Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 14, 2026

Immediate priority must be given to the GeoServer zero-day and VMware vCenter persistence campaigns, both of which enable remote code execution. The broader landscape is marked by significant data breaches at RingCentral and Beacon CRM, alongside evolving AI-driven supply chain risks in software development.

Compiled by the Slugnet Editorial System. Published Aug 14, 2026, 8:06 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    SecurityWeek

    Hackers Exploiting Unpatched GeoServer Zero-Day

    What happened

    Attackers are actively exploiting a zero-day SQL injection vulnerability in GeoServer. Successful exploitation can lead to remote code execution on affected systems.

    Why it ranks #1

    Confirmed active exploitation of a zero-day with RCE potential represents the highest urgency tier (1).

    Who should care

    Application security teams, SOC and incident response teams

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    Microsoft patches LegacyHive Windows zero-day vulnerability

    What happened

    Microsoft has released security patches for a Windows zero-day vulnerability known as LegacyHive. The flaw was disclosed following the July 2026 Patch Tuesday cycle.

    Why it ranks #2

    A patched zero-day in a ubiquitous OS falls into tier 1/2 due to immediate enterprise exposure and remediation requirements.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply the latest Microsoft security patches to address the LegacyHive vulnerability.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    What happened

    Threat actors are exploiting CVE-2026-59310 in VMware vCenter Syslog Server to deploy a reverse SSH tool. This technique provides attackers with persistent remote access to the environment.

    Why it ranks #3

    This is a material update to a previously reported vulnerability, providing specific technical details on the exploitation method (reverse SSH) for persistence.

    Who should care

    Cloud security teams, SOC and incident response teams

    What to do

    Patch CVE-2026-59310 and audit vCenter logs for unauthorized reverse SSH connections.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    RingCentral data breach exposed info of 1.6 million accounts

    What happened

    The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts during a July breach. The stolen data includes names, addresses, email addresses, and phone numbers.

    Why it ranks #4

    A material breach of a widely used enterprise communication platform involving over a million accounts falls into tier 3.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    SecurityWeek

    Over 1,000 Charities Hit by Beacon CRM Data Breach

    What happened

    A data breach at Beacon CRM has impacted over 1,000 charities. The incident was caused by a compromised AWS access key exposed in public JavaScript build artifacts.

    Why it ranks #5

    A supply-chain style compromise via leaked cloud credentials affecting numerous organizations falls into tier 3.

    Who should care

    Application security teams, Cloud security teams

    What to do

    Audit JavaScript build artifacts for exposed secrets and rotate AWS access keys.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    What happened

    Akira ransomware affiliates are bypassing endpoint detection and response solutions by booting compromised systems into Safe Mode with Networking. This allows them to exfiltrate data even when EDR is active in normal mode.

    Why it ranks #6

    Novel threat actor techniques for bypassing enterprise security controls fall into tier 4.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Restrict the ability to boot into Safe Mode and monitor for unexpected system restarts.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    SecurityWeek

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    What happened

    A new Rust-based macOS infostealer called AmnesiaStealer is targeting users to harvest passwords and keychain data. The malware also captures Chromium browser data and Safari cookies to hijack sessions.

    Why it ranks #7

    New malware campaigns targeting enterprise endpoints fall into tier 3/4.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    Help Net Security

    New Android malware relays bank cards to fraudsters while victims still hold them

    What happened

    Researchers discovered WindRelay, an Android malware that uses Near Field Communication to relay live payment card data to fraudsters. The attack is paired with the SpyNote remote access trojan for full device control.

    Why it ranks #8

    Novel mobile malware utilizing NFC for financial theft falls into tier 3/4.

    Who should care

    Individual users, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    consumer
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Help Net Security

    AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

    What happened

    AWS Certificate Manager is phasing out email validation for public certificates throughout 2027. This move aligns with the CA/B Forum deadline to end email-based domain validation by March 2028.

    Why it ranks #9

    A significant change in identity and certificate infrastructure with a clear operational timeline falls into tier 4.

    Who should care

    Cloud security teams, IT and platform operations

    What to do

    Plan the transition from email validation to DNS validation for AWS public certificates before 2027.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

    What happened

    AI coding tools are introducing unvetted or hallucinated open source dependencies into development pipelines. This creates a scale challenge where traditional security reviews cannot keep pace with AI-generated code ingestion.

    Why it ranks #10

    Research on the operational consequences of AI in the software supply chain falls into tier 4.

    Who should care

    Application security teams

    What to do

    Implement package governance at the point of selection before dependencies enter the development pipeline.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email