Daily Cybersecurity Briefing — August 15, 2026
- Paul Baity
- 2 days ago
- 4 min read
ACTIVELY EXPLOITED VULNERABILITIES
CVE-2026-58231 | SAP Commerce Cloud | CVSS 10.0 | Maximum-severity RCE vulnerability under active exploitation. Organizations should apply SAP patches immediately.
CVE-2026-65400 | Apple macOS Screen Sharing | Critical authentication bypass | Actively exploited in the wild to deploy cryptocurrency mining malware. Apply latest Apple security updates.
Microsoft Windows 'LegacyHive' Zero-Day | Disclosed post-July 2026 Patch Tuesday. Patch released. FCEB agencies should prioritize remediation.
CVE-2026-20349 | Cisco ASA & FTD | Heap Inspection Vulnerability | Added to CISA KEV August 11. Patch immediately.
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Use-After-Free | Added to CISA KEV August 11. FCEB patch deadline: August 25, 2026.
CVE-2026-72898 | Metabase | SQL Injection | Unauthenticated remote attacker can inject arbitrary SQL and gain administrator access to the instance. Added to CISA KEV August 11.
CVE-2026-18577 | N-able N-central | Authentication Bypass via Alternate Path | Added to CISA KEV August 3. Managed service providers using N-central should patch immediately.
BREACHES
Port of Seattle | Rhysida ransomware | Port refusing to pay ransom; stolen data expected to be published on the dark web imminently.
Morgan Records Management | 52 GB of sensitive records exposed (August 12, 2026). Nature of breach and full scope of affected individuals still being assessed.
Highwoods Properties (USA) & Morguard (Canada) | Helix ransomware group | Both major real estate firms targeted. Morguard attack announced August 7, 2026.
Multi-sector wave (August 5, 2026) | Threat actors OROVA, Play, KRYBIT, INC_RANSOM, and Aur0ra claimed responsibility for breaches across numerous companies and industry sectors.
CISA Advisory AA26-222A — Gunra Ransomware | Double-extortion model: data exfiltrated prior to encryption and threatened for public release unless ransom is paid.
THREATS & POLICY
Scattered Spider takedown | 19-year-old member extradited to the U.S. and awaiting sentencing for cybercrime charges. Extradition completed July 2, 2026.
FBI disrupted NetNut botnet | Network of approximately 2 million hijacked home devices used to route cybercrime traffic dismantled (July 3, 2026) with private-sector partners.
EU data protection watchdog raised red flags over expanded Europol powers (August 14, 2026), citing privacy implications for EU citizens.
2026 U.S. Cyber Strategy & Cybercrime Executive Order | Shifts doctrine from 'defend and recover' to 'deter and disrupt.' Federal agencies directed to treat cybercrime groups as transnational criminal networks.
GAO raised concerns about redundant and inefficient cybersecurity regulations in a July 22 letter to Congressional committees.
CLOUD & SAAS SECURITY
Google Cloud Threat Horizons H1 2026 Report | AI-powered attackers exploiting misconfigurations at speeds that human security teams cannot match. Automated lateral movement is now a primary threat vector.
95% of cloud security failures traced to human misconfiguration — not platform vulnerabilities. Misconfigured storage buckets, exposed management interfaces, and incorrect network controls are top culprits. (Security Boulevard, August 2026)
Non-Human Identity (NHI) attacks | Cloud Security Alliance survey: 79% of IT and security professionals feel ill-equipped to prevent attacks exploiting automated bots and API credentials.
Generative AI enabling highly personalized phishing and deepfake campaigns targeting SaaS environments. Most SaaS breaches still begin with misconfigurations or overprivileged accounts, not sophisticated external attacks.
IDENTITY & AUTHENTICATION
Pass-the-Passkey Attack Research | Presented by SpecterOps at Black Hat USA 2026 | 20+ attack techniques targeting Windows 11, Microsoft Entra ID, Google Chrome, and password managers. Bypasses phishing-resistant FIDO2 MFA without breaking the FIDO2 standard.
CVE-2026-34348 | Windows Event Logging Service | Information Disclosure | Windows was logging passkey private key material in cleartext to event logs readable by any authenticated local user. Fully patched Windows 11 now truncates signature fields.
Google Chrome Windows passkey sync vulnerability | All Chrome versions on Windows with TPM supporting passkey sync are affected, enabling passkey theft and MFA bypass. Patch status: under investigation.
Microsoft Entra ID passkey rollout | Starting September 1, 2026, users enrolled in SMS/voice MFA will be automatically enabled for passkeys. Admins should review enrollment workflows and user communication plans now.
MOBILE SECURITY
New Android banking malware | Combines NFC relay attack + RAT to enable real-time fraudulent bank card use without physical device possession. (Malwarebytes, August 2026)
Android banking malware scale | 34 active banking malware families targeting 1,243 financial institutions across 90 countries. 90 zero-day exploits actively used against mobile platforms in H1 2026.
Apple iOS mercenary spyware alerts | Apple now sends Threat Notifications to iPhone users targeted by nation-state spyware (e.g., NSO Group Pegasus zero-click exploits via iMessage and WhatsApp). (Malwarebytes, August 2026)
Android Security Bulletin — August 2026 | Google released monthly patches addressing critical and high-severity vulnerabilities across Android OS components. Apply updates immediately.
RESEARCH & TOOLS
GPUBreach (Black Hat USA 2026) | Rowhammer bit-flip attacks on NVIDIA GDDR6 GPU memory chain into full CPU-level privilege escalation — first demonstrated hardware-level GPU-to-CPU exploit chain.
OpenAI Daybreak AI security platform expanded (August 10) | GPT-5.6 Cyber discovered CVE-2026-15903, a V8 heap-sandbox escape in Chrome — patched by Google. Daybreak provides approved defenders GPT-5.6 Sol for defensive security research.
ShieldBreak PoC — Microsoft Defender patch bypass | Researchers claim CVE-2026-50656 (RoguePlanet) patch is inadequate, enabling SYSTEM-level access. No official Microsoft response as of August 14. (The Hacker News)
Black Hat USA 2026 AI security surge | 29% of all briefings (35/121) directly addressed AI security, AI red teaming, or LLM-assisted offensive security. Post-quantum migration and OT security also heavily featured. (cybersecuritypulse.net)
Sources
CISA KEV — Aug 11 additions: https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
CISA KEV — Aug 3 addition: https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
CISA Gunra Ransomware Advisory: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Pass-the-Passkey Attacks (The Hacker News): https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html
Pass-the-Passkey Windows/Entra ID (GBHackers): https://gbhackers.com/pass-the-passkey-attack-exploits-windows-and-entra-id/
Android banking malware (Malwarebytes): https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time
Apple spyware alerts (Malwarebytes): https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware
ShieldBreak PoC (The Hacker News): https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
Black Hat + DEF CON 2026 Recap: https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside
Data Breaches August 2026 (BreachSense): https://www.breachsense.com/breaches/2026/august/
Cloud Misconfigurations 2026 (Security Boulevard): https://securityboulevard.com/2026/08/why-cloud-misconfigurations-continue-to-cause-data-breaches-in-2026/
Google Cloud Threat Horizons H1 2026: https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026
US Cybercrime Executive Order (Weaver): https://weaver.com/resources/strategic-priorities-in-the-2026-us-cyber-strategy-and-cybercrime-executive-order/
New InfoSec Tools (August 14, 2026): https://www.news4hackers.com/new-information-security-products-tools-released-this-week-august-14-2026

Comments