The 24-hour period from August 8-9, 2026 revealed a critical wave of router and IoT vulnerabilities alongside sustained ransomware activity targeting diverse sectors. Twenty critical-severity vulnerabilities were disclosed, predominantly affecting D-Link DWR-M961 routers (15 CVEs) and MSI networking devices, all enabling remote command injection with CVSS scores of 9.8. These flaws present immediate exploitation risks for threat actors conducting network compromise campaigns. Concurrently, Mirai and Mozi botnet infrastructure continued aggressive IoT device targeting through 49 malware distribution URLs, while ransomware groups victimized organizations ranging from healthcare technology firms to municipal governments. Two U.S. cities—Suisun and Coweta—suffered operational disruptions from cyberattacks affecting emergency services, with Coweta refusing ransom demands based on past reinfection experiences. The Brinks Home breach exposed 732,162 customer records including partial payment card data, representing the most significant credential exposure event of the period. Supply chain compromise continued as the Head Mare hacktivist group trojanized TrueConf video conferencing installers with backdoors.
A cluster of 20 critical-severity vulnerabilities were disclosed affecting consumer and enterprise network infrastructure, creating widespread remote code execution opportunities.
D-Link DWR-M961 routers with hardware version C1 contain 15 distinct command injection vulnerabilities across multiple CGI interfaces (app.cgi, formWsc, formL2tpv3ConfigSetup, formNtp, formPinManageSetup, formIMEISetup, formSmsManage, formUSSDSetup, diagnostic interfaces, and FOTA upgrade endpoints). Remote attackers can inject malicious commands through unsanitized parameters to achieve root-level code execution. Affected firmware versions prior to 1.1.5_C1_202607071108.
MSI Radix AXE6600 router firmware version v781521 contains command injection vulnerability in wps.cgi allowing remote attackers to execute arbitrary commands via unsanitized pin2g, pin5g, or pin6g parameters. CVSS 9.8.
Two buffer overflow vulnerabilities (CVE-2026-71958, CVE-2026-71957) in D-Link DWR-M961 quicksetup.cgi and app.cgi interfaces allow remote attackers to write overly long strings to various fields (test4, ssid2, username, netAcc.addlist[].name) and execute arbitrary commands. CVSS 9.8.
AI Copilot Content Generator plugin for WordPress (versions up to 1.5.6) fails to properly verify user authorization, allowing unauthenticated attackers to perform privileged actions. CVE-2026-14526, CVSS 9.8.
GIMP DDS file parser contains heap-based buffer overflow when processing crafted DirectDraw Surface files with mismatched D3D9 pixel format and bits-per-pixel declarations, leading to undersized buffer allocation and potential code execution. CVE-2026-42170, CVSS 7.8.
Flowise through version 3.1.4 contains SSRF vulnerability where the httpSecurity.ts SSRF guard omits Oracle Cloud (192.0.0.192) and Alibaba Cloud (100.100.100.200) metadata endpoints from DEFAULT_DENY_LIST, enabling authenticated attackers to access cloud instance metadata. CVE-2026-67620, CVSS 7.7.
Mirai and Mozi botnets maintained active malware distribution infrastructure with 49 malicious URLs delivering multi-architecture payloads targeting IoT devices.
Multiple domains (jam.cleverpondky.com, chaninami123123.duckdns.org) hosting Mirai ELF binaries compiled for diverse architectures including x86, ARM variants, MIPS, PPC, SH4, and M68K. Payloads named 'manji.*' targeting vulnerable routers and IoT devices for botnet recruitment.
Multiple IP addresses (60.17.89.214, 123.11.12.92, 125.41.9.22, 115.49.202.198) distributing Mozi botnet 32-bit MIPS ELF binaries via HTTP. Targeting unpatched routers and network devices for DDoS and proxy operations.
Distribution of sysorbit.apk from 94.154.43.244 - Android-targeting Mirai malware variant. Represents continued botnet expansion into mobile IoT devices.
Multiple FTP and TFTP URLs (41.216.189.236, 41.216.189.92, 91.92.42.213) distributing shell scripts (nz.sh, phantom.sh, phantom1.sh, phantom2.sh) for multi-stage malware delivery, likely part of automated exploitation frameworks.
Threat actors continue exploiting software distribution channels to deliver backdoored applications to end users.
Head Mare hacktivist group exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering backdoors. Supply chain attack targeting enterprise communication infrastructure, potentially affecting multiple organizations downloading compromised installers.
Multiple ransomware groups (Qilin, IncRansom, Everest, Storm) claimed nine new victims spanning healthcare, finance, real estate, and industrial sectors.
Everest ransomware group claimed attacks on Ingersoll Rand (industrial equipment manufacturer) and Omnicell (healthcare technology/medication management systems). High-profile targeting of critical infrastructure and healthcare supply chain organizations.
Storm ransomware group targeted United Group of Companies (real estate development/management) and Sawyer Savings Bank (150+ year community bank). Financial services sector remains high-value target for data exfiltration and extortion operations.
Qilin ransomware claimed four victims including Impact Centre Chrétien, Clausing (civil engineering), and CLLS Co Ltd. Diversified targeting across religious, construction, and logistics organizations suggests opportunistic victim selection.
Louisville Bar Association compromised by IncRansom group, potentially exposing legal professional data, member information, and sensitive legal communications. Professional associations represent high-value targets for credential and communication theft.
Two U.S. municipalities suffered significant operational disruptions from cyberattacks, with one impacting emergency services infrastructure.
Suisun City, California declared local emergency following cyberattack that disabled 911 dispatch system and other critical IT infrastructure at 5:45 AM on August 8. Malicious software infection compromised emergency services capabilities, representing significant public safety risk.
City of Coweta, following system-wide ransomware attack, refused to pay ransom demands. City manager cited previous experience with another municipality where payment led to reinfection weeks later, demonstrating ineffectiveness of ransom payment as recovery strategy.
Brinks Home suffered the most significant breach with 732,162 exposed records including partial payment card data following ShinyHunters extortion campaign.
ShinyHunters threat group targeted Brinks Home in 'pay or leak' extortion campaign, subsequently publishing 732,162 unique email addresses along with customer names, dates of birth, phone numbers, physical addresses, partial credit card data, and purchase history. Data includes leads, customers, and Brinks staff information.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.