DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 13, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 13, 2026


📊 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Microsoft Patches Actively Exploited Zero-Day in August Update

Microsoft's August 2026 Patch Tuesday addressed 421 vulnerabilities, including a critical zero-day (CVE-2026-68820) actively exploited by the North Korean Lazarus Group. The privilege escalation flaw was used in the 'Operation Dream Job' campaign to deploy a new backdoor named 'Troy' against aerospace and defense targets. CISA has added the vulnerability to its KEV catalog, mandating urgent patching for federal agencies. The update also fixed 43 other critical remote code execution flaws.

📖 Read full report →


2. ShieldBreak Exploit Bypasses Defender's RoguePlanet Patch

A security researcher has released 'ShieldBreak,' a proof-of-concept exploit for a new zero-day vulnerability that bypasses Microsoft's patch for the 'RoguePlanet' flaw (CVE-2026-50656). The exploit allows a local, low-privileged user to gain full SYSTEM privileges on fully updated Windows 10, Windows 11, and Windows Server 2025 systems running Microsoft Defender. The public release of the PoC creates a significant risk, as there is currently no official patch for this bypass.

📖 Read full report →


3. DentaQuest Suffers Massive Data Breach Affecting 15M+

DentaQuest, a major U.S. dental and vision benefits administrator, has disclosed a data breach affecting over 15 million individuals, making it the largest healthcare-related breach in the U.S. for 2026. The attack, which occurred in May 2026, resulted in the compromise of sensitive personal and health information, including Social Security numbers and medical data. The extortion group ShinyHunters has claimed responsibility and leaked the data after ransom negotiations failed.

📖 Read full report →


4. Trezor Discloses Data Breach from Hacked Shipping Partner

Cryptocurrency hardware wallet maker Trezor has disclosed a data breach affecting nearly 14,000 customers. The breach originated from its third-party shipping partner, ShipMonk, whose systems were compromised. The incident exposed customer names, addresses, emails, and phone numbers for orders shipped between May and August 2026. While crypto funds are safe, the leaked data creates a significant risk of targeted phishing attacks against Trezor users.

📖 Read full report →


5. APT Exploits Critical VMware vCenter Flaw CVE-2026-59310

A suspected Advanced Persistent Threat (APT) group is actively exploiting a critical remote code execution vulnerability in VMware vCenter Server (CVE-2026-59310, CVSS 9.8). The unauthenticated directory traversal flaw is being used to compromise servers and establish persistent access using a reverse SSH shell. Security firm QUIRSO reports that exploitation began just five days after the patch was released, with over 360 victim IPs identified across 47 countries. Organizations are urged to patch immediately.

📖 Read full report →


6. Jewelbug APT Runs Espionage and Crypto Scams in Parallel

A sophisticated Chinese hacker-for-hire group, dubbed 'Jewelbug' by Symantec, is operating a dual-purpose cybercrime platform. The group conducts state-level espionage against government and military targets in Asia and the Middle East while simultaneously running large-scale cryptocurrency theft campaigns. Jewelbug uses a custom C2 panel called 'XG-Web' and a suite of malware, including 'Fostealer' and a malicious browser extension, to manage both financially motivated and espionage-focused operations from the same infrastructure.

📖 Read full report →


7. AI Cyberattacks Move from Experiment to Operational Reality

According to Flashpoint's midyear threat report, cybercriminals have fully operationalized Artificial Intelligence, moving beyond experimentation to use AI for accelerating attack speed, scale, and sophistication. The report highlights over 22 million illicit discussions on AI toolkits and notes that criminals are running custom, uncensored large language models on private infrastructure. This shift has contributed to a 45% surge in ransomware-as-a-service (RaaS) activity and the theft of 1.7 billion credentials in the first half of 2026.

📖 Read full report →


8. Palo Alto Networks Patches 11 Flaws in PAN-OS, GlobalProtect

Palo Alto Networks has released its August 2026 security bulletin, addressing 11 new vulnerabilities across its product lines, including PAN-OS, GlobalProtect, and Prisma. None of the flaws are rated critical, with the highest CVSS score being 7.2. The patches address issues such as privilege escalation, buffer overflows, and information disclosure. The GlobalProtect VPN client received the most fixes, highlighting the need for endpoint patching.

📖 Read full report →


9. City-Forum Campaign Targets Misconfigured Salesforce & ServiceNow

An ongoing data theft campaign dubbed 'City-Forum' is targeting misconfigured Salesforce Experience Cloud and ServiceNow portals worldwide. The attackers use custom tools to systematically scrape and exfiltrate data left accessible to unauthenticated guest users. The campaign, active since at least March 2025, does not exploit a platform vulnerability but rather customer-side misconfigurations. The actor has developed novel techniques to attack modern Salesforce LWR sites, indicating a high level of sophistication.

📖 Read full report →


10. Wesco Investigates CRM Breach After ExfilSquad Claims Data Theft

Global supply chain company Wesco has confirmed it is investigating a security incident involving its cloud CRM environment. The acknowledgment follows a claim by the data extortion group ExfilSquad, which asserted it had stolen 2.6 million records containing customer and employee PII. The group subsequently leaked the data on its dark web site after a ransom was not paid. The attack vector is suspected to be a misconfiguration in Wesco's Microsoft Power Pages or Dynamics 365 environment.

📖 Read full report →


11. WellPoint Texas Reports Data Breach Impacting 101,000

WellPoint Texas, Inc., a Medicaid managed care provider, has reported a data breach to the Texas Attorney General affecting 101,047 individuals. The details of the cybersecurity incident are currently sparse, but the compromised information may include names, addresses, dates of birth, and health insurance details. The exposure of this sensitive data places the affected Medicaid members at an increased risk of identity theft and fraud. Several law firms have launched investigations.

📖 Read full report →


12. Armored Likho APT Uses 'Still Toolkit' for Espionage in Russia

The cyber-espionage group 'Armored Likho' has launched a new campaign targeting Russian individuals and organizations with a new Rust-based malware suite called 'Still Toolkit.' According to Kaspersky, the toolkit is designed for espionage, with components that steal Telegram session data to hijack accounts and covertly record audio from a victim's microphone. The campaign, which began in May 2026, uses fundraising-themed lures to trick victims into running the malware.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)