers. Cisco said it isn’t aware of any malicious exploitation as of the September 2 disclosure. The Hacker News

The same day, Cisco also released a hardening update for IOS XR software bundling seven vulnerabilities, two of which are also rated 9.8, affecting all releases regardless of configuration. The Hacker News

Google patches Chrome’s sixth actively exploited zero-day of 2026

Google shipped an emergency Chrome update fixing a high-severity flaw in the browser’s V8 JavaScript engine that was already being exploited in the wild. The bug, a type confusion issue, could let an attacker run arbitrary code inside Chrome’s sandbox via a specially crafted webpage. The Hacker News

This marks the sixth Chrome zero-day patched so far in 2026, underscoring how frequently browsers remain a top target for attackers. Users are advised to update immediately and restart their browsers. The Hacker News

”Superior” campaign hijacks 19 browser extensions to steal crypto and passwords

Researchers uncovered a campaign dubbed Superior involving 19 malicious Chrome and Edge extensions capable of stealing cryptocurrency, saved passwords, browser sessions, and form data. The operator reportedly built 14 of the extensions from scratch and took over five previously legitimate ones, pushing malicious updates to unsuspecting users. GridinSoft, LLC

Sendgrid Alternative 2023

One hijacked extension alone had roughly 70,000 users at the time of its malicious update, highlighting how browser extensions remain an underappreciated attack surface for both consumers and enterprises. GridinSoft

New BraZetsu malware framework fuels underground access marketplace

Researchers detailed a sophisticated Python-based Windows malware framework called BraZetsu that’s being used to power a marketplace for compromised computer access. Unlike typical infostealers built for one-off credential theft, BraZetsu functions as a comprehensive toolkit that helps initial access brokers turn hacked systems into sellable commercial assets. The Hacker News

The framework’s emergence points to a maturing criminal economy, where gaining a foothold on a machine is increasingly treated as a product to be resold rather than a means to a single attack. The Hacker News

Lazarus Group used a Windows zero-day in latest Operation Dream Job wave

North Korea’s Lazarus Group has been observed using a new wave of its long-running Operation Dream Job recruitment-lure campaign, this time weaponizing a previously unknown Windows kernel driver flaw. The zero-day was used to gain system-level privileges and deploy a new version of the FudModule rootkit, designed specifically to blind endpoint security tools. Substack

Spf Validator 4560

The campaign continues Lazarus’s pattern of posing as recruiters to trick targets - often in the crypto and tech sectors -into opening malicious files disguised as job assignments.CyberWarrior76

Russian-linked “LAUNDRY BEAR” espionage campaign targets webmail accounts

A joint government advisory detailed an ongoing Russian-linked campaign, tracked by different vendors as LAUNDRY BEAR, Void Blizzard, and TA488, that’s been targeting webmail accounts since at least mid-2025. More than twenty government agencies co-signed the advisory, which assesses the activity is almost certainly intelligence collection carried out on behalf of the Russian Federation. Substack

Separately, Microsoft flagged a related but distinct campaign it’s calling CaptiveCrunch, linked to a sub-cluster of the well-known APT29 (Midnight Blizzard) group, which uses fake captive Wi-Fi portals to redirect and compromise targets. CyberWarrior76

Brad Slavin
Brad Slavin

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.