Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

25 August 2026

9 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.

One week of Security Weekly Digest, 9 stories, as published.

Exploited CVEs

CVE-2026-21962: HTTP Server and Oracle Weblogic Server Proxy Plug-in

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 27 Aug 2026 — 2 days out.

CISA KEV · 25 August 2026 · Read the original →

Exploited CVEs

CVE-2026-64849: MLflow

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Why it matters — Confirmed exploited in the wild. CVSS 9.3 (CRITICAL). CISA remediation deadline 02 Sep 2026 — 8 days out.

CISA KEV · 25 August 2026 · Read the original →

Exploited CVEs

CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 21 Aug 2026 — already passed.

CISA KEV · 25 August 2026 · Read the original →

Exploited CVEs

CVE-2026-59310: Broadcom VMware vCenter

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 21 Aug 2026 — already passed.

CISA KEV · 25 August 2026 · Read the original →

Exploited CVEs

CVE-2026-65400: Apple macOS

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 21 Aug 2026 — already passed.

CISA KEV · 25 August 2026 · Read the original →

Ransomware

CISA Updates Medusa Ransomware Advisory

CISA, FBI, and HHS updated their joint advisory on Medusa ransomware on August 18, 2026, detailing expanded techniques and tooling, including faster exploitation of unpatched vulnerabilities and improved post-exploitation capabilities. Medusa actors have impacted over 500 critical infrastructure organizations.

Why it matters — Organizations must prioritize patching and implement enhanced incident response to counter Medusa's rapid exploitation and stealthier post-exploitation tactics.

CISA · 25 August 2026 · Read the original →

Vulnerabilities

CISA Adds Actively Exploited Vulnerabilities to KEV

On August 18, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: VMware vCenter (CVE-2026-59310), Microsoft SharePoint (CVE-2026-55040), Windows IKE Service Extensions (CVE-2026-33824), and Apple macOS (CVE-2026-65400), indicating active exploitation in the wild.

Why it matters — Federal agencies must patch these actively exploited flaws by August 21, 2026, and all organizations should assume compromise if unpatched.

CISA · 25 August 2026 · Read the original →

Threat Actors

Ransom Busters Impersonates Incident Responders

A ransomware affiliate, 'Ransom Busters,' is contacting victims of ransomware attacks, claiming to have infiltrated the attackers' servers and offering to delete stolen data and provide encryption keys for a fee between $20,000 and $60,000.

Why it matters — Organizations should be wary of unsolicited recovery offers from third parties, as they may be deceptive tactics by the original attackers to extort further payments.

The Hacker News · 25 August 2026 · Read the original →

Threat Actors

Doubloon Dredger Abuses Notion for Token Harvesting

The financially motivated threat actor 'Doubloon Dredger' is abusing free Notion accounts, malicious PDFs, and device code phishing to harvest authentication tokens from targeted organizations. The attacks involve impersonating senior executives to send document-sharing notifications.

Why it matters — Organizations using Notion should educate users about phishing tactics and implement strong authentication, as legitimate platform abuse bypasses traditional email security.

Infosecurity Magazine · 25 August 2026 · Read the original →

Go ahead and clear your calendar; the backlog has already been decided.

9 stories, every Tuesday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →