11 August 2026
AI-powered ransomware, widespread npm supply chain attacks, and new regulatory mandates define a turbulent week in cybersecurity.
CVE-2026-8037: Progress LoadMaster
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
CISA KEV · 11 August 2026 · Read the original →
CVE-2026-63077: JetBrains TeamCity
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CISA KEV · 11 August 2026 · Read the original →
CVE-2026-34486: Apache Tomcat
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
CISA KEV · 11 August 2026 · Read the original →
ChainDrop npm Worm Infects 1,300+ Packages
A self-propagating worm named 'ChainDrop' compromised over 1,300 npm packages, with a combined 2 billion monthly downloads, after attackers hijacked a Keyv maintainer's GitHub account. The malware, an evolution of Shai-Hulud, steals credentials and spreads by publishing malicious updates with legitimate provenance.
bleepingcomputer.com · 11 August 2026 · Read the original →
FBI, NSA Warn of Gunra Ransomware Threat
The FBI, NSA, CISA, and South Korea's National Police Agency issued a joint advisory on Gunra ransomware, a RaaS operation that emerged in 2025 and targets critical infrastructure and government organizations. Gunra uses double extortion and exploits firewall/VPN vulnerabilities for initial access.
The Record · 11 August 2026 · Read the original →
FCC Mandates Stronger Emergency Alert Cybersecurity
The FCC implemented new cybersecurity rules for Emergency Alert System (EAS) participants, requiring stronger passwords, prompt security patch application, and network firewalls. This action aims to prevent emergency alert hijacking and modernize public warning systems, effective July 1, 2026.
Industrial Cyber · 11 August 2026 · Read the original →
Unlimited Technology Systems Breach Impacts 3.8 Million
Healthcare software company Unlimited Technology Systems reported a data breach impacting over 3.8 million people, where an unauthorized actor accessed sensitive patient information from its commercial data center between October 5-10, 2025. Exposed data included names, SSNs, dates of birth, and medical information.
BleepingComputer · 11 August 2026 · Read the original →
China-Linked Storm-1175 Deploys StormEncryptor Ransomware
Microsoft disclosed that China-linked threat actor Storm-1175 is deploying a new ransomware strain, StormEncryptor, marking a shift from their previous use of Medusa ransomware. Initial access likely involves exploiting CVE-2026-18577 in N-able N-central, with rapid progression from access to encryption.
The Hacker News · 11 August 2026 · Read the original →
In case anyone was wondering where this sprint's capacity went.
8 stories, every Tuesday
Published here every week. Follow by RSS to get it as it lands.