Daily Cybersecurity Briefing — August 18, 2026
- Paul Baity
- Aug 18
- 4 min read
ACTIVELY EXPLOITED VULNERABILITIES
CISA KEV (Aug 11): CVE-2026-20349 — Cisco Secure Firewall ASA/FTD Heap Inspection vulnerability; CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free LPE (FCEB patch deadline: August 25, 2026); CVE-2026-72898 — Metabase SQL Injection vulnerability. All three have confirmed active exploitation.
CISA KEV (Aug 3): CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate Path or Channel vulnerability added based on active exploitation evidence.
CVE-2026-19478 (CVSS 9.4) — GitLab CE/EE critical unauthenticated GraphQL vulnerability allowing remote modification or deletion of public projects and user data; CISA added to KEV catalog. Patch immediately.
Ray Framework (AI/ML distributed computing) — Critical flaw added to CISA KEV catalog with evidence of active exploitation. Ray is widely used to scale AI and machine learning workloads.
ShieldBreak PoC published claiming a Microsoft Defender patch bypass yielding SYSTEM-level access — under vendor investigation. Do not assume patched Defender instances are fully protected until confirmed by Microsoft.
August 2026 Patch Tuesday: Microsoft addressed 421 CVEs, including one zero-day under active exploitation. Prioritize updates for Windows, Defender, and WinSock components.
BREACHES
SafePal Hardware Wallet: Authorization flaw in an order-tracking plugin exposed names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.
Heights Finance: Data breach confirmed impacting at least 1.2 million individuals. Nature of compromised data has not been fully disclosed.
Azure Tenants: A hacker claims to have stolen millions of records from corporate Azure tenants, including PII. Verification ongoing; 4.9 million Salesforce records reportedly compromised after ransom negotiations failed.
France Finance Ministry (Aug 14): Attackers used stolen staff credentials to access and copy tax and property data on 678,000 individuals and businesses.
Eva AI Limited (Aug 17): Listed on the Direwolf ransomware leak site; group claims to have stolen internal data. Details on scope pending.
Questal / ShinyHunters: Ransomware group claims theft of 21 million Salesforce records, including PII, totaling 147 GB of internal corporate data.
THREATS & POLICY
Octagon Android Bot: New malware uses hidden VNC and accessibility overlay techniques to steal cryptocurrency wallet credentials from victims' mobile devices.
AI-Assisted Theft: Threat actors are now using AI tools to rapidly identify and prioritize high-value files for exfiltration, increasing efficiency of data theft campaigns.
US Cyber Policy (2026): The Trump Administration released 'President Trump's Cyber Strategy for America' and an Executive Order on Combating Cybercrime, directing federal agencies to treat cybercrime organizations as transnational criminal networks and authorizing greater latitude for private sector offensive cyber operations. Public-private confidence showing signs of strain due to agency politicization.
AI Hallucination Risk: The Solicitors Regulation Authority issued a warning about AI hallucinations leading to data leaks and professional liability exposure in legal and regulated industries.
CLOUD & SAAS SECURITY
Google Cloud H1 2026 Threat Horizons Report: Identity issues were involved in 83% of cloud and SaaS compromises — highlighting the need for MFA enforcement, least-privilege access, and continuous identity monitoring.
Misconfiguration Dominance: 95% of cloud security failures still stem from misconfigurations — misconfigured storage buckets, exposed APIs, excessive permissions, and insecure network settings remain the leading causes.
AI Agents as SaaS Risk: Cloud Security Alliance ranks AI-enhanced attacks #2 in 2026 cloud threats. AI agents operating autonomously within SaaS environments are emerging as a new governance blind spot; employees routinely exposing sensitive company data to AI platforms.
A hollowed-out data governance layer is leaving CISOs flying blind into AI-driven attacks, with visibility gaps in SaaS telemetry preventing timely detection.
IDENTITY & AUTHENTICATION
Device Code Phishing Surge: Attacks exploiting OAuth 2.0 device authorization grants are up 1,500% — Huntress tracked a 1,380% spike in early 2026. Victims authenticate on genuine Microsoft pages, satisfying MFA, while session tokens are hijacked by attackers.
EvilTokens PhaaS: The first turnkey device-code phishing-as-a-service kit launched Feb 2026 via Telegram bots. By March, researchers tracked 1,000+ domains hosting EvilTokens pages.
Infostealer Scale: 8.6 billion session cookies were recaptured from 13.2 million infostealer infections in 2025; 40% of those infections occurred on endpoints already running EDR or antivirus solutions.
CISA Guidance: FIDO-based (phishing-resistant) authentication is recommended as the strongest defense against device code phishing and other MFA bypass techniques.
MOBILE SECURITY
Octagon Android Bot: Malware leverages hidden VNC (Virtual Network Computing) and Android accessibility service overlays to intercept and steal cryptocurrency wallet credentials from infected devices.
Android Kernel Exploit via VoLTE (Aug 17): SSD Secure Disclosure published a two-stage exploit chain achieving full Android kernel access through a VoLTE (Voice over LTE) video call — no user interaction required beyond answering a call.
RESEARCH & TOOLS
Google HEIR (Open Source): Google released HEIR (Homomorphic Encryption IR), an open-source tool enabling AI models to perform computation on encrypted data without ever decrypting it — a potential breakthrough for privacy-preserving machine learning.
ShieldBreak PoC: A public proof-of-concept claims to bypass a patched Microsoft Defender vulnerability, yielding SYSTEM-level access. Security teams should monitor vendor advisories closely while Microsoft investigates.
CVE Volume Surge: 1,877 new CVEs were tracked during the week of August 3–9, with six already under active exploitation — reinforcing the rapid PoC-to-exploitation timeline now measured in hours.
Android VoLTE Exploit Chain: SSD Secure Disclosure released a two-stage kernel exploit triggered via VoLTE video call, underscoring that zero-click and near-zero-interaction mobile attack surfaces remain active.
Sources
The Hacker News — https://thehackernews.com/
CISA KEV Alert (Aug 11) — https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
Senserva KEV Tracker — https://senserva.com/exploited-this-week.html
SecurityWeek — August 2026 Patch Tuesday — https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
SharkStriker — August 2026 Data Breaches — https://sharkstriker.com/blog/august-2026-data-breaches/
Dark Reading — Device Code Phishing Up 1,500% — https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles
Google Cloud Threat Horizons H1 2026 — https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026
Security Boulevard — Cloud Misconfigurations 2026 — https://securityboulevard.com/2026/08/why-cloud-misconfigurations-continue-to-cause-data-breaches-in-2026/
Security Online — Weekly CVE Report August 2026 — https://securityonline.info/weekly-cve-report-august-2026/
The Hacker News — ShieldBreak PoC — https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
IT Security News Hourly Summary Aug 18 — https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-08-18-00h-6-posts
Weaver — 2026 US Cyber Strategy — https://weaver.com/resources/strategic-priorities-in-the-2026-us-cyber-strategy-and-cybercrime-executive-order/

Comments