top of page
Search

Daily Cybersecurity Briefing — August 26, 2026

ACTIVELY EXPLOITED VULNERABILITIES

  • CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Double Free Vulnerability. Added to CISA KEV catalog Aug 18, 2026. FCEB patch deadline applies.

  • CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability. Added to CISA KEV Aug 18, 2026. Two chained SharePoint flaws enable unauthenticated remote code execution on vulnerable servers.

  • CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability. Added to CISA KEV Aug 18, 2026.

  • CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability. Added to CISA KEV Aug 18, 2026.

  • CVE-2026-72529 & CVE-2026-72530 — TrueConf Server Missing Authentication and Code Injection. Both added to CISA KEV Aug 20, 2026.

  • Google Chrome 152 released for Windows, macOS, and Linux with 327 security fixes, including 10 critical vulnerabilities. Update immediately.

  • OpenSSL flaws allow remote attackers to crash servers with malformed packets — patch urgently.

BREACHES

  • Questal — ShinyHunters ransomware group claimed theft of 21M+ Salesforce records (PII) and 147 GB of internal corporate data.

  • The Butcher Brothers — Play ransomware group listed the organization on its public leak site; scope of exfiltrated data under investigation.

  • ProHealth Medical Group (Singapore) — Krybit ransomware group claimed theft of 114 GB of healthcare data.

  • Hyundai Motor Türkiye — Cyber attack claimed by CRPx0 ransomware group; data exposure scope unknown.

  • Developer Credential Exposure — A routine development mistake exposed thousands of software repositories containing sensitive credentials and financial information.

THREATS & POLICY

  • Operation Jackal — Law enforcement executed 58 arrests dismantling the money laundering network behind global scams.

  • CaptiveCrunch Campaign — Russia-linked Storm-2945 (Midnight Blizzard) compromised hotel and conference captive portals to distribute CornFlake and ChocoShell malware.

  • CoreRAT — New remote access trojan discovered giving threat actors full system control capabilities.

  • Amatera Stealer — Malware hidden inside plain English words targets Windows users; evades traditional signature-based detection.

  • CVE Volume — 3,976 new vulnerabilities logged in the single week of Aug 10–16, 2026.

CLOUD & SAAS SECURITY

  • AI Gateway Supply Chain Breach — A supply chain attack through a popular AI gateway library exposed cloud credentials, SSH keys, and Kubernetes tokens across 2,500+ organizations and ~434,000 CI/CD pipelines. Described by CloudSEK as the largest AI infrastructure supply chain breach of 2026.

  • IAM Misconfiguration Crisis — Weak IAM configurations affect up to 98% of cloud environments per Intruder/Help Net Security report.

  • CSA 2026 Cloud Threat List — Identity and AI-related threats now top the Cloud Security Alliance's annual rankings for the first time; AI lowers the barrier for sophisticated offensive capabilities while accelerating scanning and exploit development.

  • Gen AI SaaS Blind Spots — Integration of generative AI across SaaS ecosystems has created new security blind spots that many organizations remain unprepared to address.

IDENTITY & AUTHENTICATION

  • Pass-the-Passkey — SpecterOps researchers presented 20+ attack techniques at Black Hat USA (Aug 5, 2026) targeting Windows 11, Microsoft Entra ID, web browsers, password managers, and enterprise auth workflows. As of Aug 10, Microsoft Entra still uses JWTs as WebAuthn challenges rather than pseudorandom nonces.

  • MFA Fatigue Surge — MFA fatigue attacks rose 217% year-over-year (2025 Verizon DBIR); push-notification MFA is a growing liability in high-risk environments.

  • AiTM Phishing Continues — Adversary-in-the-middle proxies bypass push MFA, TOTP, and SMS OTP at scale; FIDO2 hardware keys and origin-bound passkeys remain resistant.

  • Fake Apple Support AI Calls — Social engineering campaign uses AI-generated calls to target stolen-device owners for device passcodes and 2FA codes.

MOBILE SECURITY

  • Manic Android Malware — Targets 169 apps and can relay exfiltrated data through nearby infected devices even when the source phone is offline.

  • Android Security Bulletin August 2026 — Google released monthly patches addressing multiple critical device vulnerabilities.

  • Sideload Threat Scale — Google Play Protect identified 27M+ malicious sideloaded apps in 2025 (up from 13M in 2024); 34 active banking malware families target 1,243 financial institutions across 90 countries.

RESEARCH & TOOLS

  • SkillSpector (NVIDIA) — Open-source scanner that reads an AI agent skill (directory, zip, SKILL.md, or Git URL) and returns a risk score, findings list, and recommendations. Released August 2026.

  • Future AGI — Open-source (Apache 2.0, self-hostable) platform for tracing, evaluating, simulating, and guardrailing LLM agents.

  • HOL Guard — Open-source antivirus tailored specifically for AI agents; released August 2026.

  • ShieldBreak PoC — Proof-of-concept exploit for Microsoft Defender Malware Protection Engine local privilege escalation (CVE-2026-50656 / RoguePlanet) released ~2.5 hours after Patch Tuesday; affects fully patched Windows 11 25H2 and Windows Server 2025.

  • Friendly Fire (AI Now Institute) — PoC demonstrating hijacking of defensive cyber AI agents for remote code execution. Full reproduction files available on GitHub.

Sources

https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog

https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog

https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html

https://sharkstriker.com/blog/august-2026-data-breaches/

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/

https://shattered.io/cloud-iam-misconfiguration-litellm-breach-2026/

https://virtualizationreview.com/articles/2026/08/24/identity-ai-lead-csas-2026-cloud-threat-list.aspx

https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

https://compliancehub.wiki/pass-the-passkey-entra-id-phishing-resistant-mfa-compliance-2026/

https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html

https://source.android.com/docs/security/bulletin/2026/2026-08-01

https://www.helpnetsecurity.com/2026/08/26/hottest-cybersecurity-open-source-tools-august-2026/

https://ainowinstitute.org/publications/friendly-fire-exploit-brief

https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026/

 
 
 

Recent Posts

See All
Daily Cybersecurity Briefing — August 28, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-8452 — Citrix NetScaler ADC & Gateway (CVSS 8.8): Memory overflow vulnerability added to CISA KEV on August 26. FCEB agencies must patch by August 29, 2026.

 
 
 
Daily Cybersecurity Briefing — August 27, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-21962 (CVSS 10.0) — Oracle HTTP Server / WebLogic Server Proxy Plug-in Authentication Bypass. Unauthenticated attackers with network access can read or modi

 
 
 
Daily Cybersecurity Briefing — August 25, 2026

ACTIVELY EXPLOITED VULNERABILITIES CVE-2026-21962 (CVSS 10.0) | Oracle HTTP Server & WebLogic Server | Unauthenticated RCE via HTTP | Added to CISA KEV; FCEB agencies must patch by August 27, 2026 CVE

 
 
 

Comments


Post: Blog2_Post
bottom of page