Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

11 August 2026

AI-powered ransomware, widespread npm supply chain attacks, and new regulatory mandates define a turbulent week in cybersecurity.

One week of Security Weekly Digest, 8 stories, as published.

Exploited CVEs

CVE-2026-8037: Progress LoadMaster

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Why it matters — Confirmed exploited in the wild. CVSS 9.6 (CRITICAL). CISA remediation deadline 10 Aug 2026 — already passed.

CISA KEV · 11 August 2026 · Read the original →

Exploited CVEs

CVE-2026-63077: JetBrains TeamCity

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 08 Aug 2026 — already passed.

CISA KEV · 11 August 2026 · Read the original →

Exploited CVEs

CVE-2026-34486: Apache Tomcat

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Why it matters — Confirmed exploited in the wild. CVSS 7.5 (HIGH). CISA remediation deadline 07 Aug 2026 — already passed.

CISA KEV · 11 August 2026 · Read the original →

Supply Chain

ChainDrop npm Worm Infects 1,300+ Packages

A self-propagating worm named 'ChainDrop' compromised over 1,300 npm packages, with a combined 2 billion monthly downloads, after attackers hijacked a Keyv maintainer's GitHub account. The malware, an evolution of Shai-Hulud, steals credentials and spreads by publishing malicious updates with legitimate provenance.

Why it matters — Organizations using npm packages must audit their dependency trees for compromised versions and revoke any credentials exposed on developer workstations or CI/CD runners that executed affected packages.

bleepingcomputer.com · 11 August 2026 · Read the original →

Ransomware

FBI, NSA Warn of Gunra Ransomware Threat

The FBI, NSA, CISA, and South Korea's National Police Agency issued a joint advisory on Gunra ransomware, a RaaS operation that emerged in 2025 and targets critical infrastructure and government organizations. Gunra uses double extortion and exploits firewall/VPN vulnerabilities for initial access.

Why it matters — Organizations, especially critical infrastructure, must prioritize patching internet-facing VPNs and firewalls, implement immutable offline backups, and segment networks to prevent Gunra ransomware attacks.

The Record · 11 August 2026 · Read the original →

Policy & Compliance

FCC Mandates Stronger Emergency Alert Cybersecurity

The FCC implemented new cybersecurity rules for Emergency Alert System (EAS) participants, requiring stronger passwords, prompt security patch application, and network firewalls. This action aims to prevent emergency alert hijacking and modernize public warning systems, effective July 1, 2026.

Why it matters — EAS participants must immediately implement these baseline security controls to comply with new regulations and protect critical public warning infrastructure from cyberattacks.

Industrial Cyber · 11 August 2026 · Read the original →

Breaches

Unlimited Technology Systems Breach Impacts 3.8 Million

Healthcare software company Unlimited Technology Systems reported a data breach impacting over 3.8 million people, where an unauthorized actor accessed sensitive patient information from its commercial data center between October 5-10, 2025. Exposed data included names, SSNs, dates of birth, and medical information.

Why it matters — Healthcare providers using Unlimited Technology Systems must notify affected patients and offer identity protection services, while all organizations should review vendor security and incident response plans.

BleepingComputer · 11 August 2026 · Read the original →

Ransomware

China-Linked Storm-1175 Deploys StormEncryptor Ransomware

Microsoft disclosed that China-linked threat actor Storm-1175 is deploying a new ransomware strain, StormEncryptor, marking a shift from their previous use of Medusa ransomware. Initial access likely involves exploiting CVE-2026-18577 in N-able N-central, with rapid progression from access to encryption.

Why it matters — Organizations using N-able N-central must immediately patch CVE-2026-18577 and implement robust monitoring for rapid post-compromise activity to defend against Storm-1175.

The Hacker News · 11 August 2026 · Read the original →

In case anyone was wondering where this sprint's capacity went.

8 stories, every Tuesday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →