Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 22, 2026

Immediate priority must be given to patching Zimbra Collaboration Suite following its addition to the CISA Known Exploited Vulnerabilities catalog. The broader threat landscape is characterized by sophisticated identity bypasses using passkeys and high-impact endpoint threats leveraging signed Microsoft drivers.

Compiled by the Slugnet Editorial System. Published Aug 22, 2026, 8:08 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    CISA Advisories

    CISA Adds One Known Exploited Vulnerability to Catalog

    What happened

    CISA has added a critical OS command injection vulnerability in the Zimbra Collaboration Suite, CVE-2026-73570, to its Known Exploited Vulnerabilities catalog. This flaw is being actively used by threat actors as a frequent attack vector for federal enterprise compromise.

    Why it ranks #1

    Confirmed active exploitation of an enterprise collaboration suite added to CISA's KEV catalog places this in the highest urgency tier.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Prioritize patching Zimbra Collaboration Suite installations immediately per CISA directives.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

    What happened

    Researchers discovered a technique to weaponize Microsoft Defender's signed boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level operations. This allows attackers to delete security software at boot across Windows 7 through Windows 11 without exploiting a software flaw.

    Why it ranks #2

    This is a high-impact technique affecting nearly all Windows enterprise endpoints by bypassing EDR/security tools using legitimate signed drivers.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

    What happened

    Fourteen trojanized npm packages masquerading as calendar and streak utilities are delivering the RedC2 4.0 Linux backdoor. The implant utilizes AI-assisted command and control to maintain stealthy persistence on developer systems.

    Why it ranks #3

    Active supply chain compromise targeting developers with a sophisticated, AI-enhanced backdoor represents a high-impact threat to the software build pipeline.

    Who should care

    Application security teams, SOC and incident response teams

    What to do

    Audit npm dependencies for unauthorized calendar or streak utility packages and scan Linux environments for RedC2 indicators.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    Hundreds of leaked AWS keys give full control over corporate accounts

    What happened

    Over 9,300 active Amazon Web Services access keys leaked between 2022 and 2026 remain valid and publicly exposed. These keys provide full administrative control over the associated corporate cloud accounts.

    Why it ranks #4

    Widespread exposure of high-privilege cloud credentials provides immediate, trivial entry for attackers into enterprise environments.

    Who should care

    Cloud security teams, Identity and access teams

    What to do

    Rotate all AWS access keys and implement automated secrets scanning to identify leaked credentials in public repositories.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    SecurityWeek

    New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

    What happened

    The iAuthFlow V2 phishing toolkit allows attackers to register their own passkeys on victim accounts. This enables persistent access that survives both password resets and the revocation of active sessions.

    Why it ranks #5

    This represents a material evolution in identity attacks, bypassing traditional remediation steps like password resets by abusing FIDO/passkey standards.

    Who should care

    Identity and access teams, SOC and incident response teams

    What to do

    Review account security settings for unauthorized registered passkeys and educate users on phishing attempts targeting authentication setup.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    SecurityWeek

    Critical Isolated-vm Vulnerability Leads to RCE on Host

    What happened

    A critical type confusion vulnerability in isolated-vm can lead to a V8 sandbox escape and control-flow hijacking of the host process. This flaw allows for remote code execution on the host machine.

    Why it ranks #6

    Critical RCE via sandbox escape in a widely used VM isolation library is a high-severity infrastructure vulnerability.

    Who should care

    Application security teams, Cloud security teams

    What to do

    Update isolated-vm to the latest patched version to prevent host process hijacking.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    BleepingComputer

    New SynkLoader malware pushed in Microsoft Teams phishing campaign

    What happened

    A new malware family called SynkLoader is being distributed via Microsoft Teams phishing campaigns. The malware uses a fake lock screen to trick users into providing credentials.

    Why it ranks #7

    Active campaign using trusted enterprise collaboration tools (Teams) for credential theft represents an immediate operational risk.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Implement phishing awareness training specifically for Teams-based attacks and monitor for unusual lock screen behavior on endpoints.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

    What happened

    Malware targeting Android-based vehicle head units developed by DoFun is spreading through built-in firmware updaters. The attackers use these infections to conduct ad fraud and build a proxy botnet.

    Why it ranks #8

    This demonstrates an expanding attack surface into automotive IoT via supply chain update mechanisms, though the immediate enterprise impact is lower than server RCEs.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    consumer
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Dark Reading

    OWASP Flags Top AI Skill Risks in New Security Blueprint

    What happened

    OWASP has released a new security blueprint and top 10 list specifically for AI skill risks. The guidance introduces a Universal Skill Format to standardize the security of AI add-ons.

    Why it ranks #9

    Substantial defensive research providing an operational framework for securing emerging AI agent capabilities.

    Who should care

    Application security teams, CISOs and security leaders

    What to do

    Adopt the OWASP AI security blueprint to assess and mitigate risks associated with AI add-ons and skills.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    SickKids data breach exposes employee and job applicant info

    What happened

    Toronto's Hospital for Sick Children suffered a data breach exposing personal information of employees and job applicants. The incident was caused by a vulnerability in third-party software, though clinical systems remained unaffected.

    Why it ranks #10

    Material breach resulting from a supply chain flaw, illustrating the risk of third-party software in sensitive environments.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email