Sam's News β security β 2026-08-20¶
Security¶
8.5 China-Nexus Hackers Breach 361 Organizations in 5 Days; CISA Sets 3-Day Patch Deadline¶
China-attributed threat actors compromised 361 organizations across 47 countries within five days of a VMware vCenter vulnerability being patched, with a second Chinese group deploying an autonomous AI hacking operation. CISA issued a binding directive setting August 21, 2026, as the mandatory patch deadline for federal agencies.
- 361 organizations across 47 countries breached in 5 days post-patch disclosure
- CVE-2026-59310: directory traversal in VMware vCenter CVSS 9.8, no workaround
- Second threat actor deployed autonomous AI hacking using DeepSeek language model
- CISA Binding Operational Directive 26-04 set August 21, 2026 patch deadline for federal agencies
Sources: Tech Times AI Web Searched
8.5 Data Breaches Surge to 471M Victims in H1 2026, Doubling 2025 Total¶
The Identity Theft Resource Center reports 471 million victim notices in the first half of 2026, exceeding all of 2025, driven by AI-powered attacks and zero-day exploits.
Sources: https://tech-insider.org/ Web Search Update to: Data Breaches Hit 471M Victims in H1 2026, Doubling 2025 Total
8 Critical Elementor Pro WordPress plugin flaw enables remote code execution¶
A critical vulnerability in Elementor Pro allows attackers to upload executable files and achieve remote code execution on vulnerable WordPress sites.
- CVE-2026-32475, CVSS score 9.0 (critical)
- Affects all versions prior to and including 4.2.1
- Unauthenticated remote code execution via File Upload field in Forms module
- Patch 4.2.2 released August 19, 2026
- Requires only default File Upload field (no special settings needed)
- Discovery: July 16, 2026 via Patchstack Bug Bounty Program
Sources: The Hacker News AI Web Searched, BleepingComputer RSS
8 Federal agencies warn of active AI-generated attacks on critical infrastructure controllers¶
The U.S. government warned of an active threat using AI-generated exploit scripts targeting Siemens S7 Programmable Logic Controllers in critical infrastructure.
- Joint warning August 19, 2026 from NSA, CISA, FBI, DOE, EPA
- Threat actors use AI-generated code with open-source automation libraries (snap7.dll/python-snap7)
- Target: Internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy facilities
- July 2026 attack disrupted 30+ water systems across 12+ states
- Iranian cyber operatives suspected involvement
- State-sponsored adversaries using AI for code checks and scripting to scale operations
- Joint advisory issued August 20, 2026 by NSA, CISA, FBI, EPA, DOE
- Threat actors using AI to develop exploitation scripts
- Targets include Siemens S7-200, S7-300, S7-400, S7-1200, S7-1500 PLCs
- Affected sectors: energy, manufacturing, water, food, agriculture, chemical, commercial
- AI scripts reduce expertise and development time for ICS attacks
Sources: The Register AI Web Searched, SecurityWeek AI Web Searched, The Hacker News RSS
8 Critical GitLab vulnerability CVE-2026-19478 exploited in the wild¶
A critical GitLab flaw allowing unauthenticated modification or deletion of public projects is being actively exploited shortly after public disclosure.
- CVE-2026-19478: critical zero-click GitLab vulnerability
- Affects self-managed instances
- Difficult to detect due to lack of technical disclosure details
Sources: SecurityWeek RSS Update to: Critical GitLab zero-click vulnerability poses detection challenges for self-managed instances
8 Critical Zimbra RCE vulnerability actively exploited in attacks¶
Poland's CERT has observed attackers actively exploiting a critical vulnerability in Zimbra Collaboration servers.
- Critical RCE vulnerability in Zimbra Collaboration Suite actively exploited
- Attackers trigger flaw via email delivery to backdoor servers
- Targets unpatched ZCS installations
Sources: Bleeping Computer AI Web Searched, Cybersecurity News AI Web Searched, BleepingComputer RSS, The Hacker News RSS, SecurityWeek RSS
8 Critical authentication bypass vulnerability patched in Citrix NetScaler¶
Citrix released patches for a critical-severity authentication bypass vulnerability affecting NetScaler ADC and Gateway deployments.
- CVE-2026-19490: critical authentication bypass, CVSS 9.3
- Affects NetScaler ADC and Gateway versions 13.1 and 14.1
- Remote attackers can exploit without user interaction or authentication
- Fixed versions released: 14.1-73.32, 13.1-63.21 and FIPS variants
- No active exploitation documented yet, but Rapid7 expects imminent attacks
Sources: SecurityWeek AI Web Searched, The Hacker News RSS
8 CISA warns federal agencies of active MLflow vulnerability exploitation¶
The Cybersecurity and Infrastructure Security Agency warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, a machine learning platform used for model development and management.
- Critical vulnerability in MLflow actively exploited by threat actors
- MLflow platform used for machine learning model development and management
- CISA alert directed at federal agencies
Sources: BleepingComputer AI Web Searched, SecurityWeek RSS
8 NASA AIT-GUI security flaws allow unauthenticated spacecraft command injection¶
Security researchers disclosed a chain of flaws in NASA's AIT-GUI operator console allowing unauthenticated attackers to issue arbitrary commands to spacecraft and instrument systems. The vulnerabilities stem from hardcoded binding, missing authentication on state-changing routes, and unvalidated input handling; AIT-GUI 2.5.2 released August 12, 2026, addresses these issues.
- Vulnerability chain GHSA-p9r8-2q67-fp86 CVSS 9.4; affects AIT-GUI 2.5.1 and earlier
- Flaws allow unauthenticated remote arbitrary spacecraft and instrument commands
- Web server binds to 0.0.0.0:8080 by default with no authentication on state-changing routes
- Patch released August 12, 2026 (AIT-GUI 2.5.2); advisory published August 13, 2026
Sources: The Hacker News AI Web Searched
8 Chinese hackers breached 361 networks in five days; CISA shortens patch window to three days¶
Chinese threat actors breached 361 organizations within five days, prompting CISA to mandate a three-day patch window for affected enterprise software flaws.
Sources: Tech Times RSS