Daily Digest

EU Cyber Resilience Guidance, Ransomware, and Zero-Days Dominate Cybersecurity News

EU Cyber Resilience Guidance, Ransomware, and Zero-Days Dominate Cybersecurity News

August 10, 2026
10 articles (5 new, 5 updated)
30 min read

Summary

The European Union is preparing for the Cyber Resilience Act (CRA) with ENISA expanding its role in the CVE Program, onboarding new CNAs like NCIA and AISLE to manage vulnerability reporting ahead of the September 2026 mandate for manufacturers. Meanwhile, the Qilin ransomware group continues its double-extortion tactics, adding Chun Tai Sing Chemical Industry to its leak site.

Critical vulnerabilities remain actively exploited. Microsoft Threat Intelligence reports Storm-1175 is leveraging a flaw in N-able N-central (CVE-2026-18577) to deploy a new custom ransomware, StormEncryptor, targeting MSPs. A Metabase zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf) is also being exploited for admin access, with updated patch versions released and new detection methods identified.

In supply chain attacks, PhantomCore RAT has been identified as the backdoor used in a Head Mare campaign targeting Russian organizations via compromised TrueConf installers. WordPress has patched a high-severity 'XSS2Shell' flaw (CVE-2026-64638) that could lead to remote code execution.

On the incident response front, Suisun City, California, declared a state of emergency after a cyberattack disrupted 911 services. IEH Corporation disclosed that a phishing attack compromised an employee's Microsoft 365 account, exposing sensitive defense-related data.

Proactive measures are also being taken. California has launched an AI Cyber Defense Program to protect critical infrastructure, and the Netherlands has finalized its NIS2 law, effective August 15, 2026, imposing new obligations on thousands of organizations.

Filter by Category

New Articles (5)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.