Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 12, 2026

Immediate priority must be given to patching VMware vCenter and Cisco firewalls due to confirmed active exploitation of critical remote vulnerabilities. The broader landscape is dominated by a massive Microsoft Patch Tuesday and emerging supply chain risks targeting AI infrastructure.

Compiled by the Slugnet Editorial System. Published Aug 12, 2026, 8:07 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    What happened

    Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom VMware vCenter. This flaw, tracked as CVE-2026-59310 with a CVSS score of 9.8, allows unauthenticated attackers with network access to execute arbitrary code.

    Why it ranks #1

    Confirmed active exploitation of a critical vulnerability in core enterprise virtualization infrastructure takes top priority over other vulnerabilities and breaches.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply the available patches for VMware vCenter immediately.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

    What happened

    Cisco has warned of a high-severity vulnerability in Secure Firewall ASA and FTD software being exploited in the wild. CVE-2026-20349 allows unauthenticated remote attackers to trigger a denial-of-service condition by sending crafted HTTP requests.

    Why it ranks #2

    Confirmed active exploitation of edge security infrastructure is highly urgent, though ranked below vCenter due to the impact being DoS rather than RCE.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Update Cisco ASA and FTD software to the latest patched versions.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    Help Net Security

    Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

    What happened

    Microsoft's August 2026 Patch Tuesday addresses over 400 vulnerabilities, including a zero-day under active attack. CVE-2026-68820 is a use-after-free flaw in the Windows Ancillary Function Driver that allows local attackers to elevate privileges to SYSTEM.

    Why it ranks #3

    Active exploitation of a Windows kernel driver for privilege escalation is critical, but requires initial access, placing it below remote edge exploits.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Deploy August 2026 security updates across all Windows endpoints.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Help Net Security

    Lazarus hackers pair fake job offers with Windows zero-day exploit

    What happened

    The Lazarus group is targeting the defense sector using fake job offers and trojanized PDF software. These attacks leverage a Windows zero-day to gain system access as part of Operation Dream Job.

    Why it ranks #4

    Active threat actor campaign utilizing a zero-day represents immediate enterprise exposure, though targeted specifically at the defense sector.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    SecurityWeek

    Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    What happened

    A supply chain attack on LiteLLM, originating from a compromise of Trivy, has impacted over 2,500 organizations. Malicious releases distributed credential-stealing malware capable of harvesting cloud keys and Kubernetes tokens.

    Why it ranks #5

    Material supply chain compromise affecting AI infrastructure with high organizational impact falls into the third urgency tier.

    Who should care

    Application security teams, Cloud security teams, SOC and incident response teams

    What to do

    Audit LiteLLM installations and rotate any potentially exposed cloud or Kubernetes secrets.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

    What happened

    Adobe has patched three critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. CVE-2026-48362 is a CVSS 10.0 command injection flaw that could lead to arbitrary code execution.

    Why it ranks #6

    Critical high-impact vulnerability in widely used enterprise web infrastructure (CVSS 10) without confirmed active exploitation yet.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Update Adobe ColdFusion and related products to the latest versions.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

    What happened

    SAP released a patch for a maximum-severity flaw in Commerce Cloud (Data Hub Adapter). CVE-2026-58231, rated 10.0 on the CVSS scale, allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks.

    Why it ranks #7

    Another CVSS 10.0 vulnerability in enterprise infrastructure; ranked below Adobe due to narrower product scope (Data Hub Adapter).

    Who should care

    Application security teams, IT and platform operations

    What to do

    Apply the SAP Commerce Cloud security patch for CVE-2026-58231.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    BleepingComputer

    New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

    What happened

    A new Microsoft Defender zero-day exploit named ShieldBreak has been released. The exploit demonstrates a patch bypass for CVE-2026-50656, granting the attacker SYSTEM privileges on Windows.

    Why it ranks #8

    High-impact vulnerability in security software (Defender) that bypasses existing patches; however, it is currently a PoC release rather than confirmed wide exploitation.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

    What happened

    Flaws in Zoom's annotation tool could allow a meeting participant to hijack another attendee's client. The vulnerability requires no user interaction, such as clicks or downloads, beyond participating in the meeting.

    Why it ranks #9

    High-impact vulnerability in widely used collaboration software with zero-interaction requirements, though less critical than server-side RCEs.

    Who should care

    CISOs and security leaders, IT and platform operations

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Schneier on Security

    Prompt Injections for Defense

    What happened

    Researchers found that placing specific prompt injections alongside secrets in Amazon Web Services can neutralize AI hacking agents. These prompts trick the attacking LLM into attempting a forbidden action, causing it to shut down.

    Why it ranks #10

    Novel defensive technique for AI security with clear operational consequences for protecting cloud-stored secrets.

    Who should care

    Application security teams, Cloud security teams

    What to do

    Evaluate the use of honey-prompts alongside sensitive keys in AWS to detect and disrupt AI-driven exfiltration.

    Impact
    low
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email