top of page
Search

Daily Cybersecurity Briefing — August 19, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CVE-2026-33824 — Microsoft IKE Service Extensions Double Free Vulnerability: Critical RCE flaw in Windows Internet Key Exchange that allows unauthenticated remote code execution with no user interaction. Fixed in April 2026 Patch Tuesday. Added to CISA KEV on August 18, 2026. FCEB agencies must remediate per BOD 22-01.

  • CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability: Allows authentication bypass over a network connection. Fixed in July 2026 Patch Tuesday. Active exploitation began shortly after PoC release. Added to CISA KEV on August 18, 2026.

  • CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability: Added to CISA KEV on August 18, 2026 based on evidence of active exploitation in the wild.

  • CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability: Added to CISA KEV on August 18, 2026 based on evidence of active exploitation.

  • CVE-2026-18577 — N-able N-central Authentication Bypass (CVSS 8.2): Stems from incomplete patching of CVE-2026-18556. Allows unauthenticated attackers to bypass authentication and take over administrative accounts. CISA added to KEV August 3, 2026 with an emergency 72-hour FCEB patch deadline (due August 6). Fixed in N-central version 2026.3.1.7. Attackers used this to pivot to managed endpoints at customer sites.

  • August 11 KEV Batch — CISA added three additional CVEs: CVE-2026-20349 (Cisco Secure Firewall ASA/FTD Heap Inspection), CVE-2026-68820 (Windows Ancillary Function Driver for WinSock Use-After-Free), and CVE-2026-72898 (Metabase SQL Injection). All are actively exploited.

BREACHES

  • Heights Finance: Personal and financial data of over 1.2 million individuals exposed following compromise of a third-party cloud platform. Breach reported August 19, 2026.

  • Wesco (Global Supply Chain): Confirmed an active investigation into a cybersecurity incident on August 11, 2026, following data theft claims and public leakage by new extortion group ExfilSquad.

  • Questal: ShinyHunters ransomware group claimed theft of over 21 million Salesforce records and 147 GB of internal corporate data.

  • ProHealth Medical Group (Singapore): Krybit ransomware group claimed responsibility for a ransomware attack, asserting theft of over 114 GB of healthcare data.

THREATS & POLICY

  • ExfilSquad — New Data Extortion Group: Emerged July 26, 2026 targeting organizations across the US, UK, and Nigeria in sectors including technology, finance, government, education, and law enforcement. Group operates an onion-based Data Leak Site and threatens public exposure without deploying ransomware or encryption. Has claimed breaches of city governments, universities, and private companies. Skepticism about claim credibility was followed by release of data samples.

  • EtherHiding ClickFix Campaign: An active malware distribution campaign is leveraging a novel blockchain-based obfuscation technique called EtherHiding, using the Polygon blockchain to dynamically rotate C2 infrastructure and evade detection. CAPTCHA-style ClickFix lures deliver the payload while the true C2 domain is retrieved from an Ethereum smart contract.

  • FBI / NetNut Botnet Disruption (July 3, 2026): FBI and private sector partners disrupted NetNut, a criminal proxy network of approximately 2 million hijacked home devices used to route cybercrime operations.

  • 2026 US Cyber Strategy: Federal cybersecurity posture is shifting from 'defend and recover' to 'deter and disrupt.' A new executive order directs agencies to treat cybercrime organizations as transnational criminal networks and coordinate diplomatic, law enforcement, and technical tools against them. Lawmakers are also pushing to simplify fragmented cybersecurity regulatory requirements.

CLOUD & SAAS SECURITY

  • AI-Enhanced Attacks Ranked #2 Cloud Threat: The Cloud Security Alliance ranked AI-enhanced attacks as the second most significant cloud threat of 2026, with AI system compromise also entering top rankings. Organizations are being urged to implement Zero Trust architectures and cloud-native protection strategies.

  • AI-Powered Breach of Mexican Government Agencies: A breach spanning nine Mexican government agencies involved a single operator running AI coding tools in parallel, executing over 5,000 commands and exposing approximately 400 million records. The incident underscores the threat posed by agentic AI in adversarial hands.

  • Threema Messaging Service Hit by DDoS: Multiple DDoS attacks struck the Threema secure messaging platform earlier this week, causing severe communications disruptions. Attributed to deliberate targeting of privacy-focused infrastructure.

IDENTITY & AUTHENTICATION

  • StubMaker — RubyGems Typosquatting Campaign: 16 malicious RubyGems packages discovered August 15, 2026, by OpenSourceMalware. Packages mimic popular Ruby dependencies with subtle typos and deliver StubMaker, a Windows-based infostealer. Malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data. Published by two fake developer accounts ('mod8rz41mje' / 'rbq95bwt6q').

RESEARCH & TOOLS

  • Ghostjacking — AI Agent Prompt Injection Attack (DEF CON, August 9, 2026): Tenet Security revealed Ghostjacking, a technique embedding malicious instructions inside logs routinely read by AI coding agents (Cloudflare blocked-request logs, Datadog alerts, Sentry error reports). Demonstrated 90% success rate enabling DNS hijacking, cloud credential theft, backdoor creation, and firewall bypass — all without triggering alerts. Recommended mitigations: block outbound network access by default, require human approval before any agent executes a command, and prevent data an agent reads from becoming instructions it runs.

  • GhostApproval Flaw: A related vulnerability named GhostApproval was identified affecting six major AI coding assistants, enabling attackers to bypass approval workflows in agentic AI tools.

  • Cursor CLI Arbitrary Code Execution (Patched): Cursor fixed a vulnerability in its CLI coding agent that allowed a maliciously crafted cloned repository to execute arbitrary commands on a developer's machine before the user was prompted to approve trust — and even when sandboxing was explicitly enabled.

Sources

CISA Adds Four Known Exploited Vulnerabilities to Catalog (Aug 18): https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog

CISA Adds Exploited N-able N-central Flaw to KEV: https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html

SharePoint Vulnerability Exploited After PoC Release: https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw: https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html

Ghostjacking AI Agent Attack: https://cybersecuritynews.com/ghostjacking-attack/

ExfilSquad Dark Web Profile: https://socradar.io/blog/dark-web-profile-exfilsquad/

Wesco ExfilSquad Breach Investigation: https://www.rescana.com/post/wesco-cloud-crm-data-breach-exfilsquad-data-theft-and-supply-chain-risks-analyzed

16 Typosquatted RubyGems Packages Steal Browser Credentials: https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html

CVE-2026-33824 Windows IKE VPN Exploited: https://blog.gridinsoft.com/cve-2026-33824-windows-ike-vpn-exploit/

AI Security Failures Define the Week in August 2026: https://www.esecurityplanet.com/weekly-roundup/ai-security-failures-active-exploits-and-breaches-define-the-week-in-august-2026/

GhostApproval Flaw Hits Six Major AI Coding Assistants: https://www.infosecurity-magazine.com/news/ghostapproval-flaw-ai-coding/

2026 US Cyber Strategy and Cybercrime Executive Order: https://weaver.com/resources/strategic-priorities-in-the-2026-us-cyber-strategy-and-cybercrime-executive-order/

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — August 28, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-8452 — Citrix NetScaler ADC & Gateway (CVSS 8.8): Memory overflow vulnerability added to CISA KEV on August 26. FCEB agencies must patch by August 29, 2026.

 
 
 
Daily Cybersecurity Briefing — August 27, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-21962 (CVSS 10.0) — Oracle HTTP Server / WebLogic Server Proxy Plug-in Authentication Bypass. Unauthenticated attackers with network access can read or modi

 
 
 
Daily Cybersecurity Briefing — August 26, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Double Free Vulnerability. Added to CISA KEV catalog Aug 18, 2026. FCEB patch deadline applies. CVE-2026-55040

 
 
 

Comments


Post: Blog2_Post
bottom of page