DJBSEC's CyberNews 2026-08-14

Today’s daily news covers the following categories: Ransomware Vulnerability Threat Intelligence Data Breach Authentication Privacy


Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Ransomware

Microsoft says the China-linked, financially motivated Storm-1175 group has shifted away from Medusa ransomware and begun deploying a new C++ strain called StormEncryptor. The group is known for rapidly weaponizing newly disclosed vulnerabilities, sometimes moving from initial compromise to data theft and ransomware deployment within a single day. Recent operations have used legitimate remote-access and administrative tools including AnyDesk, SimpleHelp, PowerShell, PsExec, and RDP to establish persistence and move laterally. Microsoft suspects the latest campaign may involve exploitation of the recently disclosed N-able authentication bypass vulnerability, although that connection has not been confirmed. The activity demonstrates how quickly ransomware operators can capitalize on newly disclosed vulnerabilities before organizations complete patching.

Read More

Thousands of Exposed Controllers Put Data Center Cooling and Power at Risk

Vulnerability

Researchers identified roughly 6,300 internet-exposed industrial-control and building-automation devices located within one kilometer of 1,063 U.S. data centers, potentially creating risks to cooling, power, and environmental systems. The findings were based on passive Shodan data and do not prove that every device actually belongs to a nearby data center, but they reveal a significant surrounding attack surface. Many exposed systems use BACnet, Fox/Niagara, Modbus, and other protocols associated with air conditioning, sensors, power monitoring, and building controls. Compromise of these systems could potentially cause thermal alarms, protective shutdowns, power disruptions, or equipment damage. Researchers recommend eliminating direct internet exposure, segmenting building automation networks, strengthening remote access, and including facilities equipment in organizational asset inventories.

Read More

Cloudflare Says 1 Tbps DDoS Attacks Are Becoming the New Normal

Threat Intelligence

Cloudflare says large-scale distributed denial-of-service attacks surged during the first half of 2026, with the company blocking 935 network-layer attacks exceeding one terabit per second. Hyper-volumetric attacks increased 519 percent between the first and second quarters, with 805 attacks above one terabit per second occurring during the second quarter alone. Across the first six months of the year, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests. Despite the growth in massive attacks, more than 90 percent of network-layer incidents ended within 10 minutes, leaving organizations little time to respond manually. The findings reinforce the need for automated DDoS defenses capable of responding before extreme traffic volumes overwhelm network infrastructure.

Read More

CISA Warns of Actively Exploited Windows Ancillary Function Zero-Day

Vulnerability

CISA has added CVE-2026-68820, an actively exploited Windows zero-day, to its Known Exploited Vulnerabilities Catalog. The use-after-free vulnerability affects the Windows Ancillary Function Driver for WinSock and can allow an attacker who already has limited local access to elevate privileges on a compromised computer. Successful exploitation could provide higher-level permissions and help an attacker progress from an initial foothold toward full system control. CISA added the vulnerability to its catalog on August 11 and set an August 25 remediation deadline for federal civilian agencies covered by its binding directive. Organizations running affected Windows systems should prioritize Microsoft’s available security update because exploitation has already been confirmed in real-world attacks.

Read More

Microsoft Patches Exchange Server Flaws Enabling RCE and Privilege Escalation

Vulnerability

Microsoft has released security updates for multiple Exchange Server vulnerabilities that could enable remote code execution, denial-of-service attacks, privilege escalation, spoofing, and security feature bypasses. One of the most serious flaws, CVE-2026-62911, involves an authentication capture-replay weakness and was previously demonstrated at Pwn2Own Berlin. Under the required conditions, exploitation could give an attacker expanded permissions within Exchange and potentially allow access to mailboxes, messages, and attachments. The vulnerabilities affect supported releases including Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. Although Microsoft currently lists exploit maturity for the highlighted flaw as unproven, its public demonstration makes timely patching particularly important.

Read More

LiteLLM Supply Chain Breach Exposes Secrets From Thousands of Organizations

Data Breach

Researchers investigating the LiteLLM supply chain compromise say the incident may have exposed credentials and secrets belonging to more than 2,500 organizations and hundreds of thousands of CI/CD environments. The TeamPCP attackers first compromised Trivy’s release infrastructure, which allowed a poisoned version of the scanner to steal LiteLLM’s PyPI publishing token from an inadequately secured CI/CD pipeline. The attackers then used that token to publish malicious LiteLLM versions 1.82.7 and 1.82.8, which harvested sensitive information from affected systems. The malware was capable of collecting cloud credentials, AI API keys, CI/CD secrets, and other valuable authentication material. The incident demonstrates how compromising a single trusted development dependency can cascade through software pipelines and expose downstream organizations.

Read More

Fortinet Patches Authentication Flaws Across FortiWeb, FortiManager, and FortiClient

Authentication

Fortinet has released fixes for multiple authentication-related vulnerabilities affecting FortiWeb, FortiManager, and FortiClient products. The most serious, CVE-2026-26035, affects FortiWeb installations using Remote RADIUS authentication with a non-default wildcard configuration. Under those conditions, flawed username matching could allow a remote unauthenticated attacker to log into the FortiWeb GUI or command-line interface using arbitrary credentials and potentially obtain administrative control. The vulnerability affects numerous FortiWeb versions across several supported release branches. Administrators should review whether the vulnerable RADIUS configuration is enabled and apply Fortinet’s updated releases as quickly as possible.

Read More

AI Watermark Removal Tools Flood the Web, but Most Cannot Prove They Work

Threat Intelligence

A growing number of websites and open-source projects claim they can remove watermarks used to identify AI-generated content, but researchers say many of those claims are misleading. Some tools can legitimately remove hidden Unicode characters or strip C2PA, EXIF, and XMP metadata, but those techniques do not necessarily remove statistical watermarks embedded through an AI model’s word choices. Removing that type of watermark would generally require substantially rewriting the text, potentially using another AI model. Independent analysis has also found that some supposedly effective cleaners fail to remove even basic hidden payload techniques. The findings highlight the difficulty of verifying AI provenance and the growing marketplace of questionable tools promising to defeat AI detection systems.

Read More

Akira Ransomware Disables EDR but Fails to Encrypt Victim

Ransomware

Akira ransomware attackers attempted to evade endpoint security by rebooting a compromised Windows system into Safe Mode, temporarily disabling working EDR and blinding antivirus protections. The attackers modified the Safe Mode registry so AnyDesk would continue running after the reboot, preserving remote access while security controls were unavailable. Their plan backfired when the Akira ransomware executable encountered memory and PowerShell errors and failed to encrypt the victim’s files. Despite that failure, the attackers still managed to steal credentials and data for extortion in less than five hours from initial access. Researchers recommend enforcing MFA on VPN accounts and monitoring for suspicious Safe Mode configuration changes and remote-access tools being added to Safe Mode services.

Read More

Adobe Commerce Flaw Comes Under Attack Shortly After Disclosure

Vulnerability

Attackers began targeting a critical Adobe Commerce vulnerability shortly after details of the flaw became public. CVE-2026-71362 carries a CVSS score of 9.1 and can allow an unauthenticated attacker to switch customer sessions, take over accounts, and access private customer information. Security firm Sansec detected and blocked exploitation attempts after Adobe released its advisory, showing how quickly attackers moved to weaponize the disclosure. The vulnerability affects Adobe Commerce, Commerce B2B, and Magento Open Source releases through the July 2026 patches. Adobe has released an isolated security fix, and organizations running affected commerce platforms should prioritize deployment because exploitation attempts are already underway.

Read More

Global Attack Campaign Exploits Critical VMware vCenter Vulnerability

Vulnerability

Attackers are continuing to exploit the critical VMware vCenter vulnerability CVE-2026-59310 in a global campaign, with new victims still appearing as organizations race to patch vulnerable systems. Researchers say attackers can establish persistent access using the open-source reverse_ssh tool, creating outbound control channels from compromised vCenter servers. That persistence means simply installing VMware’s patch may not remove an attacker who compromised the system before remediation. Researchers observed exploitation beginning only about five days after public disclosure, illustrating how quickly skilled attackers can reverse-engineer patches and develop working exploits. Organizations should patch vulnerable vCenter instances while also conducting forensic investigations for reverse_ssh and other indicators of an existing compromise.

Read More

Apple Sends New Threat Notifications Over Mercenary Spyware Attacks

Privacy

Apple has sent a new round of threat notifications to users it believes were individually targeted by sophisticated mercenary spyware attacks. These operations typically target a small number of high-profile individuals such as journalists, activists, politicians, and diplomats and can cost attackers millions of dollars to conduct. Apple describes its notifications as high-confidence warnings based on internal threat intelligence and investigations, although it does not disclose the specific evidence that triggered each alert or attribute attacks to particular governments or vendors. Genuine Apple threat notifications will never ask recipients to click links, install applications, provide passwords, or supply verification codes, and users can verify an alert directly through their Apple Account. Apple recommends that recipients take the warning seriously, enable Lockdown Mode, and seek expert cybersecurity assistance.

Read More




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • DJBSEC's CyberNews 2026-08-28
  • DJBSEC's CyberNews 2026-08-27
  • DJBSEC's CyberNews 2026-08-26
  • DJBSEC's CyberNews 2026-08-25
  • DJBSEC's CyberNews 2026-08-24