top of page
Search

Daily Cybersecurity Briefing — August 16, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CVE-2026-58231 (SAP Commerce Cloud, CVSS 10.0): Maximum-severity authentication bypass under active exploitation. All FCEB agencies should treat this as priority patching.

  • CVE-2026-65400 (Apple macOS Screen Sharing, CVSS 9.8): Critical authentication flaw actively exploited in the wild to deploy cryptocurrency miners. Apple patches available.

  • CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock, Use-After-Free): Added to CISA KEV catalog August 11. Actively exploited — CrowdStrike and Microsoft recommend prioritizing this patch from August Patch Tuesday.

  • CVE-2026-20349 (Cisco Secure Firewall ASA/FTD, Heap Inspection Vulnerability): Added to CISA KEV catalog August 11. FCEB patch deadline applies.

  • CVE-2026-72898 (Metabase, SQL Injection): Added to CISA KEV catalog August 11.

  • CVE-2026-18577 (N-able N-central, Authentication Bypass): Added to CISA KEV catalog August 3.

  • GeoServer Zero-Day (SQL Injection/RCE): Disclosed August 12 by researcher @q1uf3ng. Attackers rapidly expanded exploitation to SAP Commerce Cloud, VMware vCenter, Adobe Commerce, and WordPress 7.0.4 shortly after disclosure.

  • Microsoft August 2026 Patch Tuesday (August 12): 421 CVEs patched; 62 critical; one actively exploited zero-day (CVE-2026-68820). LegacyHive Windows zero-day also patched. Key risk categories: Elevation of Privilege (42%), Remote Code Execution (26%).

BREACHES

  • RingCentral (1.6M accounts): ShinyHunters hacked RingCentral via social engineering in July, stealing 623GB of data. After the company refused to pay ransom, threat actors leaked 280GB on their dark web site August 13–14. Exposed data includes email addresses, names, phone numbers, and physical addresses. Have I Been Pwned has been updated.

  • Questal: ShinyHunters claimed theft of over 21 million Salesforce records including PII, plus 147GB of internal corporate data.

  • ProHealth Medical Group: Krybit ransomware group claimed a ransomware attack and theft of over 114GB of healthcare data.

  • Morguard (Canada): Helix ransomware group announced a cyberattack against this major Canadian real estate firm on August 7.

THREATS & POLICY

  • CISA released advisory AA26-222a on Gunra Ransomware, providing indicators of compromise (IOCs) and TTPs to help defenders detect and respond to this emerging ransomware group.

  • Apple issued new Threat Notification alerts to additional iPhone users tied to ongoing mercenary spyware operations (Pegasus-style), where zero-click exploits target iMessage and WhatsApp to gain full device access.

  • FBI (July 3): Disrupted NetNut, a botnet of approximately 2 million hijacked home devices used to route cybercrime traffic, in coordination with private sector partners.

  • Scattered Spider: A 19-year-old member was extradited to the U.S. and now awaits sentencing for cybercrime charges.

  • Sen. Ron Wyden urged OMB, CISA, and NIST to lead a campaign to purge legacy internet-accessible VPNs from federal agencies, citing ongoing risk from unpatched and outdated infrastructure.

CLOUD & SAAS SECURITY

  • Google Cloud released its H1 2026 Threat Horizons Report, documenting AI-powered automated cloud attacks that operate at speeds exceeding human response capabilities.

  • 95% of cloud security failures still stem from misconfiguration (human error), not platform vulnerabilities. Organizations average 43 misconfigurations per cloud account.

  • Generative AI integration across SaaS platforms is creating new security blind spots — internal AI agents frequently operate without proper access controls, monitoring, or isolation.

  • The window between cloud deployment and first attack has shrunk to hours. Security Boulevard analysis confirms continuous automated validation is now required for all cloud environments.

IDENTITY & AUTHENTICATION

  • Three new passkey attack techniques disclosed at Black Hat USA 2026 (The Hacker News): (1) Windows event log signature replay, (2) Chrome memory extraction of synced private keys, (3) session reuse exploiting Windows Hello keys in already-compromised sessions. These defeat "phishing-resistant" MFA without breaking cryptography.

  • Microsoft Entra ID MFA Changes: Starting September 1, 2026, users enrolled in SMS or voice MFA will be automatically enabled for passkeys. Microsoft-provided SMS and voice delivery is scheduled to retire February 1, 2027.

  • MFA fatigue attacks rose 217% year-over-year per the 2025 Verizon DBIR. Push-notification MFA is increasingly considered a liability in high-risk environments.

MOBILE SECURITY

  • Android Security Bulletin for August 2026 published — multiple critical patches available for Android devices. Users and MDM administrators should prioritize updates.

  • Apple Threat Notifications: New alerts sent to iPhone users targeted by mercenary spyware campaigns. Pegasus-style zero-click exploits continue to target iMessage and WhatsApp without any user interaction required.

  • 34 active Android banking malware families now targeting 1,243 financial institutions across 90 countries. Spyware detections are up 51% year-over-year, with much targeting mobile devices for credential theft and surveillance.

  • Jamf Threat Labs: More than half of organizations have at least one device currently exposed to known exploit chains.

RESEARCH & TOOLS

  • ShieldBreak PoC (The Hacker News): Published proof-of-concept claims a full patch bypass for CVE-2026-50656 (RoguePlanet), enabling SYSTEM-level access despite Microsoft's most recent patch. Under active analysis by the security community.

  • CVE-2026-50522 (SharePoint Server, Critical Deserialization): Active exploitation began within hours of public PoC disclosure — a reminder that PoC publication timelines now directly compress the patching window.

  • Weekly Vulnerability Volume: 1,782 new CVEs tracked last week; 282+ have public PoC exploits available, significantly elevating real-world exploitation probability.

Sources

https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html

https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026/

https://blog.qualys.com/vulnerabilities-threat-research/patch-tuesday/2026/08/11/microsoft-patch-tuesday-august-2026-security-update-review

https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/

https://www.techtimes.com/articles/324576/20260815/ringcentral-was-hacked-phone-call-16m-users-contact-details-now-arm-vishing-attacks.htm

https://source.android.com/docs/security/bulletin/2026/2026-08-01

https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026

https://senserva.com/exploited-this-week.html

https://www.esecurityplanet.com/weekly-roundup/ai-security-failures-active-exploits-and-breaches-define-the-week-in-august-2026/

https://securityboulevard.com/2026/08/why-cloud-misconfigurations-continue-to-cause-data-breach-in-2026/

https://workos.com/blog/how-attackers-are-bypassing-mfa-using-ai-in-2026

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — August 15, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-58231 | SAP Commerce Cloud | CVSS 10.0 | Maximum-severity RCE vulnerability under active exploitation. Organizations should apply SAP patches immediately. C

 
 
 
Daily Cybersecurity Briefing — August 14, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-20349 (Cisco Secure Firewall ASA/FTD) — Heap Inspection vulnerability. Added to CISA KEV on August 11, 2026. FCEB agencies must remediate under BOD 26-04. C

 
 
 
Daily Cybersecurity Briefing — August 13, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-68820 (Windows Ancillary Function Driver for WinSock — Use-After-Free): Actively exploited in the wild by North Korean threat actors (Lazarus Group / Operat

 
 
 

Comments


Post: Blog2_Post
bottom of page