Weekly Cybersecurity Newsletter – Top 50 Stories (Aug 17–21) | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Welcome to this edition of the CyberPress weekly cybersecurity newsletter — your cybersecurity bulletin covering the 50 most important stories from August 17 to 21, 2026, organized day by day.

It was a heavy week for breaches and exploited flaws: Cl0p claimed 89 GB from Shell, stolen Azure credentials exposed millions of employee records, and suspected Chinese actors weaponized a VMware vCenter RCE into ESXi ransomware.

CISA sounded alarms on exploited vCenter, Windows IKE and Medusa ransomware, Microsoft patched a critical Entra ID RCE, and the DOJ charged 17 IRGC-linked hackers — all while AI stayed central, from Copilot’s CoSnitch flaw to agents finding 100+ bugs in days.

Everything below is curated into one weekly cybersecurity newsletter so you can scan the week in minutes and click through to the full analysis.

  FRIDAY · AUGUST 21, 2026

1   VULN   Critical Microsoft Entra ID RCE Flaw Allows Remote Attackers to Execute Code

Microsoft disclosed a critical Entra ID remote code execution flaw that lets attackers run code without authorization. Because Entra ID underpins cloud identity for countless organizations, the bug carries broad enterprise risk.

2   MALWARE   Microsoft-Signed Defender Driver Weaponized to Disable EDR and Antivirus

Attackers are abusing a legitimately Microsoft-signed Defender driver to disable EDR and antivirus at the kernel level. Turning a trusted security component into a defense-killer is a potent evasion technique.

3   BREACH   US Bank Examines Alleged Data Breach After LockBit Ransomware Extortion Claim

A US bank is investigating an alleged breach after the LockBit ransomware group made an extortion claim. Financial-sector incidents draw intense scrutiny given the sensitivity of the data involved.

4   MALWARE   Compromised Rust Crate onering Steals Source Code During Application Builds

A compromised Rust crate named onering steals source code while applications are being built. It is another supply-chain attack aimed squarely at developer pipelines.

5   ATTACK   China-Nexus SilkParasite APT Deploys Five New RATs Against Central Asian Governments

The China-nexus SilkParasite APT is deploying five new remote access trojans against Central Asian governments. The expanded toolset points to a sustained regional espionage campaign.

6   MALWARE   Manic Android Malware Steals Banking PINs and Takes Remote Control of Devices

The Manic Android malware steals banking PINs and can take full remote control of infected phones. Mobile banking users are the clear target of this fast-spreading threat.

7   AI   OpenAI Unveils Private Safety Processing for Zero Data Retention AI Deployments

OpenAI introduced Private Safety Processing to support zero-data-retention AI deployments for sensitive use cases. The feature aims to reconcile safety monitoring with strict privacy requirements.

8   VULN   Critical N-able Passportal Bug Lets Malicious Sites Access Password Vaults

A critical N-able Passportal flaw lets malicious websites reach into users’ password vaults. Compromising a credential manager can unlock an entire organization’s secrets at once.

9   MALWARE   Agent Tesla BEC Campaign Uses Emoji-Obfuscated JScript to Steal Credentials From 40+ Apps

An Agent Tesla business-email-compromise campaign hides its JScript payload behind emoji obfuscation to steal credentials from more than 40 apps. The trick helps the loader slip past static detection.

10   MALWARE   Hackers Use Fake Google Gemini App to Steal Windows Users’ Browser Credentials

Attackers are distributing a fake Google Gemini app that steals Windows users’ browser credentials. Riding the AI-branding wave has become a reliable lure for infostealers.

11   ATTACK   Peer2Profit AstroProxy Residential Proxy Network Exposes Internal Network Resources

Researchers found the Peer2Profit AstroProxy residential-proxy network exposing internal corporate resources. Employee devices enrolled in proxy schemes can quietly bridge attackers into private networks.

  THURSDAY · AUGUST 20, 2026

12   VULN   Critical Citrix NetScaler Authentication Bypass Flaw Exposes Gateway Appliances

A critical Citrix NetScaler authentication-bypass flaw exposes gateway appliances to takeover. Edge gateways are prime targets because they sit directly on the internet.

13   CRIME   DOJ Charges 17 Iranian Hackers in IRGC-Linked Cyber Espionage Campaign

The US Department of Justice charged 17 Iranian hackers tied to an IRGC-linked cyber-espionage campaign. The indictment underscores the continued state-sponsored threat to critical sectors.

14   ATTACK   NSA and CISA Warn of Active Cyber Threat Targeting Siemens S7 PLCs

NSA and CISA warned of active threats targeting Siemens S7 programmable logic controllers. Exposed industrial controllers remain among the highest-consequence risks in operational technology.

15   MALWARE   40 Malicious Firefox Extensions Steal Crypto Wallet Recovery Phrases and Private Keys

Researchers uncovered 40 malicious Firefox extensions that steal crypto wallet recovery phrases, private keys and credentials. Browser add-ons remain an easy way to reach a user’s most sensitive secrets.

16   AI   OpenAI Astra AI Model May Reach Critical Cyber Capability Threshold

OpenAI signaled that its Astra model may be approaching a critical cyber-capability threshold. Frontier models with strong offensive potential raise fresh dual-use concerns.

17   VULN   CRLF Header Injection Flaws Enable HTTP Request Smuggling and Cookie Theft

Newly detailed CRLF header-injection flaws enable HTTP request smuggling and cookie theft. The technique can let attackers hijack sessions across shared web infrastructure.

18   VULN   Cisco BroadWorks XXE Flaw Allows Unauthenticated Remote File Disclosure

A Cisco BroadWorks XXE flaw allows unauthenticated attackers to disclose remote files. XML external-entity bugs can expose configuration and credential material to outsiders.

19   PATCH   Microsoft Defender Update Causes Quick and Full Virus Scans to Crash

A faulty Microsoft Defender update caused quick and full virus scans to crash on Windows PCs. Reliability issues in built-in defenses can quietly leave endpoints unprotected.

20   MALWARE   Hackers Use Fake Claude, ChatGPT and Copilot Installers to Spread Malware

Attackers are distributing malware-laced fake installers for Claude, ChatGPT and Copilot. The surge in AI adoption has made popular assistant brands an irresistible lure.

21   MALWARE   New WordlistLoader Hides Shellcode in Plain English Words to Deliver Amatera Stealer

The new WordlistLoader conceals shellcode inside ordinary English words to deliver the Amatera stealer. Encoding payloads as text helps the loader evade content inspection.

22   MALWARE   Aeternum Botnet Hides C2 Infrastructure in Polygon Smart Contracts to Evade Takedowns

The Aeternum botnet stores its command-and-control infrastructure inside Polygon smart contracts. Anchoring C2 on-chain makes the operation highly resistant to takedowns.

23   VULN   CISA Warns of VMware vCenter Path Traversal Flaw Exploited in the Wild

CISA warned that a VMware vCenter path-traversal flaw is being actively exploited. Compromising vCenter can hand attackers control of an entire virtual estate.

24   AI   CoSnitch Microsoft Copilot Flaw Enables Silent Data Theft With a Single Click

The CoSnitch flaw in Microsoft Copilot enables silent data theft with a single click. AI assistants wired into corporate data become a powerful new exfiltration path.

25   BREACH   CISA Warns of Medusa Ransomware-as-a-Service Attacks Against Over 300 Organizations

CISA warned that Medusa ransomware-as-a-service has hit more than 300 organizations using double extortion. The advisory highlights how RaaS keeps scaling attacks across sectors.

26   VULN   CISA Warns of Windows IKE Flaw Allowing Unauthenticated Remote Code Execution

CISA flagged a Windows Internet Key Exchange flaw allowing unauthenticated remote code execution. Network-facing protocol bugs are especially dangerous because they need no user interaction.

27   AI   Google Agentic AI Finds Over 100 Critical Security Flaws in Just Two Days

Google’s agentic AI reportedly found more than 100 critical security flaws in source code within two days. It is a striking demonstration of AI-driven vulnerability discovery at scale.

28   INDUSTRY   Microsoft to Stop Security Updates for Windows 11 24H2 Home and Pro Editions

Microsoft announced it will stop security updates for Windows 11 24H2 Home and Pro editions. Users on the affected builds will need to upgrade to keep receiving fixes.

29   ATTACK   China-Nexus Hackers Target Myanmar Diplomats With Government-Themed QUICAgent Malware

China-nexus hackers are targeting Myanmar diplomats with government-themed QUICAgent malware. The campaign reflects continued espionage pressure on regional diplomatic targets.

30   BREACH   Cl0p Hackers Exploit PTC Windchill RCE Flaw to Deploy Custom Data-Theft Web Shell

Cl0p is exploiting a PTC Windchill RCE flaw to deploy a custom data-theft web shell. The group continues its pattern of weaponizing enterprise software flaws for mass extortion.

31   MALWARE   Hackers Turn Thousands of WordPress Sites Into StopAndProtect Malware Infrastructure

Attackers have turned thousands of WordPress sites into infrastructure spreading StopAndProtect malware via ClickFix. Compromised legitimate sites lend the campaign credibility and reach.

32   ATTACK   Suspected Chinese Hackers Turn VMware vCenter RCE Into Root Backdoors and ESXi Ransomware

Suspected Chinese hackers are turning a VMware vCenter RCE into root backdoors and ESXi ransomware. Owning virtualization management lets one flaw threaten an entire data center.

33   VULN   PoC Exploit Released for Microsoft SCCM Attack Chain From Domain User to SYSTEM

A proof-of-concept exploit was released for a Microsoft SCCM chain that escalates a domain user to SYSTEM. Public PoCs sharply increase the urgency of hardening configuration-management servers.

34   BREACH   Pokémon Center Data Breach Exposes Customer Names, Addresses and Order Details

A Pokémon Center breach exposed customer names, addresses and order details. Retail and fan-commerce sites remain attractive targets for data thieves.

35   VULN   GitLab Critical Vulnerability Lets Unauthenticated Attackers Modify or Delete Projects

A critical GitLab flaw lets unauthenticated attackers modify or delete projects. Tampering with source repositories can poison builds far downstream.

36   AI   Threat Actors Use Claude Code, Codex and DeepSeek AI to Power Cyberattacks

Researchers documented threat actors using Claude Code, Codex and DeepSeek to accelerate cyberattacks. AI coding tools are becoming force-multipliers on both sides of the fight.

37   AI   OpenAI Warns AI-Powered Attackers Can Find and Exploit Longstanding Security Flaws

OpenAI warned that AI-powered attackers can uncover and exploit longstanding security flaws. The company urged defenders to automate their own security to keep pace.

38   MALWARE   Shadow hVNC Lets Hackers Operate a Second Windows Desktop Invisible to the Victim

Shadow hVNC lets attackers operate a hidden second Windows desktop invisible to the victim. The covert session enables fraud and control without tipping off the user.

39   MALWARE   Hackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers are exploiting an MLflow SSRF flaw to steal cloud credentials and secrets. Machine-learning platforms increasingly sit on privileged cloud access, raising the stakes.

40   PATCH   Apple Patches Code Execution and Kernel Memory Flaws in iOS 26.6.1 and macOS 26.6.2

Apple shipped iOS 26.6.1 and macOS 26.6.2 to fix code-execution and kernel-memory flaws. Prompt updates are essential given the sensitivity of data on Apple devices.

41   ATTACK   Operation ASTERIX Processes 885,000 Phone Numbers to Find Crypto Users for Targeted Fraud

Operation ASTERIX processed 885,000 phone numbers to identify cryptocurrency users for targeted fraud. The industrial-scale profiling shows how organized crypto theft has become.

42   MALWARE   C2Looper Backdoor Uses GitHub C2 and Shellcode Injection to Establish Ransomware Footholds

The C2Looper backdoor uses GitHub for command-and-control and shellcode injection to plant ransomware footholds. Hiding C2 in trusted developer platforms complicates detection.

43   BREACH   Shell Investigates Data Breach After Cl0p Ransomware Group Claims 89 GB Data Theft

Shell is investigating a data breach after the Cl0p ransomware group claimed the theft of 89 GB of data. The claim adds a major energy company to Cl0p’s growing victim list.

44   MALWARE   ChainDrop npm Worm Hijacks GitHub Actions OIDC to Poison 444 Packages With Valid Provenance

The ChainDrop npm worm hijacks GitHub Actions OIDC to poison 444 packages while carrying valid SLSA provenance. Faking provenance undermines a key defense developers rely on to trust packages.

45   BREACH   Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records

Attackers used compromised Azure credentials to steal millions of enterprise employee records. Leaked cloud credentials remain one of the fastest routes to mass data theft.

46   VULN   GeoServer SQL Injection Vulnerability Lets Unauthenticated Attackers Execute Remote Code

A GeoServer SQL injection flaw lets unauthenticated attackers achieve remote code execution. Public geospatial servers are widely deployed across government and utilities.

47   VULN   Hackers Attempt to Exploit Critical SAP Commerce Cloud RCE Flaw

Attackers are attempting to exploit a critical SAP Commerce Cloud remote code execution flaw. Enterprise commerce platforms hold rich customer and payment data, raising the impact.

48   MALWARE   Windows Malware Corrupts PE Headers While Dropping Files to Evade On-Access Scanners

A Windows malware family corrupts PE headers as it drops files to evade on-access antivirus scanners. The trick lets payloads slip onto disk without triggering real-time detection.

49   MALWARE   Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT

A signed ClickOnce installer uses a Google Workspace decoy to deploy credential stealers and a RAT. The valid signature and familiar branding help it earn the victim’s trust.

50   ATTACK   Evooo1Bot Linux Botnet Hijacks Routers and Firewalls for DDoS, SOCKS5 Proxy and Credential Theft

The Evooo1Bot Linux botnet hijacks routers and firewalls for DDoS, SOCKS5 proxying and credential theft. Turning network defenses into attack infrastructure gives operators stealth and reach.

FREQUENTLY ASKED QUESTIONS  

What is the CyberPress weekly cybersecurity newsletter?

The CyberPress weekly cybersecurity newsletter is a once-a-week cybersecurity bulletin that rounds up the 50 most important stories of the week — vulnerabilities, cyber attacks, data breaches, AI threats and malware — organized day by day with links to the full analysis on cyberpress.org.

How is a cybersecurity bulletin different from daily security news?

A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns and breaches that actually matter in one weekly cybersecurity newsletter.

How do I subscribe to the CyberPress weekly cybersecurity newsletter?

Visit cyberpress.org and follow CyberPress on LinkedIn to receive every issue of the weekly cybersecurity newsletter. It is free and lands once a week, every week.

Found this cybersecurity bulletin useful? Subscribe to the CyberPress weekly cybersecurity newsletter — free, every week.

——————————————————-


Click Here For The Original Source.