Daily cybersecurity intelligence digest from CyberNetSec.io - August 14, 2026
📊 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. VMware vCenter Flaw (CVE-2026-59310) Exploited by APTs
A suspected Advanced Persistent Threat (APT) group is actively exploiting a critical directory traversal vulnerability in VMware vCenter Server, tracked as CVE-2026-59310 (CVSS 9.8). The attacks, observed just days after patches were released, target the vCenter Syslog server to achieve remote code execution. Attackers are establishing persistence on compromised systems using a cron job and a reverse SSH tool, indicating a sophisticated, global campaign. Over 360 unique victim IPs have been identified across 47 countries, with high concentrations in Germany, the US, and Turkey. Organizations are urged to patch immediately and hunt for signs of compromise.
2. Akira Ransomware Uses Safe Mode to Bypass EDR Defenses
The Akira ransomware group has updated its tactics to include rebooting compromised Windows systems into 'Safe Mode with Networking' to bypass Endpoint Detection and Response (EDR) security products. This technique, tracked as MITRE ATT&CK T1562.009, prevents many security tools from loading, allowing the malware to operate unimpeded. In a recent incident analyzed by Huntress, attackers gained initial access via a credential-spraying attack against an unprotected SonicWall SSL VPN. While the encryption payload failed to execute in the constrained Safe Mode environment, the attackers still successfully exfiltrated data using the s5cmd tool, demonstrating the continued threat of their double-extortion model.
3. WordPress RCE Flaw (CVE-2026-65640) Patched
A high-severity remote code execution (RCE) vulnerability, CVE-2026-65640 (CVSS 8.8), has been patched in WordPress 7.0.4. The flaw allows authenticated users with 'Author' or higher privileges to execute arbitrary code by uploading a specially crafted file. The vulnerability is present on sites that use the Imagick PHP extension and Ghostscript for file processing. An attacker can disguise malicious PostScript code within a PNG file, which is then executed by the server's backend processing engine. The patch, which has been backported to WordPress versions as far back as 4.7, addresses the issue by verifying file contents before processing. All administrators are urged to update their sites immediately.
4. City-Forum Data Theft Targets Salesforce, ServiceNow
A persistent data theft campaign named 'City-Forum' has been targeting misconfigured Salesforce Experience Cloud and ServiceNow portals since at least March 2025. The threat actor exploits overly permissive guest user accounts to access and exfiltrate sensitive data without needing to exploit a software vulnerability. The campaign uses a custom toolset, indicating a more sophisticated actor than previously seen in similar attacks. The activity has been traced to a single IP address (158.220.87.79) and has impacted organizations globally across sectors like finance, telecom, and government. Administrators are urged to audit public-facing portal configurations and guest user permissions.
5. Intel & AMD Patch Over 80 Vulnerabilities in August 2026
Intel and AMD have released their August 2026 security updates, collectively addressing over 80 vulnerabilities across a wide range of products. Intel's updates cover 72 distinct CVEs in products like PROSet/Wireless WiFi software, Xeon processors, and AI tools, fixing high-severity privilege escalation and DoS flaws. AMD released five advisories patching about a dozen flaws, including high-severity issues in its Vitis development environment that could lead to arbitrary code execution and private key disclosure. System administrators are urged to review the advisories and apply the necessary patches promptly.
6. JWR Phishing Framework Enables Live, Operator-Driven Attacks
Cisco Talos has discovered a sophisticated phishing-as-a-service (PhaaS) framework named 'JWR' that enables live, operator-driven attacks. Unlike traditional automated phishing kits, JWR uses an encrypted WebSocket channel to allow an attacker to monitor a victim's actions in real-time and dynamically guide them. The framework is capable of stealing credentials, 2FA codes, payment card data, and even images of identity documents. JWR has been observed in smishing campaigns targeting users in Southeast Asia and the Middle East, impersonating major brands like Shopify and PayPal. Talos notes similarities to another PhaaS platform, 'The Outsider,' and suggests a link to Chinese-speaking threat actors.
7. Phantom Stealer Malware Hides Payload in PNG Images
A .NET-based information stealer named Phantom Stealer is being used in active campaigns, employing steganography to hide its malicious payload within PNG image files. This technique helps it evade static analysis and detection. Distributed via phishing, malicious links, and trojanized software, Phantom Stealer targets a wide range of data on Windows systems, including browser credentials, cookies, cryptocurrency wallets (both browser and desktop), and FTP client credentials. It also features a clipboard-hijacking function to redirect cryptocurrency payments and establishes persistence via registry 'Run' keys. The combination of evasion and broad data theft capabilities makes it a significant threat.
8. LiteLLM Supply Chain Breach Exposes Corporate Secrets
A major software supply chain attack targeting the popular open-source AI tool LiteLLM has exposed a 153GB database of secrets from over 2,400 companies. The attack began with the compromise of the Trivy vulnerability scanner's CI/CD pipeline, which was then used to steal PyPI publishing tokens for the LiteLLM project. Attackers, known as 'TeamPCP,' published malicious LiteLLM versions (1.82.7, 1.82.8) containing the 'SANDCLOCK Stealer.' This malware harvested SSH keys, cloud credentials, and API keys from developer environments. The incident highlights the severe risks of cascading failures in the software supply chain.
9. CISA Warns of Johnson Controls Metasys XSS Flaw
The US CISA has issued an advisory for a high-severity persistent cross-site scripting (XSS) vulnerability, CVE-2026-34491 (CVSS 8.0), in the Johnson Controls Metasys building automation system. The flaw allows a low-privilege user to inject a malicious script into the UI, which then executes in the browser of any user viewing the component, including administrators. This can lead to session hijacking and unauthorized control. The Metasys platform is used worldwide in critical infrastructure. Johnson Controls has released patches for some affected versions (12, 13, 14, 15) and recommends upgrading for others. Asset owners are urged to apply updates.
10. Umbral Stealer Malware Targets Windows Systems
A recent threat intelligence report from CYFIRMA highlights the 'Umbral Stealer,' a .NET-based information-stealing malware targeting Windows systems. Distributed via phishing and trojanized installers, Umbral Stealer is designed to exfiltrate a wide range of data, including browser credentials, cookies, cryptocurrency wallets, and session data for Discord, Telegram, and gaming platforms. The malware also features anti-VM detection, attempts to add itself to the Microsoft Defender exclusion list, and can capture screenshots and webcam images. The focus on employee endpoints underscores the value threat actors place on personal and corporate account data.
11. Fortinet FortiWeb Critical Auth Bypass Flaw Patched
Fortinet has patched several vulnerabilities in its FortiWeb Web Application Firewall (WAF), including a critical authentication bypass flaw, CVE-2026-26035. This vulnerability allows an unauthenticated, remote attacker to log into the device's administrative GUI with any password if a non-default 'admin wildcard' setting is enabled. While the setting is not on by default, its use could lead to a complete compromise of the WAF. Fortinet also patched other authentication bypass flaws in FortiWeb and FortiManager. Customers are urged to apply updates immediately and review their configurations to ensure the vulnerable setting is disabled.
12. Fake Chrome VPN Extensions Expose User Traffic
Security researchers have uncovered a massive campaign involving over 700 fraudulent VPN extensions for Google Chrome. These extensions, which impersonate popular services like Proton VPN and NordVPN, do not provide a secure connection. Instead, they route all of the user's internet traffic through a single, attacker-controlled proxy network. This exposes users to significant risks, including man-in-the-middle attacks, credential theft, and data inspection. The scale of the operation, with hundreds of extensions pointing to the same infrastructure, indicates a coordinated effort. Users are advised to audit their browser extensions immediately and remove any suspicious VPNs.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)