The 48-hour period from August 16-17, 2026 saw significant cybersecurity activity across multiple threat vectors. Most critically, multiple CRITICAL severity vulnerabilities were disclosed affecting widely-used platforms including WordPress plugins (CVE-2026-73061, CVE-2026-18432, CVE-2026-18316) and the Scriban templating engine (CVE-2026-74790), with CVSS scores reaching 9.8. These vulnerabilities enable remote code execution, privilege escalation, and authentication bypass without user interaction.
Ransomware operations remained highly active with 30 new victim disclosures across multiple groups, including Qilin (13 victims), LockBit5 (5 victims), and MedusaLocker (5 victims). Notable victims include engineering firms, healthcare-adjacent organizations, and critical infrastructure providers. The SafePal cryptocurrency wallet breach affecting 39,798 customers represents a significant supply chain compromise with stolen data actively being sold on criminal marketplaces.
Malware distribution infrastructure showed continued IoT botnet activity with 50+ Mozi botnet URLs identified, alongside emerging threats including the new AmnesiaStealer macOS malware utilizing ClickFix social engineering and browser session hijacking capabilities. Multiple DDoS campaigns targeted secure communications platforms including Threema, indicating ongoing attacks against privacy-focused infrastructure.
Multiple critical vulnerabilities disclosed affecting WordPress plugins, templating engines, and IoT devices with remote exploitation potential
CRITICAL vulnerability in Scriban versions 3.0.0-7.2.0 allows template code to bypass access modifiers and write to private/internal properties, enabling mass assignment attacks on publicly exposed properties. CVSS 9.8.
CRITICAL privilege escalation in Frontend Admin by DynamiApps plugin (all versions ≤3.29.9) allows unauthenticated attackers to bypass authorization checks and edit user accounts. CVSS 9.8.
CRITICAL missing capability check in Solace Extra plugin (≤1.6.0) allows unauthenticated attackers to import malicious configurations leading to data loss and site compromise. CVSS 9.1.
CRITICAL vulnerability in Scriban <7.0.0 allows cached TypedObjectAccessor to expose filtered members when TemplateContext is reused with tightened MemberFilter settings. CVSS 9.1.
CRITICAL arbitrary file upload in ProSolution WP Client plugin (≤2.0.10) via Content-Disposition header manipulation allows unauthenticated remote code execution. CVSS 9.8.
Multiple CRITICAL buffer overflow vulnerabilities in Edimax EW-7478APC 1.04 routers allow remote command injection and code execution via formWlSiteSurvey and formWanTcpipSetup functions. CVSS 9.9.
CRITICAL authentication bypass in SiYuan kernel <3.7.4 lacks brute-force protection on API token authentication, enabling unlimited authentication attempts. CVSS 9.8.
Major data breach at cryptocurrency platform SafePal affecting nearly 40K customers, with stolen data actively for sale on criminal markets
SafePal confirmed data breach impacting 39,798 customers after exploitation of security flaw. Stolen customer order information including personal details now being sold by threat actors on underground markets. Affects cryptocurrency hardware wallet users.
Anubis ransomware group claims attack on Fairlife (Coca-Cola subsidiary) affecting 500 hosts with 1TB of data exfiltrated. Group reports no negotiation occurred. Significant operational disruption to dairy/beverage production infrastructure.
30 new ransomware victim disclosures across multiple threat groups with focus on engineering, manufacturing, and professional services sectors
Qilin ransomware group disclosed 13 new victims including ASCII Group (IT services), Arnall Golden Gregory (law firm), Zanichelli and Loescher (Italian publishers), MOSAID Technologies, INVENSITY engineering, and Megawide construction. Indicates sustained campaign targeting professional services and technology sectors.
LockBit5 ransomware disclosed 5 victims including French recruitment firm Groupe Actua (actua.fr), German engineering firm TECOSIM, accounting firm Dupouy et Associes, and agricultural companies. Demonstrates continued operations despite law enforcement disruption attempts.
MedusaLocker ransomware group claimed 5 victims including South African courier service Thecourierguy (2,018 email accounts compromised), French industrial firm Bija Industrie (693 emails), and UK dry cleaning business. Demonstrates targeting of logistics and service industries.
New Helix ransomware group targeting Kennedy Jenks engineering firm with phased disclosure approach (T1-T4 tiers unlocking progressively). Indicates professional exfiltration and pressure tactics.
Settra group disclosed internal documents from Ecuadorian auto dealership GALMACK, American industrial distributor AIROYAL, and entertainment network TILT Studio. Shows broad sector targeting with emphasis on financial and operational data theft.
Continued Mozi botnet activity alongside new macOS infostealer with browser hijacking capabilities
New information-stealing malware targeting macOS via ClickFix social engineering attacks includes streaming module for interactive browser control. Allows threat actors to hijack active browser sessions and perform real-time account takeover. Represents evolution of macOS-targeted credential theft.
URLhaus identified 50+ active Mozi botnet malware distribution URLs targeting IoT devices via multiple architectures (ARM, MIPS, ELF). Infrastructure includes compromised devices in China, South Africa, and globally distributed C2 nodes. Sustained IoT compromise campaign ongoing.
Multiple Mirai variant distribution URLs detected including Iran-focused botnet infrastructure (31.77.227.119) delivering SSH brute-force capabilities and Android-targeting APK payloads. Includes meower.arm7 and Services.apk for mobile device compromise.
Multiple Amadey bot dropper URLs identified distributing secondary payloads including RustyStealer and additional malware components. Infrastructure using IP ranges 91.92.242.236 and 62.60.226.140 for payload hosting.
Large-scale DDoS attacks against secure communications platforms and service outages affecting AI infrastructure
Multiple large-scale distributed denial-of-service attacks targeted Threema encrypted messaging platform causing severe communications disruptions. Represents continued targeting of privacy-focused and secure communications infrastructure. Potential state-sponsored or hacktivist motivation.
Claude AI experiencing major outage with login problems and degraded performance across multiple services. While not confirmed as malicious, represents potential targeting of AI infrastructure or supply chain vulnerability affecting AI-dependent operations.
Bipartisan cybersecurity legislation introduced targeting rural healthcare infrastructure protection
Bipartisan Rural Hospital Cybersecurity Enhancement Act introduced to House of Representatives by Rep. Glenn Thompson and colleagues. Legislation aims to strengthen cyber protections for rural hospitals facing increased ransomware and cyber threats with limited security resources.
New Jersey federal judge dismissed class action lawsuit against TABB Inc. background check company related to 2024 data leak. Court found plaintiff failed to establish concrete injury necessary for standing. Sets precedent for data breach litigation requirements.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.