Sam's News — security — 2026-08-24¶
Security¶
8.5 Critical Keycloak authentication flaw enables account takeover¶
Red Hat and the Keycloak project patched CVE-2026-18963, a critical vulnerability (CVSS 9.1) that allows unauthenticated attackers to reset any user password and seize accounts by bypassing email verification in the reset-credentials flow. Patches were released August 18–19, 2026; as of August 24 there is no evidence of active exploitation.
- CVE-2026-18963, CVSS 9.1 critical
- Unauthenticated password reset possible
- Affects administrative accounts
- Keycloak 26.7.2 patched (Aug 19, 2026)
- Red Hat RHBK versions 26.4.15 and 26.6.6 patched
- No active exploitation confirmed as of Aug 24
Sources: The Hacker News AI Web Searched
8 Multiple cybersecurity threats: CISA MLFlow warning, Siemens PLC AI attacks, CareCloud breach¶
CISA warns of an exploited critical MLflow vulnerability, ICS issues warnings about AI-driven attacks on Siemens PLCs, and CareCloud confirms a breach affecting millions.
Sources: CISO Series Web Search, CISO Series Web Search, CISO Series Web Search Update to: CISA Issues Critical Alerts for MLflow, Siemens PLCs, and CareCloud Breach
8 Iran-Linked Hackers Shut Down UK Power Plant for Four Days¶
Iran-linked hackers shut down a UK power plant for four days in July 2026, as reported on August 22, 2026. The attack raised concerns about operational resilience of smaller UK power operators and represents an expansion of Iranian cyber operations into British critical infrastructure.
- Four-day operational shutdown in July 2026
- Attack attributed to Iran-linked hackers
- Facility was a smaller power plant, not major national infrastructure
- Expansion of Iranian cyber activity into UK following pattern of GCC, US, and European targeting
- UK power plant offline for four days from Iranian cyberattack
- First disruptive Iranian cyberattack on UK critical infrastructure of this kind
- Concurrent breaches of U.S. water utilities across 12+ states assessed as Iran-linked
- Attackers using AI-generated exploitation scripts against Siemens S7 Series PLCs
- Targets include water, manufacturing, and energy infrastructure
- First reported successful Iranian cyberattack on UK power plant (July 2026)
- Iranian actors targeted water systems in 12 US states (New Jersey, Minnesota, Georgia, South Dakota)
- Attacked programmable logic controllers (PLCs)
- 12–70 million PLCs worldwide; many lack modern cybersecurity
- CISA: attackers used simple techniques—scanning and default credentials, no zero-days
Sources: SecurityWeek AI Web Searched, The Register AI Web Searched, CBS News AI Web Searched
8 Origin Energy Confirms Major Data Breach Affecting 900,000 Customer Accounts¶
Australian energy company Origin Energy confirmed a significant data breach affecting approximately 900,000 current and former customer accounts.
- 900,000 current and former customers affected
- Data compromised: names, addresses, DOB, phone, account details, partial card/bank info
- Breach first identified early July, confirmed credible July 22, disclosed July 28
- Investigations by Australian Cyber Security Centre, AFP, and other authorities
Sources: Rescana Solutions AI Web Searched, Rescana Web Search, Rescana Web Search
8 Accenture disclosed to face massive data breach threatening client security¶
A threat actor claims to have stolen a large volume of sensitive data from consulting firm Accenture in a recent cyberattack.
Sources: Cybersecurity Dive Web Search, Cybersecurity Dive Web Search Update to: Accenture Targeted in Major Data Breach Threatening Client Security
7.5 CISA urges immediate patching of exploited Microsoft, VMware, and Apple vulnerabilities¶
The US Cybersecurity and Infrastructure Security Agency called for urgent patching of four actively exploited vulnerabilities in major software vendors.
- CISA identified four vulnerabilities: CVE-2026-33824 (Windows IKE, CVSS 9.8), CVE-2026-55040 (SharePoint, CVSS 9.1), CVE-2026-59310 (VMware vCenter, CVSS 9.8), and CVE-2026-65400 (macOS Screen Sharing, CVSS 7.5)
- All four flaws are actively exploited in the wild; VMware and Apple vulnerabilities saw exploitation within days of patch release
- Federal agencies must patch by August 21, 2026, per BOD 26-04 requirements
- Windows IKE Service flaw exploited by Chinese-speaking threat actors in autonomous hacking campaigns; macOS flaw used to deploy cryptocurrency miners
Sources: SecurityWeek Web Search Update to: CISA Orders Immediate Patching of Four Actively Exploited Vulnerabilities in Microsoft, VMware, and Apple Products
7.5 Latvia confirms major cyberattack on road traffic agency exposing data of 1.2 million people—two-thirds of population¶
Latvia's road traffic agency confirmed a cyberattack that stole personal data linked to approximately 1.2 million citizens, prompting official resignations.
- 1.2 million individuals affected—approximately two-thirds of Latvia's population
- 200,000 businesses and legal entities also impacted
- Breach exposed personal ID numbers, company registration numbers, vehicle details, and payment records from 2008 onward
- Attack exploited vulnerability in internet-exposed system; agency lacked mandatory cybersecurity protections
- CSDD supervisory board submitted resignation; chief Aivars Aksenoks preparing to depart
Sources: The Record from Recorded Future News Web Search Update to: Latvia Suffers National-Scale Data Breach Exposing 1.2 Million Citizens' Records
7.5 Chinese-linked hacker demonstrates near-autonomous AI attack capability against APAC government agencies¶
A Chinese-language operator deployed a sophisticated AI framework to conduct autonomous attacks targeting government agencies across the Asia-Pacific region.
- Attack occurred mid-September 2025 using AI agentic capabilities
- Targeted ~30 global entities including tech, finance, chemicals, and government agencies
- Compromised 85 Taiwanese government accounts; ~2,500 personal records stolen
- Used Hermes and OpenClaw agent platforms coordinating up to 8 sub-agents simultaneously
- Attackers manipulated Anthropic Claude Code tool for infiltration
- First documented large-scale cyberattack executed largely without human intervention
Sources: Dark Reading Web Search Update to: Chinese-Linked Hackers Conduct Near-Autonomous AI-Driven Attack on Government Agencies
7.5 CISA Orders Urgent Patching of Actively Exploited Zimbra Vulnerability¶
CISA added CVE-2026-73570, a critical OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities catalog after Poland's CERT confirmed active exploitation on August 22, 2026. The flaw affects systems with the optional zimbra-snmp package installed and requires patching within three days per federal mandate.
- CVE-2026-73570 actively exploited
- Affects Zimbra with optional snmp package
- Unauthenticated remote code execution
- Patched version 10.1.20 released July 20, 2026
- CISA BOD 26-04: 3-day federal patching mandate
Sources: Security Affairs AI Web Searched, BleepingComputer RSS
7.5 Nissan data breach in Oracle PeopleSoft attack exposes customer information¶
Nissan suffered a data breach through a zero-day exploit in Oracle PeopleSoft between May 27 and June 9, 2026, exposing employee personally identifiable information including payroll data, tax information, and Social Security numbers.
- Zero-day in Oracle PeopleSoft exploited
- May 27–June 9, 2026 breach window
- Employee PII exposed: payroll, tax data, SSNs
Sources: IT Brew AI Web Searched