Welcome to this edition of the CyberPress weekly cybersecurity newsletter — your cybersecurity bulletin covering the 50 most important stories from August 17 to 21, 2026, organized day by day.
It was a heavy week for breaches and exploited flaws: Cl0p claimed 89 GB from Shell, stolen Azure credentials exposed millions of employee records, and suspected Chinese actors weaponized a VMware vCenter RCE into ESXi ransomware.
CISA sounded alarms on exploited vCenter, Windows IKE and Medusa ransomware, Microsoft patched a critical Entra ID RCE, and the DOJ charged 17 IRGC-linked hackers — all while AI stayed central, from Copilot’s CoSnitch flaw to agents finding 100+ bugs in days.
Everything below is curated into one weekly cybersecurity newsletter so you can scan the week in minutes and click through to the full analysis.
FRIDAY · AUGUST 21, 2026
1 VULN Critical Microsoft Entra ID RCE Flaw Allows Remote Attackers to Execute Code
Microsoft disclosed a critical Entra ID remote code execution flaw that lets attackers run code without authorization. Because Entra ID underpins cloud identity for countless organizations, the bug carries broad enterprise risk.
2 MALWARE Microsoft-Signed Defender Driver Weaponized to Disable EDR and Antivirus
Attackers are abusing a legitimately Microsoft-signed Defender driver to disable EDR and antivirus at the kernel level. Turning a trusted security component into a defense-killer is a potent evasion technique.
3 BREACH US Bank Examines Alleged Data Breach After LockBit Ransomware Extortion Claim
A US bank is investigating an alleged breach after the LockBit ransomware group made an extortion claim. Financial-sector incidents draw intense scrutiny given the sensitivity of the data involved.
4 MALWARE Compromised Rust Crate onering Steals Source Code During Application Builds
A compromised Rust crate named onering steals source code while applications are being built. It is another supply-chain attack aimed squarely at developer pipelines.
5 ATTACK China-Nexus SilkParasite APT Deploys Five New RATs Against Central Asian Governments
The China-nexus SilkParasite APT is deploying five new remote access trojans against Central Asian governments. The expanded toolset points to a sustained regional espionage campaign.
6 MALWARE Manic Android Malware Steals Banking PINs and Takes Remote Control of Devices
The Manic Android malware steals banking PINs and can take full remote control of infected phones. Mobile banking users are the clear target of this fast-spreading threat.
7 AI OpenAI Unveils Private Safety Processing for Zero Data Retention AI Deployments
OpenAI introduced Private Safety Processing to support zero-data-retention AI deployments for sensitive use cases. The feature aims to reconcile safety monitoring with strict privacy requirements.
8 VULN Critical N-able Passportal Bug Lets Malicious Sites Access Password Vaults
A critical N-able Passportal flaw lets malicious websites reach into users’ password vaults. Compromising a credential manager can unlock an entire organization’s secrets at once.
9 MALWARE Agent Tesla BEC Campaign Uses Emoji-Obfuscated JScript to Steal Credentials From 40+ Apps
An Agent Tesla business-email-compromise campaign hides its JScript payload behind emoji obfuscation to steal credentials from more than 40 apps. The trick helps the loader slip past static detection.
10 MALWARE Hackers Use Fake Google Gemini App to Steal Windows Users’ Browser Credentials
Attackers are distributing a fake Google Gemini app that steals Windows users’ browser credentials. Riding the AI-branding wave has become a reliable lure for infostealers.
11 ATTACK Peer2Profit AstroProxy Residential Proxy Network Exposes Internal Network Resources
Researchers found the Peer2Profit AstroProxy residential-proxy network exposing internal corporate resources. Employee devices enrolled in proxy schemes can quietly bridge attackers into private networks.
THURSDAY · AUGUST 20, 2026
12 VULN Critical Citrix NetScaler Authentication Bypass Flaw Exposes Gateway Appliances
A critical Citrix NetScaler authentication-bypass flaw exposes gateway appliances to takeover. Edge gateways are prime targets because they sit directly on the internet.
13 CRIME DOJ Charges 17 Iranian Hackers in IRGC-Linked Cyber Espionage Campaign
The US Department of Justice charged 17 Iranian hackers tied to an IRGC-linked cyber-espionage campaign. The indictment underscores the continued state-sponsored threat to critical sectors.
14 ATTACK NSA and CISA Warn of Active Cyber Threat Targeting Siemens S7 PLCs
NSA and CISA warned of active threats targeting Siemens S7 programmable logic controllers. Exposed industrial controllers remain among the highest-consequence risks in operational technology.
15 MALWARE 40 Malicious Firefox Extensions Steal Crypto Wallet Recovery Phrases and Private Keys
Researchers uncovered 40 malicious Firefox extensions that steal crypto wallet recovery phrases, private keys and credentials. Browser add-ons remain an easy way to reach a user’s most sensitive secrets.
16 AI OpenAI Astra AI Model May Reach Critical Cyber Capability Threshold
OpenAI signaled that its Astra model may be approaching a critical cyber-capability threshold. Frontier models with strong offensive potential raise fresh dual-use concerns.
17 VULN CRLF Header Injection Flaws Enable HTTP Request Smuggling and Cookie Theft
Newly detailed CRLF header-injection flaws enable HTTP request smuggling and cookie theft. The technique can let attackers hijack sessions across shared web infrastructure.
18 VULN Cisco BroadWorks XXE Flaw Allows Unauthenticated Remote File Disclosure
A Cisco BroadWorks XXE flaw allows unauthenticated attackers to disclose remote files. XML external-entity bugs can expose configuration and credential material to outsiders.
19 PATCH Microsoft Defender Update Causes Quick and Full Virus Scans to Crash
A faulty Microsoft Defender update caused quick and full virus scans to crash on Windows PCs. Reliability issues in built-in defenses can quietly leave endpoints unprotected.
20 MALWARE Hackers Use Fake Claude, ChatGPT and Copilot Installers to Spread Malware
Attackers are distributing malware-laced fake installers for Claude, ChatGPT and Copilot. The surge in AI adoption has made popular assistant brands an irresistible lure.
21 MALWARE New WordlistLoader Hides Shellcode in Plain English Words to Deliver Amatera Stealer
The new WordlistLoader conceals shellcode inside ordinary English words to deliver the Amatera stealer. Encoding payloads as text helps the loader evade content inspection.
22 MALWARE Aeternum Botnet Hides C2 Infrastructure in Polygon Smart Contracts to Evade Takedowns
The Aeternum botnet stores its command-and-control infrastructure inside Polygon smart contracts. Anchoring C2 on-chain makes the operation highly resistant to takedowns.
23 VULN CISA Warns of VMware vCenter Path Traversal Flaw Exploited in the Wild
CISA warned that a VMware vCenter path-traversal flaw is being actively exploited. Compromising vCenter can hand attackers control of an entire virtual estate.
24 AI CoSnitch Microsoft Copilot Flaw Enables Silent Data Theft With a Single Click
The CoSnitch flaw in Microsoft Copilot enables silent data theft with a single click. AI assistants wired into corporate data become a powerful new exfiltration path.
25 BREACH CISA Warns of Medusa Ransomware-as-a-Service Attacks Against Over 300 Organizations
CISA warned that Medusa ransomware-as-a-service has hit more than 300 organizations using double extortion. The advisory highlights how RaaS keeps scaling attacks across sectors.
26 VULN CISA Warns of Windows IKE Flaw Allowing Unauthenticated Remote Code Execution
CISA flagged a Windows Internet Key Exchange flaw allowing unauthenticated remote code execution. Network-facing protocol bugs are especially dangerous because they need no user interaction.
27 AI Google Agentic AI Finds Over 100 Critical Security Flaws in Just Two Days
Google’s agentic AI reportedly found more than 100 critical security flaws in source code within two days. It is a striking demonstration of AI-driven vulnerability discovery at scale.
28 INDUSTRY Microsoft to Stop Security Updates for Windows 11 24H2 Home and Pro Editions
Microsoft announced it will stop security updates for Windows 11 24H2 Home and Pro editions. Users on the affected builds will need to upgrade to keep receiving fixes.
29 ATTACK China-Nexus Hackers Target Myanmar Diplomats With Government-Themed QUICAgent Malware
China-nexus hackers are targeting Myanmar diplomats with government-themed QUICAgent malware. The campaign reflects continued espionage pressure on regional diplomatic targets.
30 BREACH Cl0p Hackers Exploit PTC Windchill RCE Flaw to Deploy Custom Data-Theft Web Shell
Cl0p is exploiting a PTC Windchill RCE flaw to deploy a custom data-theft web shell. The group continues its pattern of weaponizing enterprise software flaws for mass extortion.
31 MALWARE Hackers Turn Thousands of WordPress Sites Into StopAndProtect Malware Infrastructure
Attackers have turned thousands of WordPress sites into infrastructure spreading StopAndProtect malware via ClickFix. Compromised legitimate sites lend the campaign credibility and reach.
32 ATTACK Suspected Chinese Hackers Turn VMware vCenter RCE Into Root Backdoors and ESXi Ransomware
Suspected Chinese hackers are turning a VMware vCenter RCE into root backdoors and ESXi ransomware. Owning virtualization management lets one flaw threaten an entire data center.
33 VULN PoC Exploit Released for Microsoft SCCM Attack Chain From Domain User to SYSTEM
A proof-of-concept exploit was released for a Microsoft SCCM chain that escalates a domain user to SYSTEM. Public PoCs sharply increase the urgency of hardening configuration-management servers.
34 BREACH Pokémon Center Data Breach Exposes Customer Names, Addresses and Order Details
A Pokémon Center breach exposed customer names, addresses and order details. Retail and fan-commerce sites remain attractive targets for data thieves.
35 VULN GitLab Critical Vulnerability Lets Unauthenticated Attackers Modify or Delete Projects
A critical GitLab flaw lets unauthenticated attackers modify or delete projects. Tampering with source repositories can poison builds far downstream.
36 AI Threat Actors Use Claude Code, Codex and DeepSeek AI to Power Cyberattacks
Researchers documented threat actors using Claude Code, Codex and DeepSeek to accelerate cyberattacks. AI coding tools are becoming force-multipliers on both sides of the fight.
37 AI OpenAI Warns AI-Powered Attackers Can Find and Exploit Longstanding Security Flaws
OpenAI warned that AI-powered attackers can uncover and exploit longstanding security flaws. The company urged defenders to automate their own security to keep pace.
38 MALWARE Shadow hVNC Lets Hackers Operate a Second Windows Desktop Invisible to the Victim
Shadow hVNC lets attackers operate a hidden second Windows desktop invisible to the victim. The covert session enables fraud and control without tipping off the user.
39 MALWARE Hackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Attackers are exploiting an MLflow SSRF flaw to steal cloud credentials and secrets. Machine-learning platforms increasingly sit on privileged cloud access, raising the stakes.
40 PATCH Apple Patches Code Execution and Kernel Memory Flaws in iOS 26.6.1 and macOS 26.6.2
Apple shipped iOS 26.6.1 and macOS 26.6.2 to fix code-execution and kernel-memory flaws. Prompt updates are essential given the sensitivity of data on Apple devices.
41 ATTACK Operation ASTERIX Processes 885,000 Phone Numbers to Find Crypto Users for Targeted Fraud
Operation ASTERIX processed 885,000 phone numbers to identify cryptocurrency users for targeted fraud. The industrial-scale profiling shows how organized crypto theft has become.
42 MALWARE C2Looper Backdoor Uses GitHub C2 and Shellcode Injection to Establish Ransomware Footholds
The C2Looper backdoor uses GitHub for command-and-control and shellcode injection to plant ransomware footholds. Hiding C2 in trusted developer platforms complicates detection.
43 BREACH Shell Investigates Data Breach After Cl0p Ransomware Group Claims 89 GB Data Theft
Shell is investigating a data breach after the Cl0p ransomware group claimed the theft of 89 GB of data. The claim adds a major energy company to Cl0p’s growing victim list.
44 MALWARE ChainDrop npm Worm Hijacks GitHub Actions OIDC to Poison 444 Packages With Valid Provenance
The ChainDrop npm worm hijacks GitHub Actions OIDC to poison 444 packages while carrying valid SLSA provenance. Faking provenance undermines a key defense developers rely on to trust packages.
45 BREACH Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records
Attackers used compromised Azure credentials to steal millions of enterprise employee records. Leaked cloud credentials remain one of the fastest routes to mass data theft.
46 VULN GeoServer SQL Injection Vulnerability Lets Unauthenticated Attackers Execute Remote Code
A GeoServer SQL injection flaw lets unauthenticated attackers achieve remote code execution. Public geospatial servers are widely deployed across government and utilities.
47 VULN Hackers Attempt to Exploit Critical SAP Commerce Cloud RCE Flaw
Attackers are attempting to exploit a critical SAP Commerce Cloud remote code execution flaw. Enterprise commerce platforms hold rich customer and payment data, raising the impact.
48 MALWARE Windows Malware Corrupts PE Headers While Dropping Files to Evade On-Access Scanners
A Windows malware family corrupts PE headers as it drops files to evade on-access antivirus scanners. The trick lets payloads slip onto disk without triggering real-time detection.
49 MALWARE Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT
A signed ClickOnce installer uses a Google Workspace decoy to deploy credential stealers and a RAT. The valid signature and familiar branding help it earn the victim’s trust.
50 ATTACK Evooo1Bot Linux Botnet Hijacks Routers and Firewalls for DDoS, SOCKS5 Proxy and Credential Theft
The Evooo1Bot Linux botnet hijacks routers and firewalls for DDoS, SOCKS5 proxying and credential theft. Turning network defenses into attack infrastructure gives operators stealth and reach.
FREQUENTLY ASKED QUESTIONS
What is the CyberPress weekly cybersecurity newsletter?
The CyberPress weekly cybersecurity newsletter is a once-a-week cybersecurity bulletin that rounds up the 50 most important stories of the week — vulnerabilities, cyber attacks, data breaches, AI threats and malware — organized day by day with links to the full analysis on cyberpress.org.
How is a cybersecurity bulletin different from daily security news?
A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns and breaches that actually matter in one weekly cybersecurity newsletter.
How do I subscribe to the CyberPress weekly cybersecurity newsletter?
Visit cyberpress.org and follow CyberPress on LinkedIn to receive every issue of the weekly cybersecurity newsletter. It is free and lands once a week, every week.
Found this cybersecurity bulletin useful? Subscribe to the CyberPress weekly cybersecurity newsletter — free, every week.
