top of page
Search

Daily Cybersecurity Briefing — August 15, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CVE-2026-58231 | SAP Commerce Cloud | CVSS 10.0 | Maximum-severity RCE vulnerability under active exploitation. Organizations should apply SAP patches immediately.

  • CVE-2026-65400 | Apple macOS Screen Sharing | Critical authentication bypass | Actively exploited in the wild to deploy cryptocurrency mining malware. Apply latest Apple security updates.

  • Microsoft Windows 'LegacyHive' Zero-Day | Disclosed post-July 2026 Patch Tuesday. Patch released. FCEB agencies should prioritize remediation.

  • CVE-2026-20349 | Cisco ASA & FTD | Heap Inspection Vulnerability | Added to CISA KEV August 11. Patch immediately.

  • CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Use-After-Free | Added to CISA KEV August 11. FCEB patch deadline: August 25, 2026.

  • CVE-2026-72898 | Metabase | SQL Injection | Unauthenticated remote attacker can inject arbitrary SQL and gain administrator access to the instance. Added to CISA KEV August 11.

  • CVE-2026-18577 | N-able N-central | Authentication Bypass via Alternate Path | Added to CISA KEV August 3. Managed service providers using N-central should patch immediately.

BREACHES

  • Port of Seattle | Rhysida ransomware | Port refusing to pay ransom; stolen data expected to be published on the dark web imminently.

  • Morgan Records Management | 52 GB of sensitive records exposed (August 12, 2026). Nature of breach and full scope of affected individuals still being assessed.

  • Highwoods Properties (USA) & Morguard (Canada) | Helix ransomware group | Both major real estate firms targeted. Morguard attack announced August 7, 2026.

  • Multi-sector wave (August 5, 2026) | Threat actors OROVA, Play, KRYBIT, INC_RANSOM, and Aur0ra claimed responsibility for breaches across numerous companies and industry sectors.

  • CISA Advisory AA26-222A — Gunra Ransomware | Double-extortion model: data exfiltrated prior to encryption and threatened for public release unless ransom is paid.

THREATS & POLICY

  • Scattered Spider takedown | 19-year-old member extradited to the U.S. and awaiting sentencing for cybercrime charges. Extradition completed July 2, 2026.

  • FBI disrupted NetNut botnet | Network of approximately 2 million hijacked home devices used to route cybercrime traffic dismantled (July 3, 2026) with private-sector partners.

  • EU data protection watchdog raised red flags over expanded Europol powers (August 14, 2026), citing privacy implications for EU citizens.

  • 2026 U.S. Cyber Strategy & Cybercrime Executive Order | Shifts doctrine from 'defend and recover' to 'deter and disrupt.' Federal agencies directed to treat cybercrime groups as transnational criminal networks.

  • GAO raised concerns about redundant and inefficient cybersecurity regulations in a July 22 letter to Congressional committees.

CLOUD & SAAS SECURITY

  • Google Cloud Threat Horizons H1 2026 Report | AI-powered attackers exploiting misconfigurations at speeds that human security teams cannot match. Automated lateral movement is now a primary threat vector.

  • 95% of cloud security failures traced to human misconfiguration — not platform vulnerabilities. Misconfigured storage buckets, exposed management interfaces, and incorrect network controls are top culprits. (Security Boulevard, August 2026)

  • Non-Human Identity (NHI) attacks | Cloud Security Alliance survey: 79% of IT and security professionals feel ill-equipped to prevent attacks exploiting automated bots and API credentials.

  • Generative AI enabling highly personalized phishing and deepfake campaigns targeting SaaS environments. Most SaaS breaches still begin with misconfigurations or overprivileged accounts, not sophisticated external attacks.

IDENTITY & AUTHENTICATION

  • Pass-the-Passkey Attack Research | Presented by SpecterOps at Black Hat USA 2026 | 20+ attack techniques targeting Windows 11, Microsoft Entra ID, Google Chrome, and password managers. Bypasses phishing-resistant FIDO2 MFA without breaking the FIDO2 standard.

  • CVE-2026-34348 | Windows Event Logging Service | Information Disclosure | Windows was logging passkey private key material in cleartext to event logs readable by any authenticated local user. Fully patched Windows 11 now truncates signature fields.

  • Google Chrome Windows passkey sync vulnerability | All Chrome versions on Windows with TPM supporting passkey sync are affected, enabling passkey theft and MFA bypass. Patch status: under investigation.

  • Microsoft Entra ID passkey rollout | Starting September 1, 2026, users enrolled in SMS/voice MFA will be automatically enabled for passkeys. Admins should review enrollment workflows and user communication plans now.

MOBILE SECURITY

  • New Android banking malware | Combines NFC relay attack + RAT to enable real-time fraudulent bank card use without physical device possession. (Malwarebytes, August 2026)

  • Android banking malware scale | 34 active banking malware families targeting 1,243 financial institutions across 90 countries. 90 zero-day exploits actively used against mobile platforms in H1 2026.

  • Apple iOS mercenary spyware alerts | Apple now sends Threat Notifications to iPhone users targeted by nation-state spyware (e.g., NSO Group Pegasus zero-click exploits via iMessage and WhatsApp). (Malwarebytes, August 2026)

  • Android Security Bulletin — August 2026 | Google released monthly patches addressing critical and high-severity vulnerabilities across Android OS components. Apply updates immediately.

RESEARCH & TOOLS

  • GPUBreach (Black Hat USA 2026) | Rowhammer bit-flip attacks on NVIDIA GDDR6 GPU memory chain into full CPU-level privilege escalation — first demonstrated hardware-level GPU-to-CPU exploit chain.

  • OpenAI Daybreak AI security platform expanded (August 10) | GPT-5.6 Cyber discovered CVE-2026-15903, a V8 heap-sandbox escape in Chrome — patched by Google. Daybreak provides approved defenders GPT-5.6 Sol for defensive security research.

  • ShieldBreak PoC — Microsoft Defender patch bypass | Researchers claim CVE-2026-50656 (RoguePlanet) patch is inadequate, enabling SYSTEM-level access. No official Microsoft response as of August 14. (The Hacker News)

  • Black Hat USA 2026 AI security surge | 29% of all briefings (35/121) directly addressed AI security, AI red teaming, or LLM-assisted offensive security. Post-quantum migration and OT security also heavily featured. (cybersecuritypulse.net)

Sources

CISA KEV — Aug 11 additions: https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

CISA KEV — Aug 3 addition: https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog

CISA Gunra Ransomware Advisory: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

Pass-the-Passkey Attacks (The Hacker News): https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

Pass-the-Passkey Windows/Entra ID (GBHackers): https://gbhackers.com/pass-the-passkey-attack-exploits-windows-and-entra-id/

Android banking malware (Malwarebytes): https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time

Apple spyware alerts (Malwarebytes): https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware

ShieldBreak PoC (The Hacker News): https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html

Black Hat + DEF CON 2026 Recap: https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside

Data Breaches August 2026 (BreachSense): https://www.breachsense.com/breaches/2026/august/

Cloud Misconfigurations 2026 (Security Boulevard): https://securityboulevard.com/2026/08/why-cloud-misconfigurations-continue-to-cause-data-breaches-in-2026/

Google Cloud Threat Horizons H1 2026: https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026

US Cybercrime Executive Order (Weaver): https://weaver.com/resources/strategic-priorities-in-the-2026-us-cyber-strategy-and-cybercrime-executive-order/

New InfoSec Tools (August 14, 2026): https://www.news4hackers.com/new-information-security-products-tools-released-this-week-august-14-2026

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — August 16, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-58231 (SAP Commerce Cloud, CVSS 10.0): Maximum-severity authentication bypass under active exploitation. All FCEB agencies should treat this as priority pat

 
 
 
Daily Cybersecurity Briefing — August 14, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-20349 (Cisco Secure Firewall ASA/FTD) — Heap Inspection vulnerability. Added to CISA KEV on August 11, 2026. FCEB agencies must remediate under BOD 26-04. C

 
 
 
Daily Cybersecurity Briefing — August 13, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-68820 (Windows Ancillary Function Driver for WinSock — Use-After-Free): Actively exploited in the wild by North Korean threat actors (Lazarus Group / Operat

 
 
 

Comments


Post: Blog2_Post
bottom of page