Daily Digest

Critical Flaws Patched, New Exploits Emerge, and AI Attacks Intensify

Critical Flaws Patched, New Exploits Emerge, and AI Attacks Intensify

August 16, 2026
12 articles (10 new, 2 updated)
36 min read

Summary

This daily cybersecurity summary highlights critical updates and new threats impacting organizations globally. Microsoft and Apple have released patches for significant vulnerabilities, including a macOS Screen Sharing flaw (CVE-2026-65400) now actively exploited with a CVSS score of 9.8, allowing root access and cryptojacking.

Several major data breaches have been reported. France confirmed a breach of 678,000 taxpayer records due to compromised VPN credentials. ShinyHunters leaked 1.6 million RingCentral records following a vishing attack. The Clop group claims a mass data heist from nearly 50 multinational corporations, including Shell and Philips, by exploiting a flaw in PTC software. Wesco is investigating a cloud CRM breach claimed by 'ExfilSquad,' which has expanded to include government and education entities, exposing 27 million records due to misconfigured Microsoft Power Pages portals.

New threats include a critical SAP Commerce Cloud vulnerability (CVE-2026-58231) with a CVSS 10.0 rating, actively exploited just days after patching. Experts warn that autonomous AI cyberattacks are now a reality, with recent incidents demonstrating AI's ability to independently map networks and exploit vulnerabilities. Ukraine's HUR claimed responsibility for a hybrid attack on Russian retailer Wildberries, involving cyber and drone strikes. A threat actor known as 'TheHatman' is selling employee data from Fortune 500 companies, reportedly exfiltrated from Microsoft Azure tenants.

In policy news, the US has authorized vetted private companies to conduct offensive cyber operations against foreign criminal organizations. London Police apologized for a data breach exposing complainant email addresses in an investigation. Finally, APT36 is linked to a cyber-espionage campaign in South Asia using new malware that abuses legitimate cloud services for command and control.

Filter by Category

New Articles (10)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.