Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 13, 2026

Immediate priority is the remediation of Microsoft SharePoint and Adobe Commerce vulnerabilities currently under active exploitation. Simultaneously, organizations must rotate secrets following a massive 153 gigabyte credential leak from LiteLLM and audit guest access on Salesforce and ServiceNow portals.

Compiled by the Slugnet Editorial System. Published Aug 13, 2026, 8:08 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

    What happened

    Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040. The flaw allows attackers to bypass security features due to weak authentication and was patched in July 2026.

    Why it ranks #1

    Confirmed active exploitation of a high-CVSS (9.1) vulnerability in widely used enterprise infrastructure takes top priority.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply the July 2026 Patch Tuesday updates for Microsoft SharePoint immediately.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    SecurityWeek

    Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    What happened

    Fortinet has patched authentication flaws in FortiWeb and FortiManager that could allow attackers to impersonate any FortiGate appliance. These vulnerabilities also enable unauthorized logins using random usernames and passwords.

    Why it ranks #2

    Critical infrastructure vulnerabilities in network security appliances (WAF/Management) are high-impact enterprise risks, though active exploitation is not yet confirmed here.

    Who should care

    Cloud security teams, IT and platform operations

    What to do

    Update FortiWeb and FortiManager to the latest patched versions provided by Fortinet.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    Help Net Security

    153GB of stolen credentials surface after LiteLLM supply chain attack

    What happened

    A 153GB archive of stolen credentials from the LiteLLM supply chain attack has surfaced, exposing sensitive data and CI runner dumps. The leak impacts thousands of corporate domains, including Cisco, Salesforce, Samsung, and AWS.

    Why it ranks #3

    This is a material update to a previously reported incident, providing concrete evidence of the scale (153GB) and specific high-value targets affected.

    Who should care

    Cloud security teams, Identity and access teams, SOC and incident response teams

    What to do

    Rotate all cloud keys, Kubernetes tokens, and CI/CD secrets if LiteLLM was used in the environment.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

    What happened

    The City-Forum campaign is using custom tools to exfiltrate data from Salesforce Experience Cloud and ServiceNow customer portals. The attackers exploit unauthenticated guest access to enumerate and steal exposed records.

    Why it ranks #4

    Active, long-running campaign targeting major enterprise SaaS platforms with material data theft consequences.

    Who should care

    Cloud security teams, SOC and incident response teams

    What to do

    Review guest access permissions and public sharing settings in Salesforce Experience Cloud and ServiceNow portals.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    BleepingComputer

    Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

    What happened

    Attackers are attempting to exploit CVE-2026-71362, a critical vulnerability in Adobe Commerce and Magento. Successful exploitation could allow threat actors to hijack customer accounts.

    Why it ranks #5

    Active exploitation attempts of a critical flaw in widely used e-commerce platforms represent significant enterprise risk.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Apply the security patches for CVE-2026-71362 to all Adobe Commerce and Magento instances.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Dark Reading

    Belgium's eID Authentication Opens Citizen Accounts to RCE

    What happened

    Severe vulnerabilities in a key browser extension have fully compromised the trust framework of Belgium's electronic ID system. These flaws allow for remote code execution on citizen accounts.

    Why it ranks #6

    Material breach of national identity infrastructure with RCE capabilities, though scope is geographically limited to Belgium.

    Who should care

    Application security teams, Identity and access teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

    What happened

    Wireshark 4.6.8 addresses 28 security bugs, including nine critical flaws in file parsers. These vulnerabilities can be triggered simply by opening a saved capture file, requiring no network access.

    Why it ranks #7

    High-impact vulnerabilities in a standard tool used by almost all SOC and IT teams; the 'no network' trigger increases risk for analysts.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Update Wireshark to version 4.6.8 immediately.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    Dark Reading

    'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

    What happened

    The Jewelbug APT group is utilizing a single web panel to conduct both state-sponsored espionage and cryptocurrency theft. This dual-purpose operation demonstrates a blend of political and financial motivations.

    Why it ranks #8

    Significant threat actor research identifying novel operational patterns (hybrid espionage/theft), though less immediate than active CVE exploitation.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Cisco Talos Blog

    Dissecting the JWR phishing framework

    What happened

    Cisco Talos has uncovered the JWR phishing framework, which is designed to impersonate login and checkout pages of major shopping and payment platforms. The undocumented tool aims to steal user credentials through high-fidelity spoofing.

    Why it ranks #9

    New threat actor tooling discovery with clear operational consequences for credential theft, though primarily targeting consumers/end-users.

    Who should care

    Individual users, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

    What happened

    Cloudflare reports that DDoS attacks have reached record scales in the first half of 2026, with campaigns exceeding 1 terabit per second becoming more common. Attackers are increasingly using automated, multi-vector network-layer techniques.

    Why it ranks #10

    Substantial defensive research on evolving attack trends (hyper-volumetric DDoS) that informs infrastructure capacity planning.

    Who should care

    Cloud security teams, IT and platform operations

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email