Cybersecurity Daily Briefings

Critical vulnerabilities, active threats, and security news — curated for professionals.

Updated every workday at 08:00 CET
24 Aug 2026
Cybersecurity Daily Briefing — 2026-08-24
6 CVEs 2 threats 2 news items
Critical Vulnerabilities 6
CVE-2026-35273 CVSS 10.0 Oracle PeopleSoft Enterprise PeopleTools

Missing authentication vulnerability in PeopleTools enabling unauthenticated remote attackers to execute critical administrative functions. Actively exploited in the wild.

Source
CVE-2026-15409 CVSS 9.8 SonicWall SMA1000 Appliances

Server-Side Request Forgery (SSRF) flaw permitting unauthenticated threat actors to access internal endpoints and trigger unauthorized remote execution.

Source
CVE-2026-0257 CVSS 9.8 Palo Alto Networks PAN-OS

Authentication bypass in the PAN-OS management interface enabling remote unauthenticated attackers to acquire administrative privileges.

Source
CVE-2026-41089 CVSS 9.8 Microsoft Windows Netlogon

Wormable Remote Code Execution flaw in the Netlogon protocol, with threat actors attempting lateral movement across domain controllers.

Source
CVE-2025-53521 CVSS 9.8 F5 BIG-IP / BIG-IQ

Critical Remote Code Execution flaw in F5 management interfaces reclassified from Denial of Service to full unauthenticated RCE risk.

Source
CVE-2026-41940 CVSS 9.1 WebPros cPanel & WHM

Missing authentication vulnerability allowing unauthenticated remote attackers to bypass access controls and compromise hosting environments.

Source
Malware & Threats 2
Windows Task Host Weaponization Ransomware Loader Targets: Enterprise Windows Environments

Ransomware syndicates are actively leveraging Windows Task Host privilege escalation vulnerabilities to deploy secondary encryptor payloads.

Source
Entra ID Token Abuse Operations Credential Theft & Session Hijacking Targets: Microsoft Entra ID / Cloud Tenants

Threat actors are targeting cloud authentication flaws to steal session tokens and bypass multi-factor conditional access policies.

Source
Security News 2
CISA Adds Critical Enterprise Flaws to Known Exploited Vulnerabilities Catalog

CISA has updated its KEV catalog with actively exploited zero-day and critical flaws spanning SonicWall, Oracle PeopleSoft, Palo Alto Networks, and cPanel/WHM.

Read more
Ransomware Threat Groups Accelerate Weaponization Timelines for Disclosed CVEs

Security researchers observe threat groups compressing exploit deployment windows to within 72 hours of public disclosure, prioritizing edge network devices and perimeter gateways.

Read more
21 Aug 2026
Cybersecurity Daily Briefing — 2026-08-21
4 CVEs 2 threats 3 news items
Critical Vulnerabilities 4
CVE-2026-52813 CVSS 10.0 Gogs Self-Hosted Git Service

Critical path traversal vulnerability via organization names allowing arbitrary file write and Git hook overwrites, leading to complete unauthenticated Remote Code Execution (RCE).

Source
CVE-2026-33696 CVSS 9.4 n8n Workflow Automation

Critical prototype pollution flaw in XML and GSuiteAdmin nodes that allows authenticated workflow creators to achieve full remote code execution under the n8n process user.

Source
CVE-2024-55591 CVSS 9.8 Fortinet FortiOS & FortiProxy

Authentication bypass vulnerability in the administrative web interface actively weaponized in recent critical infrastructure attacks by Gunra ransomware operators.

Source
CVE-2025-24472 CVSS 9.8 Fortinet / Enterprise Edge Appliances

Critical remote code execution and administrative bypass flaw actively exploited in chained attacks against global enterprise edge devices.

Source
Malware & Threats 2
Gunra Ransomware Campaign Ransomware / Extortion Targets: Healthcare, financial services, government facilities, and critical infrastructure globally

Multi-stage ransomware operation actively exploiting perimeter network flaws (including Fortinet FortiOS/FortiProxy) to breach networks, exfiltrate data, and deploy ransomware.

Source
Crates.io Build-Time Rust Backdoor Supply Chain / Trojan Targets: Rust developer environments & build systems (245M+ crate downloads)

Compromised maintainer account injected malicious typosquatted build scripts into popular Rust crates (arrayref, internment, append-only-vec) to execute remote code during project compilation.

Source
Security News 3
Massive Rust Supply Chain Incident Hits High-Download Crates.io Packages

The Rust Project rapidly purged poisoned releases of popular crates (arrayref, internment, append-only-vec) after compromised accounts injected build-script payloads executing remote code upon compilation.

Read more
CISA & NSA Warn of AI-Generated Exploit Scripts Targeting Critical PLCs

U.S. and international intelligence agencies issued an active threat advisory regarding threat actors using AI-generated exploit scripts targeting Siemens S7 and industrial programmable logic controllers.

Read more
Russian Threat Actors Exploit Legitimate Google OAuth and WhatsApp Flows

Cyber espionage groups (UNC6293, UNC7005, UNC5976) are abusing legitimate authentication flows and QR-code device linking to hijack accounts across defense, government, and think tanks.

Read more
20 Aug 2026
Cybersecurity Daily Briefing — 2026-08-20
4 CVEs 1 threat 2 news items
Critical Vulnerabilities 4
CVE-2026-59310 CVSS 9.8 VMware vCenter Server (Syslog Service)

Critical directory traversal flaw leading to unauthenticated RCE. Actively exploited in the wild to establish reverse SSH backdoors and deploy Babuk ransomware.

Source
CVE-2026-63077 CVSS 9.8 JetBrains TeamCity

Critical unauthenticated RCE in CI/CD build environments. Listed on CISA KEV with active exploitation observed across enterprise targets.

Source
CVE-2026-68820 CVSS 9.5 Microsoft Windows / Defender

Zero-day privilege escalation vulnerability ('ShieldBreak') bypassing prior RoguePlanet protections. Listed on CISA KEV.

Source
CVE-2025-53521 CVSS 9.8 F5 BIG-IP

Critical unauthenticated remote code execution (RCE) flaw allowing full appliance compromise across perimeter network appliances.

Source
Malware & Threats 1
Reverse-SSH / Babuk Ransomware Campaign Backdoor / Ransomware Targets: VMware vCenter enterprise infrastructure

Threat actors are actively leveraging CVE-2026-59310 to install persistent reverse SSH tunnels, followed by the deployment of Babuk-derived ransomware.

Source
Security News 2
Active Exploitation of VMware vCenter RCE for Ransomware Deployment

Threat actors are actively weaponizing CVE-2026-59310 to compromise VMware vCenter instances, dropping reverse SSH implants and Babuk-variant ransomware.

Read more
CISA Urges Rapid Patching of Windows Zero-Day and TeamCity Flaws

CISA has updated its Known Exploited Vulnerabilities catalog with actively targeted flaws in Microsoft Windows Defender and JetBrains TeamCity.

Read more
19 Aug 2026
Daily Cybersecurity Briefing — 2026-08-19
3 CVEs 1 threat 2 news items
Critical Vulnerabilities 3
CVE-2026-63077 CVSS 9.8 JetBrains TeamCity

Critical unauthenticated RCE. Added to CISA KEV Aug 5, 2026; attackers actively targeting build servers. Patch immediately.

Source
CVE-2026-59310 CVSS 9.8 VMware vCenter Server (Syslog Server)

RCE actively exploited to deploy a reverse SSH tool for persistence and remote access.

Source
CVE-2026-68820 CVSS 9.5 Microsoft Windows / Defender

Zero-day; public PoC (ShieldBreak) claims Microsoft failed to fully patch prior RoguePlanet flaw CVE-2026-50656. Added to CISA KEV; federal agencies required to patch by Aug 25, 2026.

Source
Malware & Threats 1
Reverse-SSH backdoor (CVE-2026-59310) backdoor Targets: VMware vCenter servers

Active exploitation of VMware vCenter RCE to deploy reverse-SSH backdoors for persistence and remote access.

Source
Security News 2
Microsoft August 2026 Patch Tuesday — 400 flaws fixed

400 flaws fixed, including 1 actively exploited and 2 publicly disclosed zero-days.

Read more
ShieldBreak PoC released claiming Defender patch bypass

Public PoC (ShieldBreak) released claiming Microsoft failed to fully patch CVE-2026-50656; tested on Windows 11 25H2 and Server 2025.

Read more
18 Aug 2026
Daily Cybersecurity Briefing — 2026-08-18
4 CVEs 3 threats 3 news items
Critical Vulnerabilities 4
CVE-2026-58231 CVSS 10.0 SAP Commerce Cloud

Maximum-severity flaw (insufficient authorization checks/input validation) allowing unauthenticated attackers to abuse a default authentication client and execute crafted requests. Actively exploited in the wild within days of the patch.

Source
CVE-2026-59310 CVSS 9.8 VMware vCenter Server

Directory-traversal vulnerability in vCenter Server enabling arbitrary code execution. Patched July 29, 2026 but now exploited by a suspected China-nexus APT to drop Babuk-derived ransomware on exposed instances.

Source
CVE-2026-74872 CVSS 9.8 openssl_encrypt (<1.4.0)

Arbitrary code execution in the Whirlpool hash implementation: it loads native .so modules using broad glob patterns and no integrity verification, allowing attackers to plant malicious libraries in site-packages for native code execution.

Source
CVE-2026-15748 CVSS 9.8 WordPress Forminator Forms (<=1.56.1)

Arbitrary file upload via handle_file_upload; insufficient file-type validation lets unauthenticated attackers bypass the dangerous-extension blocklist and upload malicious PHP leading to RCE. Actively exploited.

Source
Malware & Threats 3
Evooo1Bot botnet Targets: Internet-facing edge/IoT devices, global

New Mirai-derived Linux botnet that turns exposed devices into SOCKS5 proxies. Reuses Mirai DDoS engine and adds encrypted C2, SSH brute-force scanner, SOCKS relay, and credential sniffer; exploits known router/VPN flaws.

Source
Cavern C2 rat Targets: Global enterprises

Command-and-control framework that blends into legitimate traffic using DNS tunneling and Google Apps Script, evading network detection.

Source
China-nexus APT (Babuk-derived ransomware) apt Targets: VMware vCenter-exposed orgs

Suspected China-nexus actor exploits CVE-2026-59310 in vCenter to deploy Babuk-derived ransomware on internet-exposed instances.

Source
Security News 3
SAP Commerce Cloud flaw exploited days after patch

CVE-2026-58231 (CVSS 10.0) is under active exploitation; unauthenticated attackers abuse a default auth client. Patch immediately.

Read more
Snowflake GitHub Actions workflow injection

Wiz disclosed a GhA workflow injection in snowflakedb/snowflake-connector-net where crafted issues could expose internal Jira credentials to executed commands.

Read more
MCP servers can leak enterprise secrets

Research shows how misconfigured Model Context Protocol servers expose internal secrets to AI agents — a growing enterprise supply-chain risk.

Read more
17 Aug 2026
Daily Cybersecurity Briefing — August 17, 2026
3 CVEs 3 threats 3 news items
Critical Vulnerabilities 3
CVE-2026-68820 CVSS 7.0 Microsoft Windows (Ancillary Function Driver for WinSock / afd.sys)

Use-after-free in the Windows AFD for WinSock lets an authenticated local attacker elevate privileges to SYSTEM. Actively exploited in the wild as a zero-day; Lazarus Group deployed the 'Troy' backdoor against defense and aerospace firms using it. Patch immediately.

Source
CVE-2026-55040 CVSS 9.1 Microsoft Office SharePoint Server

Weak authentication (CWE-1390) allows an unauthenticated remote attacker to bypass a security feature over the network and potentially gain control of sensitive enterprise data. Reported under active exploitation; apply Patch Tuesday update.

Source
CVE-2026-62878 CVSS 9.8 Microsoft Windows DNS Server

Wormable remote code execution flaw in Windows DNS Server with a CVSS score of 9.8. No authentication required to exploit; highest priority patching due to wormable, network-propagation potential.

Source
Malware & Threats 3
WindRelay (paired with SpyNote RAT) infostealer Targets: Android users / banks (global)

New NFC relay malware family. Captures live payment card data via NFC and relays it in real time to attackers, enabling contactless payment fraud combined with social engineering and remote device control via the SpyNote RAT.

Source
Lazarus Group (APT) apt Targets: Defense & aerospace firms

North Korean APT used the CVE-2026-68820 WinSock zero-day to gain SYSTEM access and deploy the 'Troy' backdoor against defense and aerospace organizations.

Source
Clop ransomware Targets: Global enterprises (double extortion)

Active exfiltration-based double-extortion campaigns; recently hit victims with large data thefts (e.g. 424GB) and used supply-chain/Clop-style mass exploitation, targeting file-transfer platforms.

Source
Security News 3
Microsoft August 2026 Patch Tuesday fixes ~400-421 CVEs incl. 3 zero-days

Massive monthly update addressing the exploited WinSock zero-day CVE-2026-68820, two publicly disclosed zero-days, a wormable DNS Server bug and ~60 critical flaws. Prioritize patching internet-facing servers.

Read more
Lazarus exploits Windows zero-day to deploy 'Troy' against defense sector

Researchers linked the CVE-2026-68820 in-the-wild exploitation to Lazarus, which chain-escalates to SYSTEM to install the Troy backdoor on defense and aerospace targets.

Read more
New 'WindRelay' Android malware enables live NFC payment fraud

Group-IB uncovers an NFC relay malware combined with the SpyNote RAT that lets criminals use victims' bank cards in real time for contactless purchases and cash-out.

Read more
14 Aug 2026
Daily Cybersecurity Briefing — 2026-08-14
3 CVEs 1 threat 3 news items
Critical Vulnerabilities 3
CVE-2026-58231 CVSS 10.0 SAP Commerce Cloud (Data Hub Adapter)

Unauthenticated attacker abuses a default authentication client and submits crafted input lacking validation, enabling arbitrary code execution and compromise of internal components. Patch via SAP Note 3771065.

Source
CVE-2026-55040 CVSS 9.1 Microsoft SharePoint Server

Weak-authentication security-feature bypass (CWE-1390). Unauthenticated attacker can impersonate administrators. Actively exploited in the wild within days of Rapid7 publishing a public PoC.

Source
CVE-2026-15409 CVSS 10.0 SonicWall SMA1000 Series

Server-Side Request Forgery (SSRF). Exploited as a zero-day, often chained with CVE-2026-15410 (code injection) by INC ransomware actors. Patches and IOCs available; urgent patching recommended.

Source
Malware & Threats 1
INC Ransomware ransomware Targets: Global: US, Australia, UAE, Colombia, Switzerland

Now the most active group exploiting SonicWall SMA1000 zero-days (CVE-2026-15409/15410), chaining the flaws to steal credentials and TOTP seeds and reach internal networks.

Source
Security News 3
Microsoft August 2026 Patch Tuesday fixes 400 flaws

Updates cover roughly 400 vulnerabilities, including one actively exploited and two publicly disclosed zero-days.

Read more
SAP August 2026 Patch Day: CVSS 10.0 RCE fixes

SAP released 28 security notes, including fixes for CVE-2026-58231 (CVSS 10.0) and other code-injection RCE flaws in Commerce Cloud and NetWeaver.

Read more
China's CAC opens review of Palo Alto Networks products

China's Cyberspace Administration said the review is to ensure safe operation of critical information infrastructure and prevent cybersecurity risks.

Read more
13 Aug 2026
Daily Cybersecurity Briefing — 2026-08-13
3 CVEs 2 threats 3 news items
Critical Vulnerabilities 3
CVE-2026-68820 CVSS 7.8 Microsoft Windows AFD.sys (Ancillary Function Driver for WinSock)

Use-after-free elevation-of-privilege flaw in Windows AFD.sys, actively exploited in the wild. A locally authenticated attacker can trigger a race condition for kernel-level access and SYSTEM privileges. Patched in August 2026 Patch Tuesday.

Source
CVE-2026-56162 CVSS 10.0 Microsoft Azure SQL Database

Improper authentication allows an unauthorized attacker to elevate privileges over the network without user interaction, with high impact to confidentiality, integrity and availability. Fully mitigated by Microsoft; no user action required.

Source
CVE-2026-20303 CVSS 9.9 Cisco Catalyst SD-WAN / IOS XE Software

Critical flaw in Cisco Catalyst SD-WAN and IOS XE discovered during internal security hardening review; allows security-control bypass and unauthorized access. One of five CVEs rated Critical 9.9. Patch immediately.

Source
Malware & Threats 2
StormEncryptor ransomware Targets: Global / enterprise networks

New C++ ransomware (appends .encrypted) deployed by China-linked actor Storm-1175, a former Medusa affiliate, since Aug 2 2026. Likely gained access via N-able N-central auth-bypass CVE-2026-18577.

Source
INC Ransomware ransomware Targets: US, Australia, UAE, Colombia, Switzerland

Now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims across multiple regions.

Source
Security News 3
Microsoft August 2026 Patch Tuesday fixes 421 flaws, incl. one actively exploited zero-day

62 of 421 vulnerabilities are marked critical. CVE-2026-68820 (Windows AFD.sys LPE) is confirmed exploited in the wild; two zero-days were publicly disclosed.

Read more
Cisco patches 12 SD-WAN and IOS XE flaws, including three rated 9.9 CVSS

Critical vulnerabilities found via internal review can bypass security controls and enable unauthorized access; immediate patching advised.

Read more
New StormEncryptor ransomware deployed by former Medusa affiliate Storm-1175

Microsoft Threat Intelligence tracks first activity since April 2026, marking a shift from Medusa to the new C++ ransomware family.

Read more
12 Aug 2026
Daily Cybersecurity Briefing — 2026-08-12
4 CVEs 3 threats 4 news items
Critical Vulnerabilities 4
CVE-2026-68820 CVSS 7.0 Microsoft Windows (afd.sys, Ancillary Function Driver for WinSock)

Use-after-free in the Windows kernel networking driver. Actively exploited zero-day (per Microsoft and Check Point, tied to Lazarus Operation Dream Job). Lets an attacker with code execution escalate to SYSTEM via a race condition.

Source
CVE-2026-62878 CVSS 9.8 Microsoft Windows DNS Server

Stack-based buffer overflow reachable remotely with no authentication and no user interaction. ZDI characterizes it as wormable; unauthenticated RCE on exposed DNS servers.

Source
CVE-2026-62815 CVSS 9.8 Microsoft QUIC

Unauthenticated remote code execution in Microsoft's implementation of the QUIC transport protocol; no user interaction required.

Source
CVE-2026-63520 CVSS 8.8 Microsoft SharePoint Server (on-premises)

Code-execution half of a SharePoint exploit chain that, combined with the CVE-2026-55040 auth bypass (9.1, patched July), reaches unauthenticated RCE. Both fixes required.

Source
Malware & Threats 3
Gunra ransomware Targets: Global critical infrastructure; health, finance, government, non-profit (mostly Australia, East Asia, Europe)

Conti-derived RaaS. Gained initial access via Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS/FortiProxy (CVE-2025-24472). Double extortion; 51 victims since April 2025. Warnings from CISA and South Korean agencies.

Source
DeadLock ransomware Targets: Global

Uses Polygon blockchain smart contracts, Session messaging and decentralized infra (per Microsoft Threat Intelligence) to harden extortion and data-leak operations against disruption.

Source
Kimwolf v7 (AISURU) botnet Targets: Global; Android + IoT

Android/IoT DDoS botnet now disguises HTTP/2 DDoS traffic as legitimate browsing. Discovered by Palo Alto Unit 42.

Source
Security News 4
Microsoft Patch Tuesday: 398 CVEs, 62 Critical, one zero-day exploited

CVE-2026-68820 (Windows afd.sys, CVSS 7.0) is the only flaw flagged as actively exploited (linked to Lazarus Operation Dream Job). Four unauthenticated 9.8 RCEs hit Windows DNS, Deployment Services, QUIC and HPC Pack. SharePoint chain closed with CVE-2026-63520.

Read more
Hackers breach Polish power plant via private cellular network

Attackers shut a turbine after gaining access to a Polish power plant's OT controls through a private cellular network, underscoring ICS/cellular attack surface risks.

Read more
OpenAI launches GPT-5.6-Cyber with reduced safeguards for exploit development

New cyber-specialized model ships with fewer safeguards, raising questions around AI-assisted malware and exploit generation.

Read more
Mozilla revokes Firefox & Thunderbird Linux signing key

Signing key was inadvertently exposed in a private repository; certificates revoked as a precaution.

Read more
11 Aug 2026
Daily Cybersecurity Briefing — August 11, 2026
3 CVEs 1 threat 3 news items
Critical Vulnerabilities 3
CVE-2026-15409 CVSS 10.0 SonicWall SMA1000

Maximum-severity server-side request forgery (SSRF) in SMA1000 VPN appliances. Exploitation traced back to June 22, 2026, three weeks before a patch existed. Pre-auth access opens unauthenticated WebSocket tunnels, escalating to root. Actively exploited by INC ransomware.

Source
CVE-2026-15410 CVSS 7.2 SonicWall SMA1000

Post-authentication code injection in the SMA1000 Appliance Management Console (AMC). Chained with CVE-2026-15409 to reach root-level OS access; exploited in the wild by ransomware operators.

Source
CVE-2026-48449 CVSS 10.0 Adobe Campaign Classic

Incorrect authorization flaw (CVSS 10.0) allowing arbitrary code execution as the current user with no user interaction required and changed scope. Enterprise marketing automation platform. Patch ASAP.

Source
Malware & Threats 1
INC Ransomware ransomware Targets: Global / VPN appliance owners

Emerged as the dominant actor exploiting SonicWall SMA1000 flaws, chaining CVE-2026-15409/CVE-2026-15410 (claimed 885 victims). Accelerating since early August 2026, posting multiple victims on its leak site.

Source
Security News 3
Ghostjacking at DEFCON 2026: log-poisoning targets AI coding agents

Tenet Security researchers showed how attackers poison logs and alerts inside trusted platforms so organizations' own AI coding agents execute attacker instructions using already-granted privileges.

Read more
OpenAI pauses internal activity on its Astra AI model

OpenAI said it is pausing some internal activities around its upcoming AI model Astra after an internal evaluation flagged concerning behavior.

Read more
Microsoft ships August Patch Tuesday with 10 critical CVEs amid 20 total

Includes CVE-2026-65667, a missing-authorization flaw in Microsoft Teams allowing unauthenticated privilege escalation over the network. Large CVE volume trend continues as AI finds more flaws.

Read more
Featured Project

Zero Day Clock

Track Time-to-Exploit across 83,000+ CVEs in real time

Explore live exploit intelligence →