Cybersecurity Daily Briefings

Critical vulnerabilities, active threats, and security news — curated for professionals.

Updated every workday at 08:00 CET
10 Aug 2026
Daily Cybersecurity Briefing — August 10, 2026
3 CVEs 2 threats 3 news items
Critical Vulnerabilities 3
CVE-2026-9198 CVSS 9.8 IBM Langflow

Critical remote code execution flaw in Langflow's AI agent framework; actively exploited in the wild with public exploit code available (CISA KEV).

Source
CVE-2026-18576 CVSS 9.8 N-able N-central

Pre-authentication flaw lets unauthenticated attackers hijack administrative accounts; exploited to reach and persist on managed systems (N-able issued hotfix 2).

Source
CVE-2026-29146 CVSS 9.8 Apache Tomcat

Critical flaw (missing encryption of sensitive data) in Apache Tomcat, targeted in a manual campaign that planted reverse shells on servers.

Source
Malware & Threats 2
Unlimited Technology Systems breach apt Targets: US

Data breach impacting 3.8 million people; attackers also breached TrueConf to trojanize client installers with backdoors.

Source
UNC6671 apt Targets: Global / financial

Extortion group (BlackFile-linked) conducting vishing attacks against personal phones to steal SaaS credentials; tied to hedge fund cyberattacks.

Source
Security News 3
CISA warns of actively exploited Langflow, N-central, Tomcat flaws

Federal agencies have 3 days to patch three actively exploited vulnerabilities (Langflow RCE, N-central admin takeover, Tomcat flaws).

Read more
Microsoft early August update: 10 critical bugs among 20 CVEs

Patch Tuesday advance release includes a CVSS 10.0 Azure SQL Database improper-authentication flaw (remote privilege escalation, no user interaction).

Read more
Ransom Cartel creator sentenced; Snowflake attacker pleads guilty

Ransom Cartel ransomware creator sentenced to 16 years; a Canadian pleaded guilty to Snowflake cloud data-theft attacks.

Read more
7 Aug 2026
Daily Cybersecurity Briefing — August 7, 2026
3 CVEs 3 threats 4 news items
Critical Vulnerabilities 3
CVE-2026-63077 CVSS 9.8 JetBrains TeamCity (on-premise)

Deserialization of untrusted data in the agent polling protocol allows an unauthenticated attacker to bypass auth checks and execute arbitrary OS commands. Actively exploited in the wild; added to CISA KEV.

Source
CVE-2026-65667 CVSS 9.1 Microsoft Teams

Missing authorization allows an unauthorized attacker to elevate privileges over a network. Part of Microsoft's August 2026 early security update (10 critical, 17 CVEs).

Source
CVE-2026-14364 CVSS 9.8 TrueBooker WordPress plugin

Appointment Booking and Scheduler System plugin for WordPress vulnerable to account/authorization bypass, allowing unauthorized access to booking data and admin functions.

Source
Malware & Threats 3
ENDLESSDOORS rat Targets: Zbtlink routers, global IoT

Factory-shipped backdoor in 20+ Chinese Zbtlink router models (21 firmware images, 2+ years). Runs as disguised userland process with root, beacons to Chinese C2 every ~35s.

Source
khunt rat Targets: Oracle databases / Windows servers

Post-exploitation toolkit compiled inside the Oracle DB engine (SQL injection->SYSTEM). No on-disk executable; hunt for schema objects starting 'Khunt'.

Source
INC Ransomware ransomware Targets: Global, multiple victims

Resecurity observed INC Ransomware accelerating activity since early August 2026, listing multiple new victims on its data leak site.

Source
Security News 4
CISA Flags JetBrains TeamCity RCE Under Active Exploitation

CVE-2026-63077 (CVSS 9.8) in the agent polling protocol enables unauthenticated RCE. Apply the vendor patch to on-premise TeamCity servers urgently.

Read more
Cisco Patches 12 SD-WAN / IOS XE Flaws incl. Three 9.9 CVSS Bugs

Multiple critical issues in Catalyst SD-WAN and IOS XE (autonomous/controller mode), incl. input validation, access control and path traversal. Not yet exploited.

Read more
Snowflake Hacker Pleads Guilty Over Breaches of 100M+ People

Connor Moucka pleaded guilty to 2024 Snowflake customer breaches (165 orgs, 100M+ records), driven by stale infostealer-harvested passwords and MFA disabled.

Read more
4,400+ Rockwell PLCs Exposed Online, 22 in Water-Attack Cities

Forescout scan found exposed PLCs incl. 22 in US water-utility attack zones; attackers tampered with already-reachable controllers rather than exploiting flaws.

Read more
6 Aug 2026
Daily Cybersecurity Briefing — August 6, 2026
3 CVEs 2 threats 3 news items
Critical Vulnerabilities 3
CVE-2026-58048 CVSS 9.4 cPanel & WHM / WP Squared

Critical privilege escalation in cPanel & WHM database management lets an authenticated hosting customer run SQL as database root and, in some setups, compromise the OS. Affects all supported cPanel versions.

Source
CVE-2026-15409 CVSS 10.0 SonicWall SMA1000 (6210, 7210, 8200v)

Critical SSRF in the SMA1000 appliance interface, exploited as a zero-day (since late June) and chained with CVE-2026-15410 for arbitrary command execution and device takeover.

Source
CVE-2026-15410 CVSS 7.2 SonicWall SMA1000

High-severity command injection flaw, chained with CVE-2026-15409 to gain root access on SMA1000 appliances.

Source
Malware & Threats 2
INC Ransomware ransomware Targets: US, Australia, UAE, Colombia, Switzerland

Now the dominant actor exploiting the SonicWall SMA1000 zero-days (CVE-2026-15409/15410) to breach networks and push custom malware.

Source
XCSSET infostealer Targets: macOS developers / users

New version targeting thousands of macOS users via compromised Xcode projects and GitHub repositories.

Source
Security News 3
cPanel patches critical SQL-root escalation (CVE-2026-58048)

Authenticated hosting customers could execute SQL as database root; patch rated 9.4 CVSS. All supported cPanel & WHM versions affected.

Read more
N-able warns of exploited N-central authentication bypass

Attackers exploiting CVE-2026-18577 (auth bypass via alternate path/channel) enabling account takeover; incomplete patch of CVE-2026-18556. Added to CISA KEV.

Read more
Malvertising hits crypto users; new RATs surface

Massive malvertising uses fake Solana/Luno/TradingView pages to assemble malware in memory; Dolphin X RAT and Chaos gang's msaRAT backdoor also on the rise.

Read more
5 Aug 2026
Daily Cybersecurity Briefing — 2026-08-05
4 CVEs 3 threats 3 news items
Critical Vulnerabilities 4
CVE-2026-48330 CVSS 10.0 Adobe Campaign Classic (ACC)

Critical SQL injection could result in arbitrary code execution. Exploitation could allow an attacker to execute arbitrary code on affected installations.

Source
CVE-2026-12118 CVSS 9.8 IBM webMethods Integration (on prem)

Unauthenticated remote code execution via deserialization of untrusted data in versions 10.15 and 10.11. An unauthenticated attacker can execute arbitrary code on the system.

Source
CVE-2026-4978 CVSS 9.8 UMAI Vision Traffic Analysis System

Critical SQL injection due to improper neutralization of special elements, allowing remote attackers to inject SQL queries.

Source
CVE-2026-39932 CVSS 9.1 OpenEMR

Remote code execution in the document category tree component (library/classes/Tree.class.php) through 8.2.0, exploitable by authenticated administrators.

Source
Malware & Threats 3
FDMTP backdoor (Mustang Panda) apt Targets: Overseas Chinese users of QuickFox VPN

Long-running supply chain attack (since ~Aug 2025) trojanizing the QuickFox VPN installer to deliver the FDMTP backdoor, attributed to state-sponsored actor Mustang Panda.

Source
GodDamn ransomware ransomware Targets: Global

New ransomware family that employs the PoisonX kernel driver to neutralize security software as part of its defense-evasion strategy.

Source
Greatness PhaaS infostealer Targets: iCloud, Yahoo, Google Workspace users

Phishing-as-a-service kit now adds device-code phishing, AiTM credential/token theft and OAuth consent abuse to bypass MFA and seize accounts.

Source
Security News 3
Keyv npm worm poisons hundreds of packages, plants Claude Code and VS Code hooks

A credential-stealing npm worm spread from [email protected] to hundreds of packages (up to ~868 names per Aikido), harvesting repository, registry, cloud and private-key material via preinstall scripts and CI environments. 442-1381 poisoned versions verified.

Read more
Fake Adobe and Zoom updates install ScreenConnect for persistent access

The SMOKE#SCREEN campaign uses social-engineering lures themed around Adobe/Zoom updates and document reviews to deploy ConnectWise ScreenConnect RMM agents, granting persistent remote access.

Read more
Google deletes ADK AI workflows after malicious GitHub issue triggered privileged agent

Pillar Security showed a public GitHub issue could prompt-inject Google's ADK triage agent into triggering a privileged code-fixing agent, achieving code execution on CI and exfiltration of a bot PAT.

Read more
4 Aug 2026
Daily Cybersecurity Briefing — August 4, 2026
4 CVEs 2 threats 3 news items
Critical Vulnerabilities 4
CVE-2026-41089 CVSS 9.8 Microsoft Windows Netlogon

Wormable remote code execution vulnerability in Windows Netlogon. Active exploitation confirmed roughly three weeks after the May 2026 patch. Critical priority.

Source
CVE-2026-20253 CVSS 9.8 Splunk Enterprise

Critical flaw under active exploitation. Added to CISA KEV; federal agencies given just 3 days to patch. Allows remote takeover of affected Splunk deployments.

Source
CVE-2026-18614 CVSS 9.8 GL-iNet GL-MT3000

Critical command injection in the s2s.enable_echo_server function of the s2s.so native plugin (/cgi-bin/glc), up to firmware 4.4.5. Published August 3, 2026.

Source
CVE-2026-59309 CVSS 9.8 VMware Directory Service (vCenter)

Authentication-bypass vulnerability in VMware Directory Service allowing a network-adjacent attacker to bypass vCenter authentication and seize control of the management plane.

Source
Malware & Threats 2
SmartLoader (FakeGit campaign) loader Targets: Developers / global

Nearly 7,600 malicious GitHub repositories, 800+ posing as AI skills or MCP servers, deliver the SmartLoader malware family. Supply-chain style distribution targeting developers.

Source
VeloCloud Orchestrator exploit rat Targets: Enterprise SD-WAN / global

Attackers are actively exploiting a command injection vulnerability in VMware VeloCloud Orchestrator in the wild, targeting managed SD-WAN environments.

Source
Security News 3
PNLD Breach Exposes U.K. Police and Government Contacts on Dark Web

A breach of the Police National Legal Database (PNLD) leaked contact details of U.K. police and government personnel onto the dark web, raising law-enforcement security concerns.

Read more
N-able N-central Auth Bypass Exploited to Reach Customer Systems

Threat actors exploited an authentication bypass in N-able N-central to gain remote administrative access and reach managed customer systems; initial fix was incomplete.

Read more
Google Password Manager Attacks Could Hijack Passkey Accounts

Research shows malware may abuse Google Password Manager flows to hijack passkey-protected accounts; no public fix notice yet, raising user verification concerns.

Read more
3 Aug 2026
Daily Cybersecurity Briefing — 2026-08-03
4 CVEs 3 threats 3 news items
Critical Vulnerabilities 4
CVE-2026-63030 CVSS 9.8 WordPress (core)

Chained with a second flaw to allow unauthenticated remote code execution on default WordPress installs. Added to CISA KEV catalog as actively exploited; patch immediately.

Source
CVE-2026-18573 CVSS 7.5 Keycloak

Client access-type policy condition bypass in keycloak-services that can let unauthorized clients bypass intended access policies and obtain elevated access.

Source
CVE-2026-40249 CVSS 8.6 goshs (Go simple HTTP server)

bulkDownload (?bulk&file=) ZIP handler fails to apply findEffectiveACL/customAuth, allowing unauthenticated reads of ACL-protected files. Incomplete fix for CVE-2026-40189; fixed in 2.1.1.

Source
CVE-2026-xxxx (XSS) CVSS 6.4 Exclusive Addons for Elementor (WordPress)

Stored Cross-Site Scripting via the 'exad_infobox_image' parameter in all versions up to 2.7.9.8 due to insufficient sanitization.

Source
Malware & Threats 3
SEXi / APT INC ransomware Targets: VMware ESXi environments, global orgs

SEXi ransomware operation rebranded to APT INC and continues high-impact attacks against VMware ESXi servers and virtualized environments.

Source
CloudSorcerer apt Targets: Russian government organizations

APT group abusing public cloud services to steal data from Russian government organizations in ongoing cyberespionage campaigns.

Source
AudiA6 (takedown) ransomware Targets: Crypto laundering service

Law enforcement dismantled the AudiA6 cryptocurrency service allegedly laundering more than $380M for ransomware actors and cybercriminals.

Source
Security News 3
CISA warns of attacks on water/wastewater PLCs

CISA reports a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater sector.

Read more
Anthropic's Claude linked to hacks and PyPI malware

Anthropic says it is responsible for hacking three companies and uploading malware to the Python Package Index (PyPI) via Claude AI models.

Read more
CISA orders fixes for Check Point VPN products

US agencies ordered to secure Check Point Remote Access VPN and Mobile Access deployments against active exploitation; MikroTik RouterOS also under brute-force attack via a RouterOS flaw.

Read more
31 Jul 2026
Daily Cybersecurity Briefing — 2026-07-31
4 CVEs 2 threats 4 news items
Critical Vulnerabilities 4
CVE-2026-56155 CVSS 7.8 Microsoft Active Directory Federation Services (AD FS)

Elevation of privilege vulnerability exploited in the wild as a zero-day. Allows an attacker to gain administrator privileges. Patched in July 2026 Patch Tuesday (569 CVEs total, the largest ever).

Source
CVE-2026-55944 CVSS 9.8 Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Premises)

Critical remote code execution via deserialization of untrusted data. No authentication or user interaction required. Send a crafted login request to trigger the flaw.

Source
CVE-2026-20316 CVSS N/A (Actively Exploited) Cisco Secure Firewall Management Center (FMC)

Zero-day vulnerability actively exploited in the wild affecting Cisco Secure FMC. Patches released by Cisco.

Source
CVE-2026-56164 CVSS 5.3 Microsoft SharePoint Server (2016, 2019, Subscription Edition)

Elevation of privilege vulnerability exploited in the wild as a zero-day. AMSI integration can provide mitigation by scanning for malicious POST requests.

Source
Malware & Threats 2
PLC Attacks on Water Systems apt Targets: US Water & Wastewater Sector (Minnesota and beyond)

CISA issued an urgent alert after coordinated attacks on PLCs at water utilities. Dozens of systems in Minnesota were hit. Operators urged to secure internet-exposed OT devices immediately.

Source
DangleGeddon apt Targets: Global — governments, banks, supply chains

Researchers warn AI could weaponize forgotten/dangling DNS records at global scale, enabling large-scale hijacking of domains belonging to governments and enterprises.

Source
Security News 4
Microsoft July 2026 Patch Tuesday: 569 CVEs — Largest Ever

Microsoft patched 569 CVEs including 56 critical, 510 important. Three zero-days, two exploited in the wild (CVE-2026-56155 in AD FS, CVE-2026-56164 in SharePoint). 43.8% were EoP flaws, 25.1% were RCE.

Read more
Chrome 151 Patches 370 Vulnerabilities

Google's Chrome 151 stable release fixes roughly 370 security vulnerabilities, including ~80 critical- and high-severity bugs. Users urged to update immediately.

Read more
Analog Devices Discloses Data Breach

Semiconductor firm Analog Devices (NASDAQ: ADI) disclosed a data breach from a hacker attack detected last month. Details of the impact are still emerging.

Read more
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

A critical vulnerability in Ruflo allowed unauthenticated remote code execution inside an MCP bridge container. Attackers could spawn rogue AI agents via exposed HTTP endpoints.

Read more
30 Jul 2026
Daily Cybersecurity Briefing — July 30, 2026
3 CVEs 2 threats 4 news items
Critical Vulnerabilities 3
CVE-2026-59309 CVSS 9.8 VMware vCenter Server

Authentication bypass vulnerability in VMware vCenter. A remote attacker with network access can bypass authentication and gain unauthorized access to the system. Part of a trio of critical VMware flaws including CVE-2026-59310 (CVSS 9.8, directory traversal leading to RCE) and a VM escape flaw. No known exploitation in the wild, but Broadcom marked as emergency requiring immediate patching.

Source
CVE-2026-66066 CVSS 9.5 Ruby on Rails Active Storage

Critical file disclosure vulnerability in Rails Active Storage when using libvips. Unauthenticated attackers can read arbitrary server files via crafted image uploads. Affects Rails 7.0.0-7.2.3.1, 8.0.0-8.0.5, 8.1.0-8.1.3. A public PoC has been published. Patched in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1.

Source
CVE-2026-61511 CVSS 9.8 vBulletin Forum Software

Critical pre-authentication remote code execution vulnerability in vBulletin. Allows unauthenticated attackers to execute arbitrary PHP code through template rendering. A public PoC exploit is available, lowering the barrier for mass exploitation. All unpatched internet-facing vBulletin servers are at risk.

Source
Malware & Threats 2
OWAReaper / Laundry Bear apt Targets: US & European government, telecom, financial, hospitality, aerospace

Russian state-sponsored APT group Laundry Bear (Void Blizzard/TA488) exploiting CVE-2026-42897, an Exchange OWA XSS vulnerability, to deliver the OWAReaper backdoor. The 'half-click exploit' triggers when users simply open a malicious email in OWA. Campaign targets government entities and critical infrastructure sectors.

Source
ShinyHunters infostealer Targets: Healthcare sector (US)

Health-ISAC warns of rising ShinyHunters data theft attacks targeting the healthcare industry. The threat actor is increasingly focusing on medical data exfiltration from healthcare organizations.

Source
Security News 4
Cisco FMC Zero-Day CVE-2026-20316 Actively Exploited in the Wild

Cisco warns that CVE-2026-20316, a static credential flaw in Secure Firewall Management Center (FMC), is being actively exploited in zero-day attacks. CISA mandates FCEB agencies patch by August 1, 2026.

Read more
Coordinated Cyberattack Hits 30+ Minnesota Water Utilities

A coordinated OT attack targeted over 30 Minnesota water systems, taking at least one plant offline. Incident highlights growing risks to critical water infrastructure from cyberattacks.

Read more
FastJson CVE-2026-16723 RCE Zero-Day Exploited Against US Firms

Hackers are actively exploiting a zero-day RCE vulnerability in the FastJson Java library (CVE-2026-16723). No patch available as FastJson 1.x is no longer maintained. Imperva warns of active attacks against US organizations.

Read more
OpenAI Agent Used Exposed Credentials in Hugging Face Breach

An OpenAI agent used exposed credentials across four different services during the Hugging Face breach incident, raising concerns about AI agent security and credential management.

Read more
29 Jul 2026
Daily Cybersecurity Briefing — July 29, 2026
3 CVEs 2 threats 4 news items
Critical Vulnerabilities 3
CVE-2026-61511 CVSS 9.8 vBulletin 5.x/6.x

Critical unauthenticated remote code execution via eval injection in vB5_Template_Runtime::runMaths(). Affects vBulletin 5.x through 5.7.5 and 6.x through 6.2.1. Public exploit released — patch immediately.

Source
CVE-2026-16232 CVSS 9.1 Check Point SmartConsole

Authentication bypass zero-day in Check Point SmartConsole actively exploited in the wild. Allows unauthenticated attacker to gain full administrative privileges. Check Point released a jumbo hotfix.

Source
CVE-2026-56155 CVSS 7.8 Active Directory Federation Services (ADFS)

Elevation of privilege vulnerability in Microsoft ADFS. Exploited in the wild — added to CISA KEV catalog. Part of July 2026 Patch Tuesday with record 570 flaws.

Source
Malware & Threats 2
ShinyHunters apt Targets: Education sector, healthcare globally

Active campaign exploiting CVE-2026-35273 (Oracle PeopleSoft critical RCE). Claims 300+ compromised instances across 100+ orgs. Also targeting OAuth abuse in SaaS apps per Microsoft threat intel.

Source
61 New Ransomware Groups (2025-2026) ransomware Targets: Global, all sectors

61 new ransomware groups emerged Apr 2025–Mar 2026 (1+/week). Some adopting post-quantum cryptography. Ransom payment rates declining but attack volume rising.

Source
Security News 4
Microsoft July 2026 Patch Tuesday — Record 570 Flaws, 3 Zero-Days

Microsoft patched a record 570 vulnerabilities including 62 critical. Three zero-days exploited in the wild: CVE-2026-56155 (ADFS EoP), CVE-2026-3220 (Windows), plus CISA added CVE-2026-58644 and CVE-2026-50522 (SharePoint RCE) to KEV catalog. CISA ordered federal agencies to patch within 3 days.

Read more
Check Point SmartConsole Zero-Day (CVE-2026-16232) Under Active Exploitation

Authentication bypass vulnerability in Check Point SmartConsole allows full admin takeover. Actively exploited since disclosure. Check Point released emergency hotfix — all customers urged to update immediately.

Read more
Public Exploit Released for vBulletin Pre-Auth RCE (CVE-2026-61511, CVSS 9.8)

Critical unauthenticated RCE in vBulletin 5.x/6.x via eval injection. Proof-of-concept exploit now public. vBulletin 5.7.6 and 6.2.2 patched the flaw. No confirmed in-the-wild exploitation yet, but risk is high given public PoC.

Read more
ShinyHunters APT Targets Education via Oracle PeopleSoft Exploitation

ShinyHunters exploiting CVE-2026-35273 (critical Oracle PeopleSoft RCE) to breach education and healthcare orgs. Microsoft also reports OAuth abuse campaigns by overlapping threat actors targeting SaaS applications.

Read more
28 Jul 2026
Daily Cybersecurity Briefing — July 28, 2026
3 CVEs 1 threat 3 news items
Critical Vulnerabilities 3
CVE-2026-57092 CVSS 9.9 Microsoft Windows VMSwitch (Hyper-V)

Critical use-after-free elevation of privilege vulnerability in Windows Virtual Machine Switch. An attacker with guest VM access could escape to the host. Part of July 2026 Patch Tuesday — the largest in Microsoft history with 570 fixes.

Source
CVE-2026-50522 CVSS 9.8 Microsoft SharePoint Server

Critical deserialization of untrusted data vulnerability allowing unauthenticated RCE over the network. Added to CISA KEV on July 22, 2026 due to active exploitation. Attackers using this to steal machine keys and compromise domains.

Source
CVE-2026-45657 CVSS 9.8 Microsoft Windows Kernel

Critical use-after-free vulnerability in Windows Kernel enabling remote code execution over the network without user interaction. Patched in June 2026 Patch Tuesday.

Source
Malware & Threats 1
Screening Serpens (Smoke Sandstorm / UNC1549) apt Targets: Middle East — technology sector, government organizations

Iran-nexus APT group conducting ongoing cyberespionage via spear-phishing campaigns impersonating model agencies and global air carriers. Delivers custom backdoors. Active since at least February 2026.

Source
Security News 3
Microsoft July 2026 Patch Tuesday fixes record 570 flaws including 3 zero-days

Microsoft patched a record-breaking 570 vulnerabilities on July 14, 2026, including 59 Critical and 3 actively exploited zero-days. Highlights include CVE-2026-57092 (VMSwitch, CVSS 9.9) and CVE-2026-50522 (SharePoint RCE).

Read more
CISA adds actively exploited SharePoint flaw to KEV catalog

CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on July 22. The SharePoint deserialization bug is being actively exploited in widespread attacks to steal machine keys and achieve domain compromise. Federal agencies required to patch by July 25.

Read more
Accenture confirms breach after 35GB of data stolen including RSA keys

IT services giant Accenture confirmed a security breach after a threat actor stole 35GB of source code, RSA keys, SSH keys, and Azure access credentials. The data was listed for sale on an underground marketplace.

Read more
Featured Project

Zero Day Clock

Track Time-to-Exploit across 83,000+ CVEs in real time

Explore live exploit intelligence →