HomeWeekly DigestsThis Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Aug 17 to Aug 24, 2026

Weekly threat intelligence digest from 370 items (48 critical, 260 high).

August 24, 2026 370 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST August 17 – August 24, 2026 This week the data underscores a single, accelerating reality: attackers are no longer chasing the perimeter, they are hijacking the trusted bridges that connect your ecosystem. From the Medusa ransomware gang leveraging stolen Azure Entra ID credentials to breach over 500 critical‑infrastructure firms, to the Clop ransomware exploit of CVE‑2026‑12569 in PTC Windchill that stole design data from GE and Philips, privileged third‑party access is the common denominator. Even state‑linked actors disabled a UK power plant while simultaneous water‑utility attacks in the U.S. demonstrated how a single supply‑chain foothold can cascade into physical disruption. 👉 Access, not vulnerability, is the primary risk driver. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain breach → MSPs, SaaS admin consoles, and CI/CD pipelines (GitLab, Azure AD) were the most frequent entry points, amplifying reach across dozens of downstream customers. * Privilege determines impact → A compromised cloud admin account exposed 1.7 M employee records across multiple Fortune 500 firms; a single ransomware affiliate used Safe Mode to bypass EDR and encrypt critical files on an undisclosed organization. * Blind‑spot assets → OT/IoT devices, third‑party plugins, and mis‑configured cloud services remain largely invisible to traditional audit inventories, leaving organizations exposed to prolonged undetected exploitation. 🔍 WHAT CHANGED THIS WEEK * Credential‑theft attacks surged, with >30 % of incidents originating from stolen Azure or Entra ID accounts, highlighting the need for stronger MFA and credential‑use monitoring. * Exploitable misconfigurations re‑emerged as a high‑impact vector: Azure tenant mis‑configurations, WordPress “StopAndProtect” network, and SAP Commerce Cloud auth‑bypass each led to data exfiltration of millions of records. * Zero‑day exploits against core platform components (Windows IKE, MLflow SSRF, ShieldBreak in Microsoft Defender) entered active exploitation faster than patch cycles, pressuring organizations to adopt real‑time vulnerability telemetry. * Fourth‑party exposure became evident when U.S. Bancorp’s incident was traced to a contractor breach, reinforcing the need to extend vendor‑risk programs beyond the immediate supplier tier. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * Azure Entra ID or other cloud identity platforms – stolen admin credentials fueled multiple high‑profile breaches. * SaaS and API providers (GitLab, Meta AI agents, OpenAI plugins) – recent CVEs and supply‑chain attacks target integration points. * OT and industrial networking stacks – TSN protocol flaws and Siemens PLC targeting show critical‑infrastructure is now in the attacker’s playbook. #Compliance #SOC2 #AuditReadiness #Cybersecurity #ThreatIntel #ContinuousCompliance #LiveThreat #VerisqAI

Articles Referenced in This Digest 370 items

Advisory (56)

HighProduct showcase: AI Paper Trail shows the privacy cost of talking to AI
HighTwitch wants your content for Amazon AI training. Here’s how to opt out
HighIs Cyber missing the Marque?
HighNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs
HighHackers Actively Target Siemens PLCs With AI Cyberattacks
HighOpenAI confirms ChatGPT is down as logins and signups fail
HighSideloading on Android: What it is, why it’s risky, and how to do it more safely
HighOpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
HighNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
HighUS warns of AI-powered attacks on Siemens PLCs in critical infrastructure
HighOpenAI puts major frontier AI training run on hold over cyber risks
HighDefending Against an Active Threat to Siemens S7 Series PLCs
HighOracle Critical Patch Update, August 2026 Security Update Review
HighCISA Adds Four Known Exploited Vulnerabilities to Catalog
HighMicrosoft confirms outage affecting search in Microsoft 365 apps
HighApple Patches iOS and macOS, (Mon, Aug 17th)
HighUS FCC Weighs Chinese Transceiver Supply-Chain Crackdown
HighUnleashing Hackers to Be the US Government's Bounty Hunters
HighMicrosoft confirms GitHub is down worldwide
HighGoogle Workspace lets Gemini access your company data by default - how to shut it down
HighApple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
MediumWindows 11 24H2 Home and Pro Support Ends Oct. 13: What Users Should Do
MediumOpenAI Adds Controls That Should've Been There Already
MediumOWASP Flags Top AI Skill Risks in New Security Blueprint
MediumMicrosoft blames Windows gaming issues on RGB lighting devices
MediumNew CUSTODY Framework Constrains AI Agents Inside the Network
MediumManaging the cyber risk of agentic AI
MediumNIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity
MediumF5 enhances AI Gateway to control AI costs, access, and security
MediumDoD Regulatory Pause: No Excuse to Weaken Supply Chain Trust
MediumMicrosoft fixes known issue causing Windows Defender crashes
MediumCISA Weighs Outsourcing Its Cyber Software Buying
MediumComcast turns your Xfinity WiFi into a home motion detector
MediumGoogle’s $10,000 refund test shows why AI agents need zero trust
MediumMicrosoft starts removing WMIC tool used by cybercriminals
MediumWindows Server 2022 reaches end of mainstream support in 60 days
MediumFrance’s Top Court Blocks Under-15 Social Media Ban
MediumAI-enriched Linux 7.2 delivers cache-aware scheduling - here's everything new
InformationalAWS makes it easier to spot firewall rules that have gone quiet
InformationalWelcoming the Sri Lankan Government to Have I Been Pwned
InformationalHardware Makers Implement Post-Quantum Cryptography as Security Threats Near
InformationalGoogle Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait
LowICE Warns Employees Against Meta Smart Glasses
InformationalWalmart will finally accept Apple Pay and Google Pay. Here's what's changing
InformationalWazuh and AI For Enhanced SOC Workflows
LowMicrosoft rolls out Classic Outlook theme for New Outlook users
InformationalWindows 11 Hotpatching Explained: How Much Does It Really Reduce Reboots?
LowGoogle will let you tailor your Discover feed using natural language now
InformationalOpenAI previews privacy-focused system for detecting AI misuse
InformationalAWS limits AI agents’ data access, even when manipulated
InformationalAndroid 17 QPR2 Beta 3: Google Adds Customization and New Scam Defenses
InformationalThe Cluster That Came Back: Disaster Recovery for High Speed Discovery
InformationalBrinqa acquires PlexTrac to bring validated remediation to exposure management
LowMicrosoft tests faster Windows File Explorer, new context menu
InformationalIAM Compliance Requirements and Best Practices
InformationalStronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity

Breach (66)

CriticalUK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
HighNIUS - 6,090 breached accounts
HighWeek in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
HighTikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
HighHackers infect Android car head units with proxy botnet malware
HighGolf Canada - 568,972 breached accounts
HighMedical records, SSNs, and bank details exposed in CareCloud data breach
HighCanada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
HighU.S. Bank says breach claims related to fourth-party incident
HighSickKids data breach exposes employee and job applicant info
HighWhat We Missed: Delta Flight Disrupted With Wi-Fi Hack
HighThe Elephants in the Technology Room - Part 5
HighDetailed Timeline of OpenAI’s Cyberattack on Hugging Face
HighHackers poison arrayref Rust crate to push infostealer malware
High9 million images of people’s faces exposed by reverse lookup service
HighUS charges 17 Iranian hackers over 31-terabyte academic data theft
HighFake Gemini installer delivers Vidar infostealer via Google Colab lure
HighWhy "Shady AI" is Security's Next Big Governance Problem
HighCryptohack Roundup: Harmony's Post-Exploit Blockchain Rollback
HighUS Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign
HighUS DOJ Charges 17 Iranians in Decade-Long Hacking Campaign
HighEHR Vendor Notifying 3.8 Million Patients of Data Theft Hack
HighInside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras
HighUS charges Iranians for sprawling hacking campaign on government agencies, universities
HighLatvian officials resign after cyberattack exposes data on 1.2 million people
HighElectronic health record company CareCloud says 3.7 million people affected by breach
HighUS charges Iranian hackers over $3.4 billion intellectual property theft
HighSakura Internet hack exposes data of up to 1.36 million accounts
HighPrison for data analyst who tried to extort $2.5 million from his employer
HighCyberattack forces UT San Antonio to delay start of fall semester
HighHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
HighA Baffling Case of Inept Iranian Strikes on Water Utilities
High50,000 Stripe Secrets Leaked in Public Code
HighFanlore - 144,520 breached accounts
HighOz Hair and Beauty - 1,988,331 breached accounts
HighHackers Expose Data of 1.2 Million Heights Finance Customers
HighHackers target Ukrainian agency managing assets seized from sanctioned Russians
HighUniversity of Texas forced to take systems offline in San Antonio after cyberattack
HighBerlin cuts two state ministries off government network after security breach
HighClop created custom web shell for Windchill data theft attacks
HighHeights Finance data breach: What customers need to know
HighBe careful what you put in “anyone with the link” Google Docs
HighHacker claims millions of records stolen from corporate Azure tenants
HighOpenAI tightens defenses after AI agents breach research environment
HighSafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
HighOne Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
HighClop Claims Data Theft From More Than 40 Companies
HighOpenAI President Urges Enterprises to Deploy AI Agents
HighLiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
HighSafePal Says 39,798 Customers Hit by Data Breach
HighPoland probes MyDr healthcare software breach potentially affecting 19 million people
HighIrregular faces criticism over ‘spin’ in AI hacking postmortem
HighSafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
HighNearly 750k had financial info, SSNs leaked in South Carolina loan company breach
HighPokémon Center data breach exposes customer info, cancels some orders
HighHacker claims 3.6 million Azure account records stolen from major companies
HighNearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack
HighPolice bust cybercrime ring accused of stealing €30 million in four-day spree
HighSafePal breach affects 39,798 customers, data allegedly for sale
HighFrance’s tax authority admits hackers made off with data on 678,000 individuals
HighAzure Breach Campaign Claims McDonald's, Vodafone as Victims
HighAkira Ransomware Uses Safe Mode to Bypass EDR
HighMcDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
HighFrench tax authority data breach affects 678,000 individuals
HighPhilips and GE investigating Clop ransomware data theft claims
MediumRussian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers

Ransomware (6)

CriticalCISA: Medusa ransomware hit over 500 critical infrastructure orgs
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
HighMedusa ransomware gang has hit over 500 organizations, CISA warns
HighRansom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
HighMore than 200 victims of Medusa ransomware identified over the last year, CISA says
HighUkrainian software developer faces 12 years in Swiss ransomware trial

ThreatIntel (157)

CriticalCritical RCE flaw in Windows IKE Extension now actively exploited
HighRansomware attackers are zeroing in on mid-market companies
HighFake bank websites play dead to evade security scanners
HighZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
HighToxicPanda Android malware uses VPN permissions to block Google Play
HighHow an Emerging Industrial Protocol Family Could Put OT at Risk
HighMalware Hijacks Android Car Head Units
HighToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
HighNamed Pipes Under Attack: Securing Windows Interprocess Communication
HighConnecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
High14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
HighLawmakers call for investigation into impact of CISA staffing cuts
HighISMG Editors: AI-Assisted Cyberattacks Gain Speed and Scale
HighThat Legitimate OAuth Login Might Be a Russian Hack
HighMore Incidents of AIs Going Rogue in Cybersecurity Challenges
HighAI Is Learning to Write Genetic Code
HighFake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
HighChatGPT's new Mac plugin analyzed my iMessages - and I found it surprisingly useful
HighThe invisible passenger in your car
HighAttackers impersonate popular AI brands to spread malware
HighAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
HighMicrosoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
HighHackers abuse FTP server banners to deliver new Windows malware
HighHundreds of leaked AWS keys give full control over corporate accounts
HighNew SynkLoader malware pushed in Microsoft Teams phishing campaign
HighYou Can't Test What You Don't Know You Own
HighQuantum Masterclass: Cryptography's Enterprise Blind Spot
HighEven MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)
HighA $25 template helped scammers build hundreds of phantom bank domains
HighThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
HighSuspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
HighChina’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
HighWhy Healthcare AI Vendor Risk Demands Stronger Oversight
HighBreach Roundup: Grandoreiro Returns
HighChatGPT for Teens tackles risky chats and homework shortcuts
HighManic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
HighIdentity Abuse Through Trusted Communication Channels
HighPolice Are Hiding Their Use of Flock Surveillance Cameras
HighHow MSPs can catch phishing attacks email filters miss
HighUsing Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
HighAgentic AI Presents New Insider Threat Model for Orgs
High'Grandoreiro' Malware Resurfaces With Mexico Campaign
HighPakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
HighUS agencies warn of AI-powered attacks on Siemens industrial controllers
High40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
HighToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
HighManic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
HighCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
HighNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
HighAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
HighSenators press TikTok over withholding of safety features for some users
HighUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
HighUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
HighStopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
HighNew Manic Android malware can exfiltrate data through nearby devices
High41 deceptive download sites show a real link, then send you somewhere else
HighThe 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
HighNo-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
High8,539 reasons to rethink how vulnerabilities get patched
HighResearchers find a loophole that lets expired credit cards make unauthorized payments
HighAI is making fraud harder to spot and identity harder to prove
HighICE Collecting DNA Samples
HighPassword spraying attacks surge 155x as hackers exploit MFA gaps
HighHackers compromise 14,500 Dahua web cameras in 35-day campaign
HighHealthtech firm CareCloud data breach impacts 3.7 million patients
HighRogue ransomware affiliate poses as recovery firm to steal payments
HighScammers are using fake crypto AML checkers to drain your wallet
HighSimple Scans for Cloud Metadata Service, (Wed, Aug 19th)
HighSilkParasite Threatens Central Asian Orgs With Flurry of RATs
HighYour Comcast router doubles as a motion detector now - and a potential police informant
HighClop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
HighMicrosoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
HighStopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
HighPhishing 3.0: The Fight Moves to Agent Versus Agent
HighSilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
HighMicrosoft Tracks MacSync Stealer by Its Behavior, Not Its Domains
HighWindows 11 24H2 Home and Pro reach end of support in 2 months
High'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
HighChina-Linked Hacker Shows AI Capabilities in APAC Attack
HighChatGPT’s new feature could give infostealers a map of your Mac activity
HighBanks look for fraud signals in customer behavior
HighPerplexity Builds Guardrails to Rein in Rogue AI Agents
HighChina-Linked APT Uses AI to Optimize Hand-Built Malware
HighIdentity Is the New Perimeter, AI Is Blowing It Wide Open
HighApple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss
HighProject noRecognition: Teaching AI to Fool Surveillance Cameras
HighLLMs and Contextual Integrity
HighYour Controls Block Known Attacks. What About the Behavior?
HighHunting MacSync Stealer infrastructure through behavioral pivots
HighSilent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
High'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
HighCopyCop Targets AI Investment in Armenia
HighPurpleDelta's Fraudulent Employment Operations
HighGoogle's AI can see your business data by default in Workspace - unless you disable it
HighDownload: 2026 Credential Risk Report
HighNETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation
High16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
HighTWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
HighAI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
HighFBI Pegasus Records Expose a Blind Spot in US Spyware Oversight
HighNew Mirai-Based Evooo1Bot Botnet Targets Linux Devices
HighWeekly Update 517: Cyber Ransoms
HighAdam Shostack Talks Hugging Face & PHANTOM-B
High'Turf War' Between Claude Agents Leads to Self-Replicating Malware
HighVideo Call Exploit Chains Two Flaws in Unisoc Modems
HighA hollowed out data layer is making CISOs fly blind into AI attacks
HighCavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
HighHow AI Builders Will Get Hacked
HighHacking Public Wi-Fi DNS to Steal Credentials
HighWhy Facebook’s war on ad blockers could help scammers
HighFake TikTok rewards promise cash you’ll never get
HighCompromising the Developer: How Modern Dependency Culture Reshaped the Supply Chain Threat Landscape
HighApple Mac Malware Lets Attackers Control Browser Sessions After Infection
HighApple Screen Sharing Security, (Mon, Aug 17th)
HighAn “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
HighLinux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
HighFortinet expands AI security portfolio with Virtue AI acquisition
HighNorth Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
HighWindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
HighAmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
HighNew PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
HighThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
HighChina-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
HighTrump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
HighCTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
HighChrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
HighMustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
HighHackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
HighEvooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
HighHow MCP Servers Can Expose Enterprise Secrets
HighPhonescams: Casting a Wide Net in an Orchard of Low-Hanging Fruit
HighInvisible AI Prompts Trigger Court Sanctions
MediumAmazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off
MediumChina joins Europe in scrapping Windows for Linux
MediumHow AWS Marketplace is using AI agents to meet the rising demand for AI agents
MediumWho Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
MediumNearly half of enterprises have no one leading PQC migration
MediumDefeating AI-Assisted Reverse Engineering (or at Least Trying To)
MediumThe best and worst AI for your privacy, ranked - and how each handles your data
MediumApple's smart home springs a leak - here's everything we expect to see in September
MediumMicrosoft says August Windows updates may cause gaming issues
MediumSmashing Security podcast #481: Never say this to a robot dog
MediumYour polite reply to that text is worth $2 on the dark web 
MediumIntezer adds native response automation without separate SOAR
MediumUS Courts To Begin Publishing Spyware Records From 2029
MediumStolen Authority
InformationalMandiant Opens Agentic Security Harness to Industry
InformationalThe best small tablets of 2026: Expert tested and reviewed
InformationalUsing Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)
InformationalCorero brings cloud-based AI threat analysis to SmartWall ONE
InformationalISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th)
InformationalOpenAI Pauses Frontier Model Training for Safety Review
InformationalDescribing attacks with crime script analysis
InformationalISC Stormcast For Wednesday, August 19th, 2026 https://isc.sans.edu/podcastdetail/10058, (Wed, Aug 19th)
InformationalHow to avoid Claude watermarking your content
InformationalISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)
InformationalGoogle’s open-source HEIR lets AI work with data it can’t see

Vulnerability (85)

CriticalSecurity Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION
CriticalGitLab Warns of Active Exploitation of Critical GraphQL Flaw
CriticalU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
CriticalCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution
CriticalU.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
CriticalPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CriticalSix Maximum-Severity Flaws Found in Cisco Products
CriticalCitrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
CriticalMicrosoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
CriticalGitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
CriticalCisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
CriticalMicrosoft warns of max severity Entra ID flaw exploited in attacks
CriticalCISA orders feds to patch actively exploited TrueConf Server flaws
CriticalCritical Elementor Pro bug exposes WordPress sites to RCE attacks
CriticalNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
CriticalCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
CriticalIsolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
CriticalCVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CriticalU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
CriticalCISA warns of hackers exploiting critical MLflow vulnerability
CriticalElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
CriticalUpdate Chrome now: Two critical vulnerabilities fixed
CriticalMultiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution
CriticalGoogle’s AI security agents found 100+ critical software vulnerabilities in just two days
CriticalCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CriticalU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
CriticalCritical GitLab Zero-Click Flaw Poses Mitigation Challenges
CriticalAttackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Critical[remote] PCMan 2.0.7 - Buffer Overflow
CriticalCritical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
CriticalCISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
CriticalU.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
CriticalGitLab Patches Critical Unauthenticated GraphQL Vulnerability
CriticalForminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
CriticalCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Critical[remote] D-Link DNS_340L - OS Command Injection
Critical[remote] ipTIME A3004T - Remote Code Execution
CriticalA week in security (August 10 – August 16)
CriticalUpdate your Mac: Screen Sharing vulnerability exploited in the wild
CriticalGeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
CriticalApple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
CriticalSAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
CriticalSuspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
CriticalUnisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
CriticalMicrosoft Faces Fresh Nightmare Eclipse Zero-Day
HighZombie Card: An expired Visa credit card can be used for purchases
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighYour Shredded Visa Card May Still Work at the Checkout
HighMLflow Flaw Opens a Path to Cloud Credentials Theft
HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighResearchers Social-Engineered Copilot Into Exposing Flaw
HighCitrix urges admins to patch new NetScaler flaws as soon as possible
HighN-able Bug Exposes Password Vault Master Keys
HighZombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
HighAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
HighCloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighApple fixes another image-processing flaw that could allow code execution
HighMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
High[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
High[webapps] Nodemailer 9.0.0 - File Read/ SSRF
High[webapps] flyto-core 2.26.7 - Arbitrary File Write
High[dos] NanaZip 6.5 - DoS
HighCISA Malcolm
HighSiemens Simcenter Nastran
HighApple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it
HighCVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
HighCISA: Windows Task Host flaw now exploited by ransomware gangs
HighSnowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
High[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
High[webapps] Joomla JCE_2.9.15 - Remote Code Execution
High[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
High[dos] Nmap 7.99 - Extension Header Integer Underflow
High[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
High[webapps] webpack_devserver 5.2.5 - CSRF
High[webapps] Probo 0.222.2 - IDOR
High[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
High[dos] NanaZip 6.5 - DoS
HighCertighost and the Privilege Hiding in Your Certificate Authority
HighShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
HighAttackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
High⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
HighCISA Adds One Known Exploited Vulnerability to Catalog 
HighMicrosoft working on Defender patch for ShieldBreak zero-day
MediumJohnson Controls Simplex Incident Manager

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests