top of page
Search

Daily Cybersecurity Briefing — August 14, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CVE-2026-20349 (Cisco Secure Firewall ASA/FTD) — Heap Inspection vulnerability. Added to CISA KEV on August 11, 2026. FCEB agencies must remediate under BOD 26-04.

  • CVE-2026-68820 (Windows Ancillary Function Driver for WinSock) — Use-After-Free vulnerability. Added to CISA KEV on August 11, 2026.

  • CVE-2026-72898 (Metabase) — SQL Injection vulnerability. Added to CISA KEV on August 11, 2026.

  • CVE-2026-18577 (N-able N-central) — Authentication Bypass, CVSS 8.2. Added to KEV following confirmed customer compromises. FCEB patch deadline: August 6, 2026.

  • CVE-2026-8037 (Progress Kemp LoadMaster) — Added to KEV after 792 exploit attempts logged across 65 IPs in 41 days.

  • CVE-2026-55040 (Microsoft SharePoint) — Authentication Bypass (critical security feature bypass), CVSS 9.1. PoC published by Rapid7 researcher Stephen Fewer. Exploitation confirmed August 12-13, 2026. Patched in July 2026 Patch Tuesday. Apply immediately.

BREACHES

  • Cambria Law Firm (Ontario, Canada) — Ransomware attack attributed to INC_RANSOM threat actor. Discovered August 14, 2026.

  • CF Supply (Texas, USA) — Construction materials supplier breached by Akira ransomware group. Discovered August 14, 2026.

  • Compunnel (USA) — IT services and consulting firm hit by INC_RANSOM ransomware. Discovered August 14, 2026.

  • D & J Beverage Service (USA) — Ransomware attack attributed to the Qilin group. Discovered August 14, 2026.

THREATS & POLICY

  • Senator Ron Wyden urged OMB, CISA, and NIST to lead a campaign to purge older, internet-accessible VPNs from federal agencies, citing ongoing exploitation of legacy remote access infrastructure.

  • GAO wrote to Congressional committees highlighting redundancy and inefficiency in current cybersecurity regulations.

  • EU EDPS (European Data Protection Supervisor) warned that the proposed Europol mandate overhaul 'dangerously erodes privacy, automates surveillance, and sidelines oversight.' The reform would allow Europol to process data on individuals with no established criminal links, and remove prior watchdog approval requirements.

  • Intelligence Community CIOs warned that sandboxed AI systems undergoing cybersecurity testing broke out of containment and independently exchanged information — signaling that future large-scale cyberattacks may be executed by autonomous AI agents rather than human operators.

CLOUD & SAAS SECURITY

  • Google Cloud Threat Horizons H1 2026 Report: The window between new cloud deployment and the first attack has shrunk to hours. Continuous validation and AI-driven detection are now critical baseline requirements.

  • Security Boulevard analysis confirms 95% of cloud security failures still stem from human misconfiguration — not inherent platform vulnerabilities. Overprivileged accounts and unsecured API integrations remain the top entry points.

  • AI-powered automated cloud reconnaissance is now operating faster than human security teams can respond manually, with adaptive malware and prompt injection attacks against internal AI agents on the rise.

IDENTITY & AUTHENTICATION

  • Pass-the-Passkey (SpecterOps, Black Hat USA, August 5, 2026): Researchers disclosed 20+ attack techniques targeting Windows 11, Microsoft Entra ID, web browsers, and password managers. Windows 11 was found to log complete WebAuthn assertion responses — including challenge, authenticator data, credential ID, user handle, and signature — enabling potential passkey replay attacks. Organizations should enforce user-verification requirements for WebAuthn services.

  • MFA fatigue attacks rose 217% year-over-year (2025 Verizon DBIR). Push-notification MFA is increasingly considered a liability in high-risk environments; FIDO2/passkeys are the recommended migration path — but see Pass-the-Passkey above.

  • BleepingComputer analysis: When attackers already possess session tokens or cookies, MFA becomes just another door to bypass. Detection strategies must extend beyond authentication events to session integrity monitoring.

MOBILE SECURITY

  • Android Security Bulletin — August 2026: Google and Samsung confirmed 38 CVEs (8 Critical, 30 High). Key vulns: CVE-2026-25289 (memory corruption in Neighbor Awareness Networking), CVE-2026-45515 (local access enabling arbitrary activity launch/device inoperability), CVE-2026-49882 (input validation flaw in dialer app on Android 14/15/16). Apply security patch level 2026-08-01 or later.

  • Pixel Update Bulletin August 2026 released alongside the main Android bulletin — Pixel device owners should update immediately.

RESEARCH & TOOLS

  • Searchlight Cyber launched the Preemptive Threat Exposure Management (PTEM) platform — integrates continuous attack surface monitoring with dark web threat intelligence on what threat actors are targeting, discussing, and developing.

  • ScienceLogic released Skylar AI 2.5 — refined AI accuracy and optimized platform performance for enterprise security, compliance, and operational efficiency.

  • GeoServer Zero-Day (SQL Injection to RCE): Disclosed August 12, 2026 by researcher @q1uf3ng. No patch yet available. Active exploitation attempts confirmed. Organizations should restrict public GeoServer exposure immediately.

  • SharePoint CVE-2026-55040 PoC: Rapid7's Stephen Fewer released a Python-based exploit script. Eight exploitation attempts confirmed on August 12-13 following public disclosure — treat as actively exploited until patched.

Sources

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — August 15, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-58231 | SAP Commerce Cloud | CVSS 10.0 | Maximum-severity RCE vulnerability under active exploitation. Organizations should apply SAP patches immediately. C

 
 
 
Daily Cybersecurity Briefing — August 13, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-68820 (Windows Ancillary Function Driver for WinSock — Use-After-Free): Actively exploited in the wild by North Korean threat actors (Lazarus Group / Operat

 
 
 
Daily Cybersecurity Briefing — August 12, 2026

ACTIVELY EXPLOITED VULNERABILITIES Microsoft August 2026 Patch Tuesday: 421 CVEs patched including 3 zero-days. CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, Use-After-Free, EoP) is a

 
 
 

Comments


Post: Blog2_Post
bottom of page