Cyber Brief · Aug 19 · 12 stories
Wednesday, August 19, 2026 · sent to 1 subscribers
News
· The Hacker News · Aug 18
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.
According to in…
News
· BleepingComputer · Aug 19
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
News
· The Hacker News · Aug 19
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest.
The cybersecurity company char…
Advisories
· CISA · Aug 18
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.
The following versions of CISA Malcolm are affected:
Malcolm <26.06.1 (CVE-2026-55676)
Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134…
Advisories
· CISA · Aug 18
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-55040 Microsoft SharePoint Weak Authentication V…
News
· BleepingComputer · Aug 18
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
News
· CSO Online · Aug 18
GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw.
…
News
· CSO Online · Aug 18
In recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evolution in cyber capabil…
News
· Help Net Security · Aug 19
Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called t…
News
· Help Net Security · Aug 18
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 befo…
News
· SecurityWeek · Aug 19
The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs.
The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek.
News
· SecurityWeek · Aug 19
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.