The 48-hour period from August 2-3, 2026 revealed critical vulnerabilities across multiple platforms and significant data breach activity. Most notably, three major organizations face imminent data exposure from ShinyHunters ransomware group, with combined exposure affecting over 27 million Salesforce records containing PII. Critical authentication bypass vulnerabilities were disclosed in WordPress plugins (CVE-2026-8457, CVSS 9.8) and PyAthena (CVE-2026-65321, CVSS 9.8), alongside a critical FreeRDP heap overflow (CVE-2026-68579, CVSS 9.6). A hardware wallet RNG flaw resulted in an $88.6 million Bitcoin theft affecting thousands of COLDCARD users. Malware infrastructure activity remains dominated by Mozi and Mirai botnets with 50 new malware distribution URLs identified. The VPN industry faced scrutiny after NotVPN/SplitVPN was found maintaining 58 million connection logs despite "no-logs" claims, exposing fundamental trust issues in the privacy sector.
Immediate action is required for organizations using WooCommerce Social Login plugin, PyAthena, FreeRDP, ArcadeDB, or Better Auth, as publicly disclosed vulnerabilities enable authentication bypass and remote code execution. The ShinyHunters extortion campaign against Alcon, Questel, and Lumenis represents a coordinated attack with a August 4, 2026 disclosure deadline. Security teams should review Salesforce environment security posture and validate data access controls. The COLDCARD incident underscores hardware security module validation requirements for cryptocurrency operations.
Multiple critical-severity vulnerabilities disclosed across web applications, authentication systems, and remote desktop protocols enabling authentication bypass and remote code execution
WordPress WooCommerce Social Login plugin versions ≤2.8.7 accept Apple id_tokens without verifying JWT signatures against Apple's public keys, allowing attackers to forge tokens and authenticate as arbitrary users by crafting base64-encoded payloads with target user identifiers.
PyAthena versions prior to 3.35.4 contain SQL injection vulnerability in DefaultParameterFormatter.format() due to improper quote-escaping in DELETE and CTAS statements. The _escape_hive function uses backslash-escaping for single quotes, incompatible with AWS Athena's quote-doubling standard, enabling unauthenticated arbitrary SQL execution.
FreeRDP versions ≤3.29.0 contain heap-based buffer overflow in Windows clipboard client's CliprdrStream_Read function. When OLE paste consumers call IStream::Read with fixed-size buffers, the function requests file data from RDP server without size validation, enabling attackers to overflow client heap memory via malicious RDP servers.
Vikunja versions 0.22.0-2.3.0 fail to validate principal type in API token management. User IDs and link-share IDs use independent numeric sequences resolved through generic web.Auth.GetID() interface, allowing link-share JWTs with IDs matching target user IDs to be treated as user authentication tokens, enabling privilege escalation.
ArcadeDB versions before 26.7.3 bind LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers executing JavaScript to create server-wide admin users.
Better Auth versions prior to 1.4.5 use rou3 router library that normalizes paths by removing empty segments, causing /path, //path, and ///path to resolve identically. Attackers can bypass security middleware by crafting double-slash paths that evade route-specific protections while still reaching target endpoints.
User Access Manager plugin for WordPress versions ≤2.3.15 vulnerable to directory traversal via 'uamgetfile' parameter, enabling unauthenticated attackers to read arbitrary files on server including configuration files and sensitive data.
CubeWP Framework plugin for WordPress versions ≤1.1.30 contains directory traversal vulnerability in 'cubewp_get_svg_content' function, allowing unauthenticated attackers to read arbitrary server files containing sensitive information.
ArcadeDB versions before 26.7.3 fail to bind authenticated principal in MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL operations, schema mutations, and execute arbitrary JavaScript code.
ArcadeDB versions before 26.7.3 leak arcadedb.ha.clusterToken in cleartext via MCP get_server_settings tool. Attackers with MCP access can retrieve cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate arbitrary users across cluster.
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in audio input redirection channel across ALSA, sndio, WinMM, and OpenSL ES backends. Malicious RDP servers can supply crafted FramesPerPacket values causing allocation size miscalculation and memory corruption.
better-auth passkey versions before 1.4.0 contain insecure direct object reference vulnerability in passkey deletion endpoint allowing authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can enumerate and delete other users' passkeys via crafted requests.
OCPP 1.6 client in subsys/net/lib/ocpp parses inbound WAMP RPC frames using extract_string_field() which copies uid and action fields with strncpy() then scans with strlen(). Missing null-terminator validation enables buffer overflow when processing malicious OCPP server responses.
Active ransomware campaigns targeting multiple organizations with imminent data exposure deadlines, plus significant VPN provider breach exposing 58 million connection logs
Over 25 million Salesforce records containing PII stolen from Alcon Inc. (alcon.com), a major medical device company. ShinyHunters ransomware group issued final warning with August 4, 2026 deadline before public leak and additional digital disruption. Salesforce environment breach represents significant customer and employee data exposure.
Over 21 million Salesforce records containing PII and 147GB+ of internal corporate data stolen from Questel SAS (questel.com), an intellectual property services company. ShinyHunters group set August 4, 2026 deadline for ransom payment before leak. Breach includes both customer PII and sensitive corporate information.
Over 1.1 million records containing customer/employee PII and 176GB+ of internal corporate data stolen from Lumenis Ltd. (lumenis.com), a medical laser and light-based technology company. ShinyHunters ransomware group issued final warning with August 4, 2026 deadline before public data release.
Russian VPN provider SplitVPN (formerly NotVPN) advertised strict "no-logs" policy but maintained 17GB SQL database containing 58 million connection logs with user activity data. Database leaked on Altenen cybercrime forum following breach. MysteriumVPN research reveals fundamental breach of privacy commitments, exposing VPN users' connection metadata and activity patterns.
Brinks Home, one of North America's largest residential security providers, confirmed IT systems breach after ShinyHunters extortion group claimed responsibility for stealing nearly 5 million records tied to the company's Salesforce environment. Breach affects major home security provider's customer database.
CRPxO ransomware group leaked 700GB of data from Encore Enterprises, Inc. (encore.bz), a commercial real estate company. Significant data volume suggests comprehensive compromise of corporate systems including potentially sensitive real estate transaction data and client information.
Qilin ransomware group compromised Mairie de Drancy (www.drancy.fr), the municipal government of Drancy, France. Attack represents targeting of local government infrastructure, potentially affecting citizen services and municipal data including resident information and government operations.
Qilin ransomware group compromised Wire Products (www.wireproducts.us), a manufacturing company. Attack on industrial sector organization likely involves operational technology systems and manufacturing data exposure.
Sumner County Schools (Tennessee) reported network breach forcing district to delay start of 2026-27 school year. District continues investigating breach impact on student and staff data. Educational institution breach represents potential exposure of student records, staff information, and administrative systems.
Krybit ransomware group claimed multiple victims including DC Partner payment distribution agency (South Africa), ASA Nigeria microfinance bank, Municipality of Rinxent (France), Country Motors Mexico dealership, Buzz Trading manufacturing (South Africa), and Moses & Singer law firm. Coordinated campaign targeting diverse sectors across multiple countries.
Widespread Mozi and Mirai botnet activity with 50 new malware distribution URLs identified, primarily targeting IoT devices through compromised infrastructure in China
URLhaus identified 32 active Mozi botnet malware distribution URLs across compromised IoT devices and web servers, primarily located in Chinese IP space. Distribution servers hosting bin.sh and binary payloads for IoT device compromise. Indicators suggest continued expansion of Mozi peer-to-peer botnet infrastructure.
URLhaus detected 18 active Mirai botnet malware distribution URLs hosting malicious payloads targeting IoT devices. Campaign includes distribution of bin.sh scripts and compiled binaries from compromised infrastructure. Geographic distribution spans Chinese IP space with additional infrastructure in Russia and other regions.
Major cryptocurrency theft attributed to hardware wallet vulnerability, highlighting supply chain and cryptographic implementation risks
Vulnerability in COLDCARD hardware wallet firmware's random number generator (RNG) enabled attackers to steal estimated $88.6 million in Bitcoin from thousands of wallets. Flawed RNG implementation allowed seed generation prediction, compromising fundamental cryptographic security of hardware wallets. Incident represents significant supply chain security failure affecting cryptocurrency cold storage security model.
Google Chrome developing new security features to prevent malicious extension behavior and protect user browsing experience
Google preparing new Chrome security feature to block policy-installed extensions from hijacking New Tab page or changing default search engine. Enhancement targets enterprise-deployed malicious extensions that bypass user consent to modify browser behavior. Feature represents browser vendor response to extension-based browser hijacking techniques commonly used in enterprise environments.
OpenAI revealed Astra, unreleased AI model designed for complex long-running tasks, after internal version produced ten significant advances in mathematics and theoretical computer science. While not directly security-related, advanced AI capabilities have implications for both offensive security research automation and defensive threat analysis.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.