Daily Digest

Cybersecurity Brief: Zero-Days, Ransomware, and Data Breaches

Cybersecurity Brief: Zero-Days, Ransomware, and Data Breaches

August 18, 2026
12 articles (7 new, 5 updated)
36 min read

Summary

This daily cybersecurity summary highlights critical updates and new threats impacting organizations globally. Microsoft has released patches for a zero-day vulnerability (CVE-2026-68820) exploited by the Lazarus Group in an espionage campaign, now confirmed to involve a kernel-mode rootkit. Similarly, APT actors are actively exploiting a critical VMware vCenter flaw (CVE-2026-59310), with recent activity indicating the use of Babuk-derived ransomware. GeoServer has released patches for a critical SQL injection zero-day (GHSA-mqjf-5f49-2fjh), with active exploitation continuing. Colombia's Ministry of Justice was hit by a ransomware attack on August 2, 2026, leading to file encryption and ongoing restoration efforts. The Polish healthcare platform 'MyDr' experienced a major breach affecting millions, prompting an investigation and precautionary measures within the national e-Health system.

New threats include escalating Medusa ransomware tactics, with the group compromising over 500 organizations by April 2026 and accelerating exploitation. Umbraco has patched a high-severity privilege escalation flaw in its CMS backoffice Management API, alongside moderate issues in Forms and AI components. A ransomware attack on Winnipeg Hospital's building systems continues to cause operational disruption, though direct patient care remains unaffected. A critical MLflow SSRF flaw (CVE-2026-64849) is being actively exploited to steal cloud secrets. Malicious RubyGems packages are distributing a Go-based information stealer targeting credentials and crypto wallets. The Web3 casino Intraverse.io leaked nearly 16.9 million records due to an unsecured Firebase Realtime Database. Finally, NIST is seeking public input on a draft concept paper for a human-centered approach to cybersecurity, aiming to address systemic root causes of human-related security incidents.

Filter by Category

New Articles (7)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.