HomeCybersecurity NewsCybersecurity news weekly roundup August 17, 2026
August 17, 2026

Cybersecurity news weekly roundup August 17, 2026

San Mateo, CA, August 17, 2026 — Developments, threats, and responses in the news last week.

STORIES LAST WEEK

Microsoft patches 419 vulnerabilities including three zero-days

Microsoft’s August security release fixed 419 vulnerabilities, including three zero-days. CVE-2026-68820, in the Windows component handling network connections, was already exploited in a Lazarus campaign targeting defense, aerospace, and aviation job seekers. The Record, August 12, 2026

Taiwan reports AI-assisted cyberattack on government agencies

Taiwan said attackers combined manual operations with AI agents against government agencies. Researchers linked the campaign to credential theft, personnel-record theft, and reconnaissance of nuclear-safety systems, showing agentic tooling in an operational intrusion. Reuters, August 13, 2026

Cisco patches actively exploited ASA and FTD VPN flaw

Cisco said CVE-2026-20349 is being actively exploited against ASA and FTD remote-access VPN services. Crafted HTTP requests can force devices to reload and Cisco says no workaround exists beyond installing fixed software. Cisco, August 11, 2026

SAP Commerce Cloud flaw draws exploitation attempts three days after patch

Defused observed exploitation attempts against CVE-2026-58231, a CVSS 10 SAP Commerce Cloud flaw allowing unauthenticated remote code execution. SAP is investigating and urged customers to apply its Aug. 11 security note immediately. BleepingComputer, August 14, 2026

White House authorizes vetted companies to conduct cyber operations against foreign criminal groups

A presidential memorandum directs the National Coordination Center to authorize vetted U.S. companies for cyber surveillance and effects operations against foreign cybercriminal organizations under federal control, creating a formal framework for private-sector offensive cyber operations. The White House, August 12, 2026

RingCentral breach data includes about 1.6 million accounts

Have I Been Pwned counted about 1.6 million unique email addresses in data leaked from RingCentral’s July breach, alongside names, addresses, and phone numbers. RingCentral said its core platform was not affected. SecurityWeek, August 14, 2026

Trivy compromise drove most exposure attributed to LiteLLM attack

SOCRadar found 95% of 2,188 identified organizations were exposed before malicious LiteLLM packages appeared, tracing the broader compromise upstream to Trivy. The worm harvested tokens, API keys, and other secrets across six CI/CD platforms. SecurityWeek, August 14, 2026

Poisoned logs can hijack AI agents with infrastructure access

Researchers demonstrated GhostJacking by planting prompt injections in security logs. AI agents later ingested the entries and used legitimate Cloudflare, Datadog, and Sentry integrations to change DNS, execute code, or expose data. SC Media, August 11, 2026

Attackers used a private APN to pivot into a Polish power plant

CERT Polska reconstructed a destructive attack that moved from a compromised wind farm network through a private cellular APN into a CHP plant’s OT network. Investigators called it the first observed real-world use of that pivot. CERT Polska, August 8, 2026

Custom toolset extracts exposed data from Salesforce and ServiceNow portals

Reco found one attacker using a custom Go toolset to enumerate guest-accessible Salesforce and ServiceNow data across telecom, financial services, software, and public-sector targets. The campaign exploits exposed guest permissions rather than a software vulnerability. Reco, August 12, 2026

Jewelbug uses browser implants for espionage and crypto fraud

Symantec tied China-based Jewelbug to government espionage and cryptocurrency fraud run through shared infrastructure. Its XG-Web platform hijacks browsers, steals session cookies, and can extend access into hosts and internal networks. Security.com, August 13, 2026

Sandworm targets IT professionals with trojanized WireGuard client

CERT-UA said Sandworm-linked attackers are targeting system administrators and IT professionals with fake job interviews requiring a trojanized WireGuard client. The modified software decrypts embedded PowerShell and downloads additional payloads. BleepingComputer, August 11, 2026

Gunra ransomware affiliates exploit FortiOS flaws against critical infrastructure

CISA said Gunra ransomware affiliates are targeting government and critical infrastructure and exploiting FortiOS flaws CVE-2024-55591 and CVE-2025-24472. The vulnerabilities can be abused to create unauthorized administrator accounts on vulnerable firewalls. CISA, August 10, 2026

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles