Daily Cybersecurity Briefing — August 25, 2026
- Paul Baity
- 3 days ago
- 4 min read
ACTIVELY EXPLOITED VULNERABILITIES
CVE-2026-21962 (CVSS 10.0) | Oracle HTTP Server & WebLogic Server | Unauthenticated RCE via HTTP | Added to CISA KEV; FCEB agencies must patch by August 27, 2026
CVE-2026-68820 (CVSS 7.0) | Windows AFD.sys (WinSock) | Use-After-Free privilege escalation | Actively exploited by North Korea's Lazarus Group (Operation Dream Job) to gain SYSTEM access; patched in Microsoft August 2026 Patch Tuesday (398 flaws, 3 zero-days)
CVE-2026-19478 (CVSS 9.4) | GitLab CE/EE | GraphQL code injection | Unauthenticated delete/modify of public projects; exploited within days of disclosure; patched in GitLab 19.2.4, 19.1.6, 19.0.8, 18.11.11
CVE-2025-62593 | Anyscale Ray framework | DNS rebinding → browser-based RCE on developer systems | Added to CISA KEV; FCEB deadline August 20, 2026
CVE-2026-33824 | Microsoft IKE Service Extensions | Double Free | CISA KEV addition August 18, 2026
CVE-2026-55040 | Microsoft SharePoint | Weak Authentication | CISA KEV addition August 18, 2026
CVE-2026-59310 | Broadcom VMware vCenter | Path Traversal | CISA KEV addition August 18, 2026
CVE-2026-65400 | Apple macOS | Improper Authentication | CISA KEV addition August 18, 2026
CVE-2026-72529 & CVE-2026-72530 | TrueConf Server | Missing Authentication & Code Injection | CISA KEV additions August 20, 2026
Microsoft Entra ID | CVSS 10.0 | Remote Code Execution | Critical patch issued in August 2026 Patch Tuesday
BREACHES
Motorenmaier GmbH (Germany) | Qilin ransomware | Confirmed August 16, 2026 | ~162,000 files exfiltrated; group threatens to publish data unless ransom paid
Stripe API Key Leak | 659 merchant accounts exposed via live secret keys posted to data-trading forum (August 18, 2026) | ~35 GB of customer and payment data accessible; attackers can read records, create charges, redirect payouts
THREATS & POLICY
Lazarus Group (DPRK) | Operation Dream Job | Targeting defense, aerospace, and aviation in Europe and India via fake recruiter PDF lures | Deploys Troy backdoor + FudModule 3.1 rootkit (newly bypasses Windows Smart App Control) via CVE-2026-68820
Operation QUICSILVER | Suspected state-nexus espionage targeting Myanmar government and IT sectors | QUICAgent Go backdoor delivered via graduation ceremony lure documents
AI-Powered PLC Attacks | U.S. government warning: threat actors using AI-generated exploit scripts targeting Siemens S7 Series PLCs in critical infrastructure | Scripts disguised as legitimate monitoring tools
14 Trojanized npm Packages | Masquerade as calendar/streak utilities | Deliver RedC2 4.0: AI-powered Linux implant with surveillance, credential theft, payload loading, and mass-operation capabilities
CLOUD & SAAS SECURITY
Stripe Secret Key Exposure | 659 live merchant API keys published on data-trading forum August 18, 2026 | ~35 GB customer/payment data exposed; highlights secret scanning gaps in developer pipelines
SpyCloud 2026 Identity Exposure Report: 8.6 billion stolen cookies and session artifacts recaptured from malware infections | Session hijacking has become the dominant cloud access vector, bypassing MFA entirely
Google Cloud Threat Horizons H1 2026: Stolen credentials drive ~40% of cloud breaches; dwell times can exceed 200 days before detection | Zero-trust adoption accelerating as complexity gap widens
IDENTITY & AUTHENTICATION
SpyCloud 2026: 8.6 billion stolen session cookies recaptured — session hijacking now surpassing password-based attacks as the top cloud identity threat
Cloud Security Alliance: 79% of IT and security professionals feel ill-equipped to defend against non-human identity (NHI) attacks — bots, API credentials, and service accounts remain poorly governed
CISA KEV (August 18): CVE-2026-55040 (Microsoft SharePoint Weak Authentication) and CVE-2026-65400 (Apple macOS Improper Authentication) added to catalog
MOBILE SECURITY
Apple Mercenary Spyware Alerts | Notifications sent to users in 110 countries (150+ cumulative) warning of possible targeting by commercial spyware — device compromise may occur without user interaction
Manic Android Malware | Combines banking fraud and surveillance with a novel Wi-Fi mesh exfiltration technique | Infected devices relay stolen data through nearby compromised phones even when the target device is offline; distributed via phishing/dropper apps
ToxicPanda (Evolved) | Now targets 349 applications and supports 167 remote commands — significantly expanded attack surface from previous versions
Android Car Head Unit Malware (Kaspersky, June 2026) | DoFun updater abuse delivers JarService dropper enabling ad fraud and proxy botnet creation in connected vehicles
RESEARCH & TOOLS
Microsoft August 2026 Patch Tuesday | 398+ vulnerabilities patched including 3 zero-days | FudModule 3.1 rootkit analysis reveals new technique bypassing Windows Smart App Control — highest monthly patch volume on record
RedC2 4.0 AI-Powered Linux Implant | Found in 14 trojanized npm packages | AI-assisted evasion with surveillance, credential theft, and mass-operation capabilities — signals maturation of AI-assisted malware
Kimwolf v7 Android Botnet (Palo Alto Networks Unit 42) | HTTP/2 DDoS flood module constructs complete browser fingerprints | Makes malicious traffic indistinguishable from legitimate browsing — complicates detection and blocking
Sources
CISA KEV Additions August 18, 2026: https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog
CISA KEV Additions August 20, 2026: https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog
Oracle WebLogic Actively Exploited Flaw (THN): https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html
CISA Flags Ray Framework Flaw (THN): https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html
Lazarus Exploits Windows Zero-Day (THN): https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Lazarus Windows Zero-Day (BleepingComputer): https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/
Microsoft August 2026 Patch Tuesday (BleepingComputer): https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
GitLab CVE-2026-19478 Active Exploitation (THN): https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
Weekly Recap — AI PLC Attacks, GitLab, Stripe Leaks (THN): https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html
Manic Android Malware (THN): https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html
Apple Mercenary Spyware Alerts 110 Countries (THN): https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html
Microsoft Entra ID CVSS 10.0 RCE Flaw (THN): https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
SpyCloud 2026 Identity Exposure Report: https://spycloud.com/blog/2026-annual-identity-exposure-report/
Google Cloud Threat Horizons H1 2026: https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026
CISA KEV This Week (Senserva): https://senserva.com/exploited-this-week.html
Recent Data Breaches 2026 (Bright Defense): https://www.brightdefense.com/resources/recent-data-breaches/

Comments