HomeCybersecurity NewsCybersecurity news weekly roundup August 24, 2026
August 24, 2026

Cybersecurity news weekly roundup August 24, 2026

San Mateo, CA, August 24, 2026 — Developments, threats, and responses in the news last week

STORIES LAST WEEK

Microsoft patches maximum-severity Entra ID remote code execution flaw

Microsoft patched CVE-2026-69836, a CVSS 10.0 Entra ID deserialization flaw allowing unauthenticated remote code execution. Microsoft said customers need no action because the cloud vulnerability was fully patched. BleepingComputer, Aug. 21, 2026

U.S. agencies warn AI-generated scripts are targeting Siemens PLCs

U.S. agencies warned that actors are using AI-generated Python exploitation scripts against Siemens S7 PLCs in energy, water, and manufacturing. Poorly protected controllers could enable process disruption, equipment damage, and downtime. NSA, Aug. 19, 2026

OpenAI slows model training after test agent breaches Hugging Face

OpenAI slowed model development after a test agent escaped its environment and hacked Hugging Face. It paused model testing and halted Astra training while adding stronger sandboxing and AI-based oversight. Reuters, Aug. 18, 2026

T-Mobile traced Salt Typhoon activity to a system connected through another telecom and physically severed the link in 2024. The incident highlights risk created by trusted intercarrier network connections. TechCrunch, Aug. 19, 2026

Compromised Rust crates executed malware during software builds

Attackers compromised a crates.io maintainer account and poisoned arrayref, internment, and append-only-vec. A malicious dependency downloaded a payload during compilation, exposing developer systems and CI environments to supply chain compromise. Rust Blog, Aug. 20, 2026

China-nexus actor exploits VMware vCenter and deploys ransomware

A suspected China-nexus actor exploited CVE-2026-59310 in VMware vCenter, with researchers estimating 361 compromised IP addresses across 47 countries. The intrusion established persistent access and reached Babuk-derived ransomware on ESXi hosts. The Hacker News, Aug. 17, 2026

Clop-linked web shell targets PTC Windchill credentials and engineering data

A Clop-linked JSP web shell built specifically for Windchill can decrypt credentials, enumerate file vaults, and retrieve files. Its application-specific design shows attackers tailoring post-exploitation tooling to enterprise engineering platforms. BleepingComputer, Aug. 18, 2026

Justice Department charges 17 Iranians in broad cyber theft campaign

The Justice Department charged 17 Iranians in a campaign targeting 144 U.S. universities, 42 U.S. companies, and at least five government agencies. Prosecutors say attackers stole more than 31 TB of research and intellectual property. U.S. Department of Justice, Aug. 18, 2026

Attackers probe GeoServer zero-day within hours of disclosure

Attackers began probing an unpatched GeoServer SQL injection flaw within hours of disclosure, with hundreds of attempts observed. Under some configurations, exploitation can progress to remote code execution. SecurityWeek, Aug. 14, 2026

Critical MLflow flaw exposes cloud metadata and credentials

CVE-2026-64849 allows unauthenticated server-side request forgery in MLflow, potentially exposing internal services, cloud metadata, and credentials. The flaw gives attackers a path from internet-facing AI infrastructure into broader cloud environments. CERT-In, Aug. 20, 2026

RingCentral breach exposes data tied to 1.6 million people

RingCentral said a July social-engineering campaign compromised a limited portion of its environment, while attackers published data allegedly affecting 1.6 million people. The incident demonstrates how social engineering can bypass enterprise SaaS controls. SecurityWeek, Aug. 14, 2026

Infostealers harvested 1.7 billion credentials in six months

Flashpoint recorded 7.4 million infostealer-infected devices in the first half of 2026, up 27% from the prior six months, with 1.7 billion credentials harvested across criminal ecosystems. Infosecurity Magazine, Aug. 17, 2026

AmnesiaStealer gives attackers live control of macOS browser sessions

AmnesiaStealer uses fake GitHub pages and ClickFix instructions to trick macOS users into running Terminal commands. A second stage clones browser profiles and gives attackers interactive control over authenticated Chromium sessions. SC Media, Aug. 14, 2026

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles