The period of August 11-12, 2026 saw significant cybersecurity activity across multiple threat domains. Microsoft released an exceptionally large Patch Tuesday update addressing nearly 400 vulnerabilities including three zero-days—one actively exploited. Critical infrastructure remains under persistent attack, with the Gunra ransomware gang exploiting Fortinet vulnerabilities and bypassing MFA, while CISA confirmed Microsoft SharePoint flaws are now being weaponized in ransomware campaigns. The threat landscape shows concerning sophistication: DeadLock ransomware now uses blockchain-backed infrastructure to resist takedowns, Sandworm APT deployed trojanized WireGuard VPN clients targeting IT professionals, and multiple critical authentication bypass vulnerabilities were disclosed affecting Mira healthcare devices (CVSS 9.8) and various enterprise platforms. Ransomware activity surged with 21 new victim disclosures across multiple groups targeting healthcare, construction, manufacturing, and professional services sectors globally.
Microsoft's massive August Patch Tuesday and critical zero-day vulnerabilities across multiple platforms demand immediate attention
Microsoft released updates addressing 398 security vulnerabilities including one actively exploited zero-day and two publicly disclosed flaws. Security experts emphasize prioritization over volume given the massive CVE count.
Critical vulnerability in Mira healthcare device cloud API accepts any format-valid password string and returns active session tokens, enabling complete account takeover and access to sensitive hormone health records without authentication.
Versions v0.27.0 through v1.9.0 of libgit2 built with libssh2 backend contain shell command injection vulnerability allowing remote attackers to execute arbitrary commands on SSH servers via unescaped shell metacharacters in repository paths.
CISA confirmed ransomware gangs are actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability that has been flagged as exploited since early July.
Critical arbitrary code execution vulnerability in LiquidJS template engine prior to version 10.26.0 allows attackers to execute arbitrary code through crafted templates.
Unauthenticated command injection in GMS Dispatcher Service version 9.5.1 and earlier allows remote attackers to achieve remote code execution through specially crafted requests.
Low-privilege read collaborators can extract workspace OAuth credentials from readable bot configurations and overwrite them with attacker-controlled values in versions prior to 3.17.0.
Cisco warns that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited to remotely crash affected VPN devices.
Nation-state actors and ransomware operators demonstrate increased sophistication with novel evasion techniques and infrastructure targeting
Russian threat group Sandworm has been targeting system administrators and IT professionals through fake job offers since at least May, delivering trojanized WireGuard VPN clients.
US and South Korean agencies warn that Gunra ransomware-as-a-service operation is finding success against critical infrastructure targets using leaked Conti code and exploiting old Fortinet firewall/VPN vulnerabilities while bypassing multi-factor authentication.
Attackers claimed to have exfiltrated 6 terabytes of highly sensitive hospital data including sexual assault records, mental health information, abortion records, and sexual harassment incidents while hijacking the hospital's social media presence.
DeadLock ransomware operation employs decentralized blockchain-backed infrastructure to protect victim communication channels and data-leak activity from law enforcement disruption.
Multiple malware distribution campaigns targeting various platforms with social engineering and trojanized software
Convincing fake CCleaner website delivers multi-stage malware attack that installs a spyware extension inside Chrome browser for credential theft and surveillance.
Fake branded download pages are tricking Windows users into installing legitimate remote-access software being abused by attackers for system takeover.
URLhaus data shows active Mirai malware distribution targeting IoT devices across ARM, MIPS, PowerPC, x86, and other architectures with over 50 distinct malware download URLs identified.
Palo Alto Unit 42 reports Kimwolf v7 botnet now targets Android IoT devices with HTTP/2 DDoS fingerprinting capabilities, Ethereum ENS for C2 resolution, and Tor backup routing for resilience.
21 new ransomware victim disclosures affecting healthcare, construction, manufacturing, and professional services sectors globally
Genesis ransomware group claims breach of elderly care healthcare organization Interim HealthCare, potentially exposing sensitive patient health information.
Austrian luxury fire-enamel jewelry house with 70+ boutiques worldwide breached. 142+ employee files exposed including salary statements (2024-2026), social security numbers, and employment contracts across 24 countries.
DireWolf ransomware group claims breach of Leafwell, a hospitals and physicians clinics organization, potentially exposing protected health information.
Global supply chain and distribution giant Wesco confirms cybersecurity incident investigation after ExfilSquad threat group claimed data theft.
Cyberattack on France's CEVA Logistics disrupted operations at eight European warehouses, impacting retailers and Steam customers across Europe.
DragonForce ransomware targets Quest Personal Care Global Ltd, a company with 30+ years experience distributing beauty and personal care products across 65+ countries.
Settra ransomware group posted six victims including ski resort operator POWDR, telecom provider First Digital, oil/gas services firm Flowco, lighting manufacturer Oligo, tax consultancy Advanced Tax Solutions, and engineering firm Profinergy BV.
Federal judge in Minnesota approved strict handling rules for data stolen in Change Healthcare's 2024 cyberattack during ongoing lawsuit proceedings.
Novel attack techniques and security research revealing new threat vectors
DB-GPT v0.8.1 contains unauthenticated path traversal via user_id HTTP header allowing remote attackers to write arbitrary files to any server location through file upload endpoint.
Cloudflare reports mitigating over 800 network-layer DDoS attacks exceeding 1 Tbps during Q2 2026, representing a fivefold increase in massive-scale attacks.
Delta Air Lines investigating unauthorized Wi-Fi network that appeared aboard flight from Las Vegas to Atlanta carrying DEF CON hacker convention attendees, suggesting potential deauthentication attack.
Token Security research shows AI agents can improvise beyond intended task scope when given broad access to enterprise systems, requiring continuous enforcement of agent intent and permissions.
Technical guidance and tools for forensic investigators and incident responders
Mozilla announced updating the GPG key used to sign Firefox and Thunderbird releases after accidental exposure on GitHub, requiring users to update trusted keys.
Forensic Focus publishes technical guide on identifying and decrypting BitLocker Clear Key-protected forensic images using dislocker and bdeinfo tools, from signature detection to NTFS volume mounting.
Government actions, leadership changes, and regulatory developments affecting cybersecurity
FBI warns that criminals are breaking into social media accounts to steal and distribute non-consensual intimate images and videos.
Municipalities in California, Oklahoma, Wisconsin and Texas recovering from disruptive cyberattacks affecting government operations and services.
Kerianne Tobitsch, previously senior lawyer at Department of Homeland Security, named as NSA's new general counsel.
Despite recent progress and mounting political pressure, the Kids Online Safety Act may face difficulty passing this congressional session according to proponents.
OpenAI and AWS making Daybreak cybersecurity capabilities available through Amazon Bedrock to support enterprise security workflows.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.