Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 7, 2026

Immediate priority is mitigating active AitM phishing campaigns targeting Microsoft 365 financial workflows and patching critical vulnerabilities in Azure, Entra, and Cisco networking gear. We are also seeing a rise in AI-driven attack vectors targeting CI/CD pipelines and the discovery of novel session hijacking techniques via NAT manipulation.

Compiled by the Slugnet Editorial System. Published Aug 7, 2026, 8:03 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

The audio edition is not available yet.

  1. 01
    The Hacker News

    Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

    What happened

    A widespread phishing campaign is using adversary-in-the-middle (AitM) techniques and residential proxies to hijack Microsoft 365 accounts. Attackers are specifically targeting personnel involved in financial workflows to exfiltrate payroll and finance emails.

    Why it ranks #1

    Confirmed active exploitation of identity infrastructure with immediate enterprise exposure, placing it in the highest urgency tier.

    Who should care

    CISOs and security leaders, Identity and access teams, SOC and incident response teams

    What to do

    Enable phishing-resistant MFA and monitor for anomalous sign-ins from residential proxy ranges.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    SecurityWeek

    Microsoft, Apple Release Fresh Security Updates

    What happened

    Microsoft and Apple have released security updates addressing critical vulnerabilities in Azure, Entra, and SharePoint, as well as a high-severity authentication bypass in Apple products.

    Why it ranks #2

    Critical vulnerabilities in widely used enterprise identity and cloud infrastructure (Azure/Entra) take priority over general research.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply the latest security patches for Azure, Entra, SharePoint, and Apple OS.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs

    What happened

    Cisco patched 12 vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three flaws with a CVSS score of 9.9. These issues were identified during an internal security review and affect devices regardless of configuration.

    Why it ranks #3

    High-impact vulnerabilities in core enterprise networking infrastructure with critical severity scores.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Update Cisco Catalyst SD-WAN and IOS XE Software to the latest patched versions.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    SecurityWeek

    Critical Vulnerabilities Patched With Chrome 151 Update

    What happened

    Chrome 151 addresses over two dozen memory safety bugs, including critical use-after-free vulnerabilities. These flaws could potentially be leveraged for remote code execution.

    Why it ranks #4

    Critical vulnerabilities in a ubiquitous enterprise web browser represent significant exposure.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Ensure all managed browsers are updated to Chrome version 151 or higher.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

    What happened

    Flaws in Claude Code and Gemini CLI allow attackers to execute code on CI runners or hijack agent runs via GitHub issues. The attack succeeds using default vendor configurations, potentially exposing CI workflow secrets.

    Why it ranks #5

    High-impact vulnerabilities in AI developer tools that directly impact the software supply chain and secret management.

    Who should care

    Application security teams, Cloud security teams

    What to do

    Review CI/CD permissions for AI agents and avoid default configurations that allow untrusted GitHub issues to trigger workflows.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

    What happened

    Research demonstrates that malware in a signed-in Windows session can abuse Windows Hello for Business keys to authenticate to Microsoft Entra ID. This allows attackers to obtain Primary Refresh Tokens (PRT) and establish persistent cloud access.

    Why it ranks #6

    Material threat actor operation technique targeting enterprise identity and persistence mechanisms.

    Who should care

    Identity and access teams, SOC and incident response teams

    What to do

    Implement strict conditional access policies to limit the impact of compromised PRTs.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    SecurityWeek

    3.8 Million Impacted by Unlimited Technology Systems Data Breach

    What happened

    A data breach at Unlimited Technology Systems has impacted 3.8 million individuals. Attackers exfiltrated personal, medical, and health insurance information from the company's data center.

    Why it ranks #7

    Material large-scale data breach involving sensitive PII and PHI.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

    What happened

    The NatJack attack class manipulates NAT connection states to hijack TCP sessions and spoof DNS responses. The research indicates this behavior exists across multiple independent implementations, including Windows.

    Why it ranks #8

    Novel technique with operational consequences for network security and session integrity.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

    What happened

    The Zapscape vulnerability (CVE-2026-64561) allows a privileged L1 guest in a KVM/x86 environment to escape isolation and execute code on the Linux host. This risk is present when nested virtualization is exposed to untrusted guests.

    Why it ranks #9

    High-impact vulnerability in cloud/virtualization infrastructure, though requiring specific configurations (nested virtualization).

    Who should care

    Cloud security teams, IT and platform operations

    What to do

    Disable nested virtualization for untrusted guests or apply kernel patches.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    The Hacker News

    AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

    What happened

    PortSwigger's AI-assisted HTTP Terminator discovered novel HTTP desynchronization techniques and a zero-day in Apache Traffic Server. The system proved these vectors by exploring 30,000 candidate attack paths.

    Why it ranks #10

    Substantial research demonstrating how AI can be used to find complex application-layer vulnerabilities like HTTP desync.

    Who should care

    Application security teams, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email