Daily Digest

Critical Exploits, AI Influence Ops, and Router Backdoors Dominate Cybersecurity News

August 28, 2026
6 articles (5 new, 1 updated)
18 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Critical Citrix NetScaler Pre-Auth RCE (CVE-2026-8452): This critical vulnerability is now actively exploited in the wild, with CISA mandating patches for federal agencies by August 29, 2026. Threat actors are deploying web shells for persistence on over 23,000 exposed devices. Organizations are urged to patch immediately.

New Critical Vulnerabilities and Threats:

  • ServiceNow AI and Now Platforms Critical Flaws (CVSS 10.0): ServiceNow has released urgent patches for three critical, unauthenticated vulnerabilities in its AI and Now Platforms. These flaws could allow remote code execution, privilege escalation, and SQL injection without user interaction. Patches are available for hosted and self-hosted environments.
  • Critical cPanel Flaw Allows Root Access: A critical vulnerability in cPanel & WHM (CVE-2026-65643) allows authenticated users with domain parking permissions to gain root access, posing a significant risk to shared hosting environments. Patches are available for all supported versions and should be applied manually if automatic updates are not enabled.
  • New Surveillance Backdoors in Chinese-Made Routers: Security researchers have discovered two new backdoors, 'Darklantern' and 'Speakingstone,' in numerous Zbtlink router models sold globally. These backdoors provide invasive remote access and could be used for surveillance, raising concerns about supply chain security.

Industry Trends and Influence Operations:

  • Identity Attacks Fuel Ransomware in Education: A Sophos report indicates that 85% of ransomware attacks in education start with identity-based vectors, a rate higher than the cross-sector average. K-12 institutions saw a significant increase in successful data encryption, highlighting the need for enhanced identity security and user awareness training.
  • Meta Disrupts Iran-Linked AI-Powered Influence Operation: Meta has dismantled an Iran-linked influence operation that used AI-generated content and fake personas to spread anti-Republican and anti-Israel messaging on Facebook and Instagram. The operation aimed to engage with U.S. politicians and journalists to amplify its content.

Filter by Category

New Articles (5)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.