Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 25, 2026

Immediate priority must be given to patching Oracle WebLogic and Zimbra servers due to confirmed active exploitation of critical vulnerabilities. The broader landscape shows a surge in identity-based attacks, including severe flaws in Keycloak and miniOrange, alongside evolving AI agent risks.

Compiled by the Slugnet Editorial System. Published Aug 25, 2026, 8:09 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    What happened

    CISA has added a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog. CVE-2026-21962 allows unauthenticated attackers with network access via HTTP to access critical data.

    Why it ranks #1

    Confirmed active exploitation of a maximum-severity (CVSS 10.0) vulnerability in widely used enterprise infrastructure, placing it in the highest urgency tier.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply security updates for Oracle HTTP Server and WebLogic Server immediately to remediate CVE-2026-21962.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    Help Net Security

    Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

    What happened

    At least 274 internet-facing Zimbra instances have been compromised via CVE-2026-73570. This code injection flaw allows for full takeover of user communications on the collaboration platform.

    Why it ranks #2

    This is a material update to a previously reported incident, providing specific evidence of the scale of active exploitation (274 instances).

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Update Zimbra Collaboration Suite to version 10.1.20 or later.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

    What happened

    A critical password reset flaw in the Keycloak identity and access management server could allow unauthenticated remote attackers to take over any user account. The vulnerability, CVE-2026-18963, has a CVSS score of 9.1.

    Why it ranks #3

    High-impact vulnerability in critical identity infrastructure; while not yet confirmed as exploited in the wild, its potential for total account takeover is severe.

    Who should care

    Identity and access teams, IT and platform operations

    What to do

    Apply the patches released by Red Hat and the Keycloak project to address CVE-2026-18963.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

    What happened

    Attackers are targeting two severe unauthenticated authentication bypasses in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws, including CVE-2026-61979, can grant attackers administrative access to sites.

    Why it ranks #4

    Active exploitation of vulnerabilities in a common enterprise web plugin that leads to full site administrative compromise.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Update the miniOrange SAML 2.0 Single Sign On plugin to the latest version to block authentication bypasses.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    BleepingComputer

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    What happened

    An unpatched vulnerability in Calix GS7 XGS residential routers allows remote, unauthenticated attackers to create port-forwarding rules. This can expose internal local network devices to the public internet.

    Why it ranks #5

    Critical vulnerability in network edge hardware that bypasses NAT; however, it is ranked lower than enterprise server flaws due to its primary prevalence in residential/broadband contexts.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Help Net Security

    ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

    What happened

    Cybersecurity firm ReliaQuest confirmed a social engineering attack where an employee provided a password, granting attackers brief access to the company's identity system. The extortion group ShinyHunters has since posted screenshots of the breach.

    Why it ranks #6

    Material breach involving a security vendor and identity system exposure; ranked in tier 3 as it is a specific incident rather than a systemic vulnerability.

    Who should care

    CISOs and security leaders, Identity and access teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Dark Reading

    Foul Language: WordlistLoader Disguises Malware as Ordinary Text

    What happened

    A new malware delivery technique called WordlistLoader disguises malicious payloads as ordinary text to evade detection. This method is being used in ClickFix-style campaigns to deliver the Amatera infostealer.

    Why it ranks #7

    New malware campaign and evasion technique with operational consequences for endpoint detection; ranked below active enterprise exploits.

    Who should care

    SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    SecurityWeek

    First Malware Built Specifically for Car Head Units Fuels Botnet

    What happened

    Researchers have linked malware specifically designed for car head units to the BadBox botnet. The botnet has reportedly ensnared millions of devices globally.

    Why it ranks #8

    Significant scale of infection (millions of devices) and novel target; however, it lacks immediate enterprise server exposure compared to higher-ranked items.

    Who should care

    SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Help Net Security

    HOL Guard: Open-source antivirus for AI agents

    What happened

    HOL Guard is a new open-source tool designed to act as an antivirus for AI agents by intercepting risky actions. It requires user confirmation before allowing an AI assistant to execute potentially dangerous commands on a local machine.

    Why it ranks #9

    Defensive research and tooling with clear operational consequence for securing AI agent workflows, breaking ties in the lower tiers.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Consider deploying HOL Guard to provide a human-in-the-loop safety layer for developers using AI agents like Claude Code.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    New TCG guidance gives buyers a way to test PQC-ready TPM claims

    What happened

    The Trusted Computing Group has released new requirements for Trusted Platform Modules to be classified as quantum-safe. This guidance allows buyers to request evidence from vendors that their hardware meets a written baseline for post-quantum cryptography.

    Why it ranks #10

    Substantial security policy and standard development regarding long-term infrastructure resilience (PQC), placing it in the final tier.

    Who should care

    CISOs and security leaders, IT and platform operations

    What to do

    Use the TCG baseline to evaluate post-quantum cryptography claims when procuring new hardware with Trusted Platform Modules.

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email