DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 12, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 12, 2026


📊 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Gunra Ransomware Targets Global Critical Infrastructure

U.S. and South Korean agencies have issued a joint advisory on the Gunra ransomware, a Conti-Locker derivative. The group targets critical infrastructure globally by exploiting known vulnerabilities in Fortinet and Schneider Electric products, using double extortion tactics and demanding multi-million dollar ransoms. The advisory provides TTPs, IOCs, and mitigation guidance.

📖 Read full report →


2. Metabase SQLi Zero-Day (CVE-2026-72898) Exploited

A critical CVSS 10.0 unauthenticated SQL injection zero-day in Metabase is being actively exploited, allowing full admin access. Laptop maker Framework is a confirmed victim, with customer PII stolen. All users of self-hosted Metabase are urged to upgrade immediately as attackers can take over instances and steal data from connected databases.

📖 Read full report →


3. Microsoft Patches Actively Exploited Zero-Day CVE-2026-68820

Microsoft's August 2026 Patch Tuesday addresses over 400 vulnerabilities, including 42 rated critical. The update patches an actively exploited zero-day (CVE-2026-68820), a privilege escalation flaw in afd.sys used by the North Korea-linked Lazarus Group. Administrators are urged to prioritize patching to mitigate significant risks.

📖 Read full report →


4. Widespread Scanning for VMware vCenter Flaws (CVE-2026-59309)

Threat actors are conducting widespread scanning for critical vulnerabilities in VMware vCenter Server, including a CVSS 9.8 authentication bypass (CVE-2026-59309). This activity follows a Broadcom advisory and indicates that mass exploitation may be imminent. Another critical flaw, CVE-2026-59310, is already being actively exploited to deploy backdoors.

📖 Read full report →


5. New Attacks Ghostjack and GhostSplice Target AI Agents

Security researchers have unveiled 'Ghostjacking' and 'GhostSplice,' two novel attack techniques that manipulate AI coding assistants. Ghostjacking uses poisoned logs for indirect prompt injection, while GhostSplice splits malicious commands across trusted channels. These attacks highlight emerging risks in enterprise AI deployments, showing how agents can be tricked into exfiltrating data or executing malicious commands.

📖 Read full report →


6. OpenAI Launches GPT-5.6-Cyber for Security Research

OpenAI has launched GPT-5.6-Cyber, a specialized model with reduced safeguards for cybersecurity research. Available only to vetted researchers via its 'Daybreak Red' tier, the model is designed to assist in vulnerability discovery and exploit development, completing 95% of advanced cyber tasks that standard models refuse.

📖 Read full report →


7. LiteLLM Supply Chain Attack Exposes 2,500 Organizations

A major supply chain attack targeting the open-source LiteLLM framework has impacted over 2,500 organizations. The 'Team PCP' threat actor published malicious packages that were downloaded into 434,000 CI/CD pipelines, stealing cloud credentials, API keys, and other secrets. The FBI warns that the stolen data is likely to be weaponized.

📖 Read full report →


8. AI-Driven Cyberattacks Target Major US Companies

Throughout 2026, a surge of AI-enhanced cyberattacks has impacted major U.S. corporations across nearly every sector, including Nike, Wynn Resorts, Coca-Cola, and Stryker. Attackers are using AI to improve social engineering and ransomware campaigns, leading to widespread data breaches, operational shutdowns, and significant financial demands.

📖 Read full report →


9. Cisco Patches Exploited Firewall Zero-Day (CVE-2026-20349)

Cisco has patched a zero-day vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD devices that is being actively exploited. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS) condition, disrupting network traffic. Customers are urged to apply the updates immediately.

📖 Read full report →


10. SonicWall SMA Flaws (CVE-2026-15409) Added to KEV Catalog

CISA has added two critical vulnerabilities in SonicWall's SMA 1000 series remote access gateways (CVE-2026-15409, CVE-2026-15410) to its KEV catalog. The flaws are being actively chained by ransomware groups for initial access, making immediate patching a top priority for all organizations using these devices.

📖 Read full report →


11. Zoom Patches Critical Zero-Click Remote Code Execution Flaw

Zoom has patched a critical zero-click remote code execution (RCE) vulnerability in its video conferencing client. The flaw, located in the annotation feature, could have allowed a meeting participant to execute arbitrary code on another participant's machine without any user interaction. All users are urged to update their Zoom clients immediately.

📖 Read full report →


12. Ivanti Patches Critical RCE Vulnerabilities in EPM

Ivanti has released patches for several critical, remotely exploitable vulnerabilities in its Endpoint Manager (EPM) solution. These flaws could allow an attacker to execute arbitrary code on vulnerable systems, potentially leading to a full compromise of managed endpoints. Given Ivanti's history as a target, immediate patching is advised.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)