These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
CISA added CVE-2025-62593, a code injection flaw in the Ray AI compute framework, to its Known Exploited Vulnerabilities catalog on August 17, 2026, citing evidence of active exploitation. The bug lets an attacker combine a trivial User-Agent header bypass with a DNS rebinding attack so that simply visiting a malicious webpage in Firefox or Safari can hand a remote attacker code execution on a developer’s local Ray instance, no exposed dashboard required. It follows the 2024 ShadowRay campaign, which found thousands of Ray clusters compromised for crypto mining and credential theft after being left open to the internet with no authentication at all.
The Dutch National Cyber Security Centrum has warned that CVE-2026-65400, an authentication bypass in macOS Screen Sharing that Apple patched on August 6, is being actively exploited against Macs with the service reachable from the internet. CISA rescored the flaw from 7.1 to a critical 9.8 after every reported case ended the same way: an unauthenticated attacker walks straight to root access and installs a Monero cryptocurrency miner. A public proof-of-concept exploit is now circulating, and any Mac still running an unpatched OS with port 5900 open is exposed.
A facility infrastructure issue at Equinix’s FR5 site in Frankfurt on August 15, 2026, degraded AWS Direct Connect for customers whose connections terminated solely at that location, with unverified reports pointing to a cooling failure caused by a water leak. Customers running multi-site or redundant Direct Connect configurations were unaffected; those who were not had to fail over to VPN or sit with packet loss until AWS restored the underlying network equipment. It is a narrow, contained incident, and that is exactly what makes it a useful test case for European organisations that treat a single cloud region, or a single physical facility within it, as sufficient.
Coverage of Microsoft’s August 2026 Patch Tuesday has focused on CVE-2026-68820, the Windows privilege escalation flaw North Korea’s Lazarus Group exploited before a fix existed. Sitting in the same 421-bug release is CVE-2026-62878, a maximum-severity, CVSS 9.8 stack-based buffer overflow in Windows DNS Server that Zero Day Initiative researchers flagged as wormable and reachable, unauthenticated, on virtually every Windows Server domain network from an internal or external position. It has not been confirmed exploited in the wild yet. Given how easy it is to trigger and how central DNS is to every Active Directory environment, that is a narrow window, not a reason to wait.
OVHcloud used the InCyber Forum 2026 to announce it is accelerating a dedicated defence unit for European militaries, recruiting armed forces and defence industry experts cleared to work on ‘secret’ classified projects, built on France’s SecNumCloud qualification. The announcement lands in the same month OVHcloud was named the only European vendor to reach Challenger status in Gartner’s July 2026 Magic Quadrant for Cloud AI Infrastructure, a recognition it is tying directly to digital sovereignty, price transparency and open technologies. For European organisations still assuming a sovereign cloud alternative to AWS, Azure and Google Cloud is not yet mature enough for serious workloads, this is evidence that assumption needs revisiting.
TheGentlemen, a ransomware-as-a-service operation launched just a year ago by a former Qilin affiliate, posted 300 victims in Q2 2026 to become the most active ransomware group on record, after a 588 percent surge in Q1. Microsoft’s analysis of its Go-based encryptor found it self-propagates across a network once inside, reducing how much an attacker has to do by hand after the initial break-in. Two more victims, an Italian recycling firm and a Swiss property management company, were added to its leak site on 13 and 14 August, a reminder that this group is not only chasing headline targets.
Adobe shipped an out-of-cycle security update, APSB26-92, on 11 August fixing seven Commerce and Magento Open Source flaws, five of them critical. The standout is CVE-2026-71362, a CVSS 9.1 incorrect authorization bug that lets an unauthenticated attacker swap an active session onto a different customer’s account, no password, no admin access, no user interaction required. Adobe said it had no evidence of exploitation at patch time. Within days, eCommerce security firm Sansec said its Shield firewall was already blocking live attempts against it.
The European Commission’s 24 June proposal to reform the Europol Regulation would roughly double the agency’s budget to 3 billion euros for 2028-2034 and expand its staff and technical capabilities. The European Data Protection Supervisor has now weighed in with an opinion stating the proposal, as written, does not provide sufficient safeguards, calling for effective oversight and enforcement mechanisms before Europol’s legal mandate grows. It is the same institution that took legal action over the last Europol reform in 2022 on near-identical grounds.
CVE-2026-55040, a critical JWT validation bypass in on-premises SharePoint Server that lets an unauthenticated attacker forge a token and impersonate any user, including administrators, is now being exploited using a researcher’s own published proof of concept. Honeypot operator Defused recorded eight exploitation attempts on 12 and 13 August alone, and Shadowserver counts more than 8,500 SharePoint servers still reachable from the open internet this week.
Three days after this outlet covered the maximum-severity Metabase SQL injection flaw being exploited against Framework and Tally, Czech hardware wallet maker Trezor has disclosed that the same vulnerability, exploited at its fulfilment partner ShipMonk, exposed names, emails, phone numbers and shipping addresses for 13,689 customers across the US, UK, Sweden, Italy and Portugal. CISA’s federal patch deadline for the underlying CVE, added to its Known Exploited Vulnerabilities catalog on 11 August, falls today.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.