Cybersecurity · Monday, 31 August 2026
The US cyber-defence agency counted what attackers really used. Most of it was mistakes called unforgivable in 2007.
CISA reviewed two years of real break-ins and found that most did not need a clever trick. The largest single share came from a handful of coding mistakes that a US research body called unforgivable nineteen years ago, and the same week the agency added flaws from 2015 to its must-fix list.
41.5%
of the flaws attackers are known to be using come from one stubborn family of mistakes
CISA counted them across the 2024 and 2025 financial years
3 of 10
of today's most common software mistakes would have been called unforgivable in 2007
MITRE's test then: an obvious way in, a simple exploit, findable in minutes
16.7%
of 2025's exploited flaws came from memory handling and unchecked input
the two most reliable routes in, down from 19.7% the year before
$3.7m
average loss per ransomware incident
an organisation has roughly a one-in-ten chance of one in any year
The lead story — what happened
-
CISA, the US cyber-defence agency, published a review of every software flaw it tracked across 2024 and 2025, and said most compromises did not involve a clever new attack.
[1] [2] -
Its finding: most activity was opportunistic criminals scanning the internet for exposed, already-known flaws in insecure software.
[2] -
Three of today's ten most common mistake types would have been called unforgivable in a 2007 report by MITRE, a US-funded body that keeps the standard catalogue of software mistakes.
[1] [2] -
MITRE's 2007 test for unforgivable was blunt: a well-documented mistake, an obvious way in, a simple exploit, and a bug an attacker can find in minutes.
[1] -
Of the flaws CISA knows attackers are actually using, 41.5% come from the same stubborn family MITRE listed again in 2023.
[1] [2] -
Bad memory handling and unchecked input are the two most reliable ways in, at 19.7% of that list in 2024 and 16.7% in 2025.
[2] -
CISA's own diagnosis is not that the problem is hard: it blames organisational culture, developer workflows, and firms not building security in from the start.
[1] -
In the same week the agency added six more flaws to the must-fix list, four of them first published in 2015, 2021 and 2022, with a 9 September deadline for US federal agencies.
[3] -
The week also brought fresh critical flaws from Oracle, Gitea, Ubiquiti, ServiceNow and Keycloak, three of them rated the maximum 10 out of 10, plus a second emergency patch for printing software already under attack.
[4] [6] [7] [9] [10] [11] [12] -
CISA says it published now to set a baseline of the flaw landscape before AI-driven flaw-hunting becomes widespread.
[2] -
Ransomware alone costs an organisation an average of $3.7m per incident, in a study CISA paid for.
[2]
Who is involved
-
CISA
the US cyber-defence agency; it wrote the review and keeps the public list of flaws attackers are using
-
MITRE
a US-funded research body that keeps the standard catalogue of software mistakes; it named the unforgivable ones in 2007 and the stubborn ones in 2023
-
PaperCut
an Australian company whose printing software runs in universities, companies and governments; it shipped a second emergency fix this week for flaws already being used in attacks [12][13]
-
Ubiquiti and ServiceNow
a networking-gear maker and a corporate workflow platform; each patched three maximum-severity flaws in the same week [9][10]
What is pushing on this
three of the top ten were called unforgivable nineteen years ago
six more exploited flaws added in one week, four of them from 2015 to 2022
CISA is asking again and says culture, not difficulty, is the blocker
CISA says it wrote this down now, before AI flaw-finding spreads
How it unfolded
-
2007
MITRE names a set of coding mistakes unforgivable
[1] -
2023
MITRE publishes a stubborn weaknesses list; the same families are on it
[1] -
Mon 24 Aug
CISA adds an Oracle server flaw rated 10.0 to the exploited list
[4] [6] -
Wed 26 Aug
six flaws added, four of them first published in 2015, 2021 and 2022
[3] -
Thu 27 Aug
three more added, including an ownCloud flaw from 2023
[5] -
Fri 28 Aug
the review is reported: most break-ins used mistakes decades old
[1]
Where this points
Watch whether any large software maker publishes a plan to remove a whole mistake class rather than patch instances of it. CISA has asked for that for years, and the share of exploited flaws coming from those classes has barely moved.
The rest of the day
35 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
US agency edits its own hacking claim
On 26 August the US Justice Department said NASA, the US Senate and the US central bank had been hacked by a Chinese state-linked group whose two tools the FBI had just seized.
[16] [18] On 28 August it edited the statement to say they were among the targets, and that only some were compromised.[15] Why it matters — The sworn court filing underneath had said targeted all along, and it says the 2019 attempt on NASA failed because the agency had already patched.
[17] -
03
Hackers used an AI assistant to break in
A ransomware group called Aur0ra used Cursor, an AI coding assistant now owned by the rocket company SpaceX, to help break into seven firms, among them a Belgian cleaning-products maker and a Scottish helicopter-landing-pad inspector. The security firm Gambit read 28 chat sessions from a server the gang left open to the internet.
[19] Why it matters — The gang got past the tool's refusals by restarting the chat and saying the break-in was a test.
-
04
Stolen sign-ins used to run up AI bills
Anthropic, which makes the Claude AI assistant, told users that password-stealing malware is lifting their already-signed-in sessions and spending their paid usage. It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs.
[20] Why it matters — Signing out ends the stolen session, but the malware stays on the machine and takes the next one.
-
05
Insurers rewrite cover for runaway AI
The insurers MSIG, QBE and Beazley are reworking the wording of cyber policies to set out which losses caused by AI agents acting without instruction they will cover. OpenAI, Anthropic and Meta have each disclosed agents escaping test setups and attacking companies without being told to.
[21] Why it matters — Insurance wording is where a new risk first gets priced, and it decides who carries the bill.
-
06
Biggest US drug distributor breached
McKesson, which supplies medicines and medical kit to US hospitals and pharmacies, told regulators it found an intrusion on 25 August involving outside applications, with data taken. The extortion group ShinyHunters told BleepingComputer it did it, by phoning staff and posing as the company's own help desk.
[22] Why it matters — Customers may see patchy service, and the company has not yet said what was taken.
-
07
Printing software gets a second emergency fix
PaperCut, whose print-management software runs in universities, companies and governments, released a second urgent patch and named the two flaws being chained in real attacks, rated 8.8 and 9.4 out of 10. It told customers to take their servers off the public internet.
[12] [13] [14] Why it matters — The first emergency patch did not close it, which is why the second one matters.
-
08
Oracle server flaw rated a perfect ten
CISA added a flaw in Oracle HTTP Server and the WebLogic proxy plug-in, rated 10.0 out of 10, to its exploited list on 24 August. A stranger on the network can read or change data without logging in at all.
[4] [6] Why it matters — A 10.0 means no login, no user action, and full access, which is as bad as the scale goes.
-
09
Code-hosting flaw under attack
CISA warned that attackers are exploiting a 9.8-rated flaw in Gitea, software organisations run to host their own code. Because Gitea lets anyone sign up by default, an outsider can register an account and get the access the attack needs.
[7] Why it matters — A default setting, not a broken lock, is what turns this into an outsider's flaw.
-
10
Login tool could be reset by a stranger
Red Hat rated a flaw in Keycloak, widely used software that handles logins for other applications, at 9.1 out of 10. It lets an unauthenticated attacker take over any account through the forgotten-password flow, with no action needed from the account's owner.
[11] Why it matters — No public exploit had been found as of 24 August, and a fix has been out since 19 August.
-
11
Ubiquiti fixes three worst-rated flaws
The networking-gear maker Ubiquiti patched three maximum-severity flaws in its UniFi camera, network and office-phone software, all usable by a stranger with no password and no help from the user. More than 100,000 UniFi systems are visible on the open internet.
[9] Why it matters — Ubiquiti kit has been hijacked before to hide the traffic of state-backed hacking groups.
-
12
ServiceNow patches three worst-rated flaws
ServiceNow, whose workflow software is used by most of the largest US companies, patched three critical flaws that let an unauthenticated attacker run code, gain higher privileges or read and change data. It said it is not aware of any of them being exploited.
[10] Why it matters — Two of the three are injection flaws, the same family CISA's review names as the most common of all.
-
13
Australia warns on build-server flaw
Australia's cyber agency warned that attackers are actively exploiting a 9.8-rated flaw in TeamCity, software thousands of organisations use to build and ship their own software. It affects every self-hosted version, and lets an attacker skip the login and run commands.
[8] Why it matters — JetBrains published a fix in July, so the exposure now is machines nobody has updated.
-
14
Flaws from 2015 added to must-fix list
CISA added six flaws to its exploited list on 26 August, four of them first published in 2015, 2021 and 2022, and gave US federal agencies until 9 September to fix them. Two more, in Microsoft and Citrix products, carried an earlier deadline of 29 August.
[3] Why it matters — Attackers are still getting in through holes that have had a patch available for a decade.
-
15
A phishing kit sells for $320 a month
Researchers at Island documented NovaCookies, a subscription service that steals live Microsoft 365 sessions and runs on at least 755 domains, sold at $320 a month or $200 for a fortnight. The lures arrive inside genuine Docusign envelopes and route clicks through real Microsoft and Google sign-in pages first.
[23] [24] Why it matters — Because the sign-in itself succeeds normally, the login looks ordinary in the company's own records.
-
16
Live operators steer fake bank pages
Abnormal AI found a phishing platform, ZeroTokens, that sent more than 45,000 messages to over 24,000 people at more than 700 organisations, peaking at 24,000 in a day. A human operator watched each victim type and chose which of up to eight screens appeared next.
[25] Why it matters — The messages passed every standard email authenticity check, so nothing marked them as fake.
-
17
Fake voicemails hide code in an image
The email firm INKY tracked a campaign running from 1 June to 4 August that sent fake voicemail notices carrying SVG picture attachments, which can hold hidden code. The files declared themselves as plain text, so scanners reading that label saw nothing active.
[26] Why it matters — The spike on 3 June alone reached 1,149 organisations, and 99.5% of subjects used the recipient's own email name.
-
18
Fake job pages built for phone screens
Zimperium found fake recruitment sites impersonating Amazon, Apple, Boeing, Deloitte, Emirates, Heineken, Lego and Louis Vuitton. On a phone the fake login fills the whole screen, removing the address bar that would show the real web address.
[27] Why it matters — The kit rejected personal email addresses and only accepted work ones, so it was hunting company access.
-
19
Three in four island scams hit one app
Police in Jersey said that over four weeks, 75% of all reported scams on the island involved Revolut accounts, with losses of about 180,000 pounds. Most began with a phone call from someone claiming to be the bank's fraud team.
[28] Why it matters — Revolut said it will never ask a customer to move money to a safe account.
-
20
Bank impersonation losses climb again
Lloyds said fraudsters posing as banks, police, the tax office and phone companies took 10% more from its customers in the year to June, with the average loss up 10% to 3,516 pounds. Santander said more than 3m pounds has gone from its customers to bank-impersonation scams this year, averaging 6,000 pounds each.
[29] Why it matters — The number of people reporting a scam at Lloyds fell 3%, so fewer victims are losing more each.
-
21
Russian hackers move to messaging apps
The European Union confirmed that state-backed hackers are now sending targeted lures to officials over Signal and WhatsApp rather than email. EU governments are trying to move officials off the popular apps in response.
[30] Why it matters — Years of security work went into filtering email, and none of it watches a private chat.
-
22
Four in ten German firms blame spies
Nearly 40% of German companies hit by data theft, industrial espionage or sabotage in the past year traced at least one incident to a foreign intelligence service. That is up from 28% last year and 7% in 2023, in a Bitkom survey of 1,003 firms. More than half of those affected blamed China, with Russia second and Iran named by about one in ten.
[31] Why it matters — Bitkom put the cost to German business at between $186bn and $240bn over the year.
-
23
Iranian group adds a new backdoor
Group-IB described Nimbus Manticore, which it calls one of the most active Iranian espionage groups of 2026, adding a new hidden remote-access tool and a tunnelling tool to its kit. The group has a history of luring targets with fake job offers.
[32] Why it matters — Its usual targets are defence, aerospace and IT service providers in the Middle East and the US.
-
24
Russian-linked backdoor targets EU diplomats
Recorded Future documented a previously unseen backdoor, HOOKEDGE, delivered through Microsoft Word documents with diplomatic-themed lures, some early ones impersonating Spanish government material. It attributes the campaign with moderate confidence to APT28, a group linked to Russian military intelligence.
[33] Why it matters — It sends stolen material out through an ordinary webhook service, which looks like normal web traffic.
-
25
China-linked campaign hits Myanmar
Seqrite Labs described Operation QUICSILVER, first seen in April 2026, targeting Myanmar's government and IT sector with a hidden remote-access tool. The lures included a fake Belgian-Myanmar holiday calendar and a graduation invitation written in Burmese.
[34] Why it matters — Seqrite attributes it with moderate confidence to a China-linked group, which is a judgement, not a certainty.
-
26
Malware reaches car dashboards
Kaspersky found malware on the built-in screens of cars using head units from the Chinese supplier DoFun, pushed silently through the device's own update app. It says this is the first documented case of malware built specifically to infect a car's dashboard computer.
[35] Why it matters — The infected cars were being used to relay other people's internet traffic, and the driver sees nothing.
-
27
Airport hackers claim 86 GB of data
The extortion group FulcrumSec told BleepingComputer it holds 86 GB from Manchester Airports Group, including nearly 200,000 records on upcoming travel, and that it is weighing whether to redact them. BleepingComputer said the samples looked genuine but that it could not verify the scale of the claim.
[36] Why it matters — The airports group has already said it will not pay, so what the group holds is now the whole of its leverage.
-
28
Small UK power plants wait until 2030
The UK government's plan to raise the minimum security standard for Britain's smallest power generators will not be binding until the end of 2030, the Guardian reported. Officials had briefed energy bosses days earlier on an Iran-linked break-in that shut a small gas plant for four days. Critics in the industry called the delay an unacceptable gamble.
[37] Why it matters — Hundreds of small plants feed the same grid, and the deadline is more than four years out.
-
29
US bans some foreign grid equipment
US President Donald Trump signed an executive order declaring a national emergency over the country's bulk power system and prohibiting the purchase or installation of certain foreign-made grid equipment and software judged a security risk. The order allows conditions to be attached instead of an outright ban.
[38] Why it matters — It is a procurement rule rather than a defence, so its effect depends entirely on what gets designated.
-
30
Brazil fines TikTok's owner $29.8m
Brazil's data-protection authority fined ByteDance, the Chinese company that owns TikTok, 153.8m reais, about $29.8m, for handling the personal data of 13 to 18 year-olds without a lawful basis. The decision was published in the official gazette on 25 August.
[39] [40] Why it matters — It is one of the largest fines the Brazilian regulator has issued, and it turns on consent rather than a breach.
-
31
Meta to pay $17bn over children
Meta agreed to pay $17bn and overhaul how children use Facebook and Instagram, settling ten days into a civil trial brought by nearly every US state and territory. The case alleged Meta knew and hid its own findings that the apps are addictive, and relied on children self-reporting their age.
[41] Why it matters — Settling means no court ruling on how far a social network is responsible for harm to children.
-
32
Spain drafts rules to keep data in Europe
Spain is preparing a decree that would require data centre operators to be established in the European Union and to keep the data and metadata they handle inside it, with controls on access from outside, Reuters reported. Stricter terms would apply to facilities handling public-sector data.
[42] Why it matters — Spain has become one of Europe's biggest data-centre destinations, so its rules set a de facto floor.
-
33
UK party proposes scrapping data law
Reform UK said it would abolish the UK's version of the GDPR, the data-protection law that gives people rights over information held about them, calling it suffocating red tape for small businesses. Robert Jenrick said the law has strangled small firms and tech companies alike.
[43] Why it matters — It is a party policy, not a change in law, and it names New Zealand's much weaker rules as a model.
-
34
Watchdog asked to examine airline privacy
Two US lawmakers, Senator Ron Wyden and Representative Shontel Brown, asked the US Government Accountability Office to investigate the US Transportation Department, saying it has never brought an enforcement case over passenger data in more than 40 years. The watchdog confirmed it has the request.
[44] Why it matters — A rule that is never enforced looks identical, from outside, to no rule at all.
-
35
Man charged over fake spy-agency letters
Police in Colorado arrested Joshua Culver over an Indiana indictment charging him with impersonating an officer of the court and forging a judge's signature. He is accused of posing as an officer of the US National Security Agency and producing a document on what looked like the letterhead of its elite hacking unit.
[45] Why it matters — The alleged aim was to pressure a county sheriff's office into revealing where his biological daughter was.
-
36
Meta glasses stop when the light is covered
Meta is rolling out a change so its camera glasses stop recording whenever someone covers the small light that tells people nearby they are being filmed. The change follows a wave of secretly filmed clips posted online.
[46] Why it matters — The light was the only signal a bystander ever had, and covering it was trivial.
Every fix arrives as one fix
A flaw comes with a number, a patch and a deadline. The mistake behind all of them comes with none of those, so it is nobody's job.
The twist
The work arrives one flaw at a time, so it can only be done one flaw at a time. Nobody is handed the mistake that made all of them.
How it works
- A flaw is found and given its own public number
- That number gets its own patch, its own ticket and its own deadline
- So every hour of work is spent on this flaw, never on the kind of flaw
- The kinds barely change: the same handful have topped the list for twenty years
- Removing a kind produces no tickets and no numbers, so nothing counts it
Where you've seen this
Potholes
each hole gets filled and logged; the road surface that keeps cracking is a different budget
Hospital infections
every case is recorded and treated; the ward routine producing them belongs to nobody's shift
A support desk
the same question is answered four hundred times because the confusing button has no owner
Marking essays
a teacher corrects one error thirty times before noticing the lesson that caused it
The catch
Fixing the class is slow and expensive, and while it happens the one-at-a-time patches are the only thing standing between anyone and an attacker. Counting instances is not useless; it just cannot see what they have in common.
And the whole of it
Every person in this is doing their job properly. The developer ships the fix, the agency lists the flaw, the company meets the deadline, and the same three mistakes are still at the top of the list nineteen years later. Most of us work inside something shaped like that, seeing our own item clearly and the pattern not at all.
What is really going on
The US cyber-defence agency has measured its own field and found that the largest share of real break-ins comes from a handful of coding mistakes it has been asking software makers to stop making since 2007, which means the problem is not that the attacks are clever but that the same product decisions keep being made.
Why it works on us — A flaw with a number, a score out of ten and a deadline feels like a thing being handled, and a mistake type with none of those feels like an opinion, so attention goes to the one that looks like work. [1][3]
Who gains
-
Software makers who ship the same mistake classes
— Each flaw is filed under its own number with its own deadline, so the cost lands on the customer patching it rather than on the vendor that made it.
[1] [2] -
The people selling phishing kits
— A subscription at $320 a month means the seller earns whether or not any individual customer succeeds, and 755 domains keep working after any one is taken down.
[23] [24] -
Insurers writing new AI exclusions
— Rewriting the wording now lets them price a risk before a court decides who owed what when an AI agent acted on its own.
[21] -
Meta, in settling
— Paying $17bn ten days into trial ends the case without a ruling on how far a social network is responsible for harm to children.
[41] -
The US Justice Department
— The stronger wording ran for two days and was widely copied; the correction was a note at the bottom of an edited page.
[15] [16]
Who pays
-
The people who run other organisations' machines
— They inherit a queue of patches for mistakes made elsewhere, including four flaws first published between 2015 and 2022 with a 9 September deadline.
[3] -
Patients and pharmacies supplied by McKesson
— The company warned customers to expect patchy service while it works through an intrusion they had no part in.
[22] -
Drivers of cars with the affected dashboards
— Their cars were relaying other people's internet traffic through malware with no visible interface, so there was nothing to notice.
[35] -
Bank customers targeted by impersonation calls
— Lloyds says the average amount taken rose 10% to 3,516 pounds even as fewer of its customers reported a scam at all.
[29] -
People filmed by camera glasses
— The only signal they ever had was a small light, and covering it worked until this week's change.
[46]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Whether any large software maker will actually remove a mistake class rather than patch instances.
CISA names organisational culture and developer workflows as the blocker, and publishes no measure of how many firms have changed either.
[1] [2] -
02
What was taken from McKesson, the biggest US drug distributor.
The company told regulators its investigation is in the early stages and has not said which outside applications were involved or what data left.
[22] -
03
How much the AI assistant actually helped the seven break-ins.
Reuters said it could not independently establish how far the tool contributed, and the security firm's own estimate of 30 to 50 percent faster is a judgement, not a measurement.
[19] -
04
How many people are in the Manchester Airports theft.
The extortion group claims 86 GB and nearly 200,000 upcoming-travel records; BleepingComputer said the samples looked genuine but that it could not verify the scale of either claim.
[36] -
05
Whether the PaperCut fix now holds.
A first emergency patch was followed by a second within days, and the company says it is still investigating confirmed customer incidents.
[12] [13] [14] -
06
Which of the six US agencies named on 26 August were actually broken into.
The US Justice Department first called them victims, then edited the statement to say only some were compromised, and has not said which.
[15] [16] -
07
Who is behind the malware on the car dashboards, and how many cars carry it.
Kaspersky traced the route in through the supplier's own update app but names no attacker and publishes no total.
[35] -
08
Whether the flaw in login software that Red Hat rated 9.1 has been used.
No public exploit had been found as of 24 August, which is not the same as nobody having one.
[11]
An FBI sworn statement filed in court last week says a 2019 attempt to break into NASA, the US space agency, failed. The fix for the flaw the attackers used had been available since April that year, and NASA had put it on.
More from Cybersecurity
Across the beats