This daily summary highlights critical security updates and new vulnerabilities impacting various software and hardware. SonicWall zero-days (CVE-2026-15409, CVE-2026-15410) are now being actively exploited for ransomware deployment, escalating their threat level. VMware has patched a critical VM escape flaw (CVE-2026-47876) in ESXi, with active exploitation confirmed for CVE-2026-59310, allowing persistent reverse SSH tunnels. The Metabase zero-day SQL injection vulnerability (CVE-2026-72898) continues widespread exploitation, with LexisNexis confirming an incident. Microsoft's August Patch Tuesday addresses over 400 vulnerabilities, including a Windows privilege escalation zero-day (CVE-2026-68820) exploited by the Lazarus Group.
CISA warns of Gunra ransomware targeting critical infrastructure, utilizing vulnerabilities in Fortinet and Schneider Electric devices, with new TTPs including session hijacking and MFA bypass. A LiteLLM AI supply chain attack by Team PCP exposed over 2,500 companies through a novel secondary exfiltration technique using GitHub repositories. New threats include 'Ghostjacking' and 'GhostSplice' attacks targeting AI agents, and AI-powered cyberattacks impacting major U.S. corporations. Cisco has patched a zero-day DoS vulnerability in its Secure Firewall (CVE-2026-20349). Zoom has addressed a zero-click RCE flaw in its conferencing app, and Ivanti has released patches for critical RCE vulnerabilities in its Endpoint Manager.
Organizations are strongly advised to apply all available patches and review security configurations to mitigate these evolving threats.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.