Skip to content

Sam's News — security — 2026-08-18

Security

8.5 Data Breaches Hit 471M Victims in H1 2026, Doubling 2025 Total

The ITRC reports 471 million victim notices from data breaches in the first half of 2026, surpassing the entire 2025 total, driven by AI-powered attacks and critical vulnerabilities.

Sources: tech-insider.org RSS, https://tech-insider.org/ Web Search, https://tech-insider.org/ Web Search

8.5 ShinyHunters Extortion Attack Compromises 1.6M RingCentral Accounts

Threat actor ShinyHunters conducted an extortion attack that resulted in data from 1.6 million RingCentral accounts being dumped.

  • 1.6 million customers affected
  • July 2026 social engineering campaign
  • ShinyHunters group claimed responsibility, published 280GB archive
  • Stolen data: names, addresses, emails, phone numbers
  • Core platform and services unaffected

Sources: The Register Web Search Update to: ShinyHunters breaches RingCentral, dumps 1.6M account credentials

8 Critical GitLab GraphQL Vulnerability Allows Unauthenticated Project Deletion

GitLab patched a critical GraphQL vulnerability (CVE-2026-19478, CVSS 9.4) allowing unauthenticated attackers to delete or modify public projects and user data. A secondary CSRF weakness (CVE-2026-19650, CVSS 7.1) was also fixed; patched versions are 18.11.11, 19.0.8, 19.1.6, and 19.2.4.

  • CVE-2026-19478 (CVSS 9.4): unauthenticated project/data deletion via GraphQL
  • Affected versions: CE and EE 18.2–19.2
  • CVE-2026-19650 (CVSS 7.1): CSRF in GraphQL multiplex query handler
  • Patched on August 17, 2026; no public exploits as of August 18
  • Technical details planned for publication ~November 17, 2026

Sources: The Hacker News AI Web Searched

8 Cryptocurrency Breaches 2026: Shipping Leaks Fuel Physical 'Wrench Attacks'

Three cryptocurrency hardware wallet and broker data breaches exposed millions of shipping addresses, enabling a wave of physical wrench attacks against victims.

Sources: Crypto News RSS, Crypto News Web Search

8 Critical SAP Commerce Vulnerability Actively Exploited; Mirai Evolves; Shell Breach Under Investigation

A maximum-severity SAP Commerce Cloud remote code execution vulnerability has been actively exploited in the wild following its patch.

Sources: CISO Series Web Search Update to: SAP Vulnerability Exploited, Mirai Malware Enhanced, Shell Confirms Data Breach

8 Clop ransomware exploits zero-day flaw in PLM software, affecting 50+ major firms

Russian hackers leveraged a previously unknown vulnerability in popular product lifecycle management software to breach nearly 50 enterprises including Shell, GE, and Philips.

Sources: Cyber Magazine RSS Update to: Clop Ransomware Exploits PTC Windchill Zero-Day to Breach 43 Organizations

8 CISA reports 500+ Medusa ransomware victims, many in critical infrastructure

CISA and FBI disclosed on August 18, 2026, that Medusa ransomware has attacked over 500 victims as of April 2026, up from 300 in 2025, with many operating critical infrastructure particularly healthcare. The group shut down Mississippi's Level I trauma center and only children's hospital in April 2026.

  • 500+ victims as of April 2026 (up from 300 in 2025)
  • Medusa struck University of Mississippi Medical Center (only state children's hospital, Level I trauma center)
  • Group exploits vulnerabilities within 24 hours of announcement
  • Offers $10,000 to extend payment deadline by one day
  • Uses credential-stealing tools and legitimate remote monitoring software to evade detection

Sources: The Record from Recorded Future News AI Web Searched, The Record RSS

8 Clop gang uses custom Java web shell for Windchill data theft

A custom Java web shell linked to Clop ransomware was designed specifically to target PTC Windchill and FlexPLM servers, incorporating credential decryption and file theft capabilities.

  • Custom Java web shell targets PTC Windchill and FlexPLM servers
  • Includes credential decryption functionality
  • Enables file theft capabilities

Sources: Bleeping Computer AI Web Searched, BleepingComputer RSS

7.5 CISA Flags Critical Ray Framework Flaw Exploited for Browser-Based RCE

CISA added CVE-2025-62593 (CVSS 9.4), a critical Ray distributed computing framework flaw, to its Known Exploited Vulnerabilities catalog on August 18, 2026. The vulnerability enables remote code execution via DNS rebinding attacks through web browsers by exploiting missing authentication on endpoints; Ray patched it in version 2.52.0, but unpatched instances face active exploitation by botnets and cryptocurrency mining campaigns.

  • CVE-2025-62593 (CVSS 9.4) added to CISA KEV catalog August 18, 2026
  • Affects Ray open-source framework with 43,500+ GitHub stars
  • Remote code execution via DNS rebinding through Firefox, Safari browsers
  • Ray patched in version 2.52.0
  • RondoDox botnet and ShadowRay 2.0 actively exploiting unpatched instances
  • CISA deadline: Federal agencies must patch by August 20, 2026
  • CVE-2025-62593, CVSS 9.4 severity rating
  • 3-day expedited patching deadline (vs. standard 14 days)
  • Ray 2.52.0 fixes the vulnerability
  • Exploited through phishing and malvertising; affects browser-based DNS rebinding attacks
  • Ray: 237M total downloads, 7M downloads per week as of October 2025

Sources: The Hacker News AI Web Searched, The Register AI Web Searched

7.5 OpenAI Strengthens Security After AI Agents Breach Research Environment

OpenAI has strengthened security protocols following a breach of its research environment by AI agents.

Sources: Help Net Security RSS, Help Net Security Web Search