Rosetta Daily · Aug 20, 2026
Scanned 33 sources, 380 new items in the 36-hour window, 22 selected.
Critical Vulnerabilities & Active Exploitation
CISA adds four actively-exploited vulnerabilities to KEV catalog in one batch: On August 18, CISA added four high-severity flaws to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation — a Windows IKE Service Extensions double-free RCE (CVE-2026-33824), an Apple macOS improper-authentication bypass (CVE-2026-65400, CVSS 9.8), a Microsoft SharePoint weak-authentication flaw (CVE-2026-55040), and a Broadcom VMware vCenter path-traversal flaw (CVE-2026-59310). Federal agencies must prioritize remediation under BOD 26-04. The Hacker News · CISA advisory
Open-source AI framework Ray hit by actively exploited code-injection flaw: CISA added CVE-2025-62593, affecting the distributed-computing framework Ray (40,000+ GitHub stars, widely used to scale AI/ML workloads), to its KEV catalog. The flaw can trigger browser-based remote code execution. The Hacker News
Windows Task Host flaw, flagged exploited in April, now abused by ransomware gangs too: CISA confirmed ransomware operators are exploiting the same high-severity Windows Task Host vulnerability first flagged as actively exploited earlier this year. Bleeping Computer
MLflow SSRF and FUXA SCADA flaws under active malicious scanning and exploitation: watchTowr and VulnCheck independently report that critical flaws in the open-source AI platform MLflow and the industrial automation software FUXA are being used to steal cloud credentials and secrets, with activity moving from scanning to real exploitation. The Hacker News
NSA/CISA/FBI joint advisory: active threat to Siemens S7 series PLCs: Multiple U.S. agencies warn that threat actors are using AI-generated exploitation scripts disguised as legitimate monitoring tools to reconnoiter and attack internet-exposed Siemens S7 PLCs, targeting Critical Manufacturing, Energy, Water/Wastewater, Chemical, and Food/Agriculture sectors. The agencies call this "not a theoretical risk." CISA advisory
Clop-linked web shell custom-built for PTC Windchill data theft and extortion: ReliaQuest describes a JSP web shell tied to the Clop ransomware gang, purpose-built for PTC Windchill/FlexPLM servers, with credential decryption and engineering-data-vault mapping built in as a full extortion platform. Bleeping Computer
High-Severity Vulnerabilities (CVSS ≥ 8.0)
Mozilla ships Firefox 154 / Thunderbird 154 with a batch of critical fixes: The release patches a sandbox escape in the Remote Settings Client component (CVE-2026-75874, CVSS 10.0 — maximum score), an Add-ons Manager mitigation bypass (CVE-2026-74979, CVSS 9.8), a Graphics-component integer overflow (CVE-2026-74964, CVSS 9.8), and more memory-safety issues, several flagged as showing evidence of possible exploitation. Upgrade is recommended. NVD
ArcadeDB pre-26.8.1: three unauthenticated/authorization-bypass flaws combine to full takeover: Async commands executing without a bound user identity enable privilege escalation (CVE-2026-75851, CVSS 9.4); the MongoDB wire-protocol plugin doesn't enforce SASL auth (CVE-2026-75852, CVSS 9.3); the Redis wire-protocol plugin has no authentication at all (CVE-2026-75854, CVSS 9.3). Fixed in 26.8.1. NVD
Grav CMS and its API plugin disclose three authorization flaws: The API plugin (pre-1.0.14) has two broken-authorization bugs allowing scope-restricted API keys to act with super-admin privileges (CVE-2026-75832, CVE-2026-75835, both CVSS 9.3); Grav core (pre-2.0.14) fails to restrict the super-admin field in group blueprints, letting a delegated admin escalate to full super-admin (CVE-2026-75837, CVSS 9.3). NVD
A wave of critical WordPress plugin flaws, mostly unauthenticated file upload / SQL injection: Cwicly (contributor-level RCE, CVSS 9.9), GP Premium (contributor arbitrary file upload, CVSS 9.9), Templatiq (contributor arbitrary file upload, CVSS 9.9), FundEngine (unauthenticated PHP object injection, CVSS 9.8), Sticky Chat Widget (unauthenticated SQL injection, CVSS 9.3), Modern Events Calendar (unauthenticated SQL injection, CVSS 9.3), among others. Site owners should check installed plugin versions. NVD example
The widely embedded Expat XML parser has a denial-of-service flaw: Versions through 2.8.3 have O(N²) complexity in storeAtts(); a malformed XML document just a few megabytes in size can exhaust CPU on any application parsing untrusted XML, with no authentication or non-default options required (CVE-2026-66046, CVSS 8.7). Expat's broad indirect dependency footprint gives this wide supply-chain reach. NVD
Microsoft Copilot Personal "CoSnitch" flaws: one click can exfiltrate data from connected apps: Varonis Threat Labs disclosed three flaws letting a crafted link silently pull data from a victim's Copilot session and its connected apps upon a single click, partly through an undocumented URL parameter Copilot itself exposes. The associated CVE-2026-24301 (command injection leading to information disclosure, CVSS 8.8) has been fixed by Microsoft. The Hacker News
Web Security Research & Threat Intelligence
SilkParasite espionage campaign targets Central Asian governments with five brand-new RATs: First spotted in late 2025, the campaign uses seven RAT families, five never previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The Hacker News
"Operation CameraSwarm": 14,500+ Dahua devices compromised via credential attacks and P2P relay abuse: Hunt.io researchers reconstructed the campaign, active June 17–July 22, 2026, from a 407MB exposed working directory containing 2,616 files, revealing credential attacks, two auth-bypass flaws, and P2P relay techniques. The Hacker News
TWINLOOT: modular Python implant hiding entirely inside trusted SharePoint/Teams traffic: Ontinue describes a PyArmor-hardened framework whose entire C2 flow runs through SharePoint Online file tasking, blending into legitimate Microsoft 365 traffic. The Hacker News
"City Forum" infrastructure has scraped both Salesforce and ServiceNow portals for over a year: Reco traced sustained cross-industry customer-portal scraping back to a single server (158.220.87.79) active since 2025 — an unusually long-lived and broad campaign. The Hacker News
StopAndProtect operation abuses nearly 2,000 hacked WordPress sites as malware infrastructure: Rather than one malware family, the operation runs a full criminal toolkit across compromised hosts to distribute malware and stage stolen documents, screenshots, and activity logs. The Hacker News
Huntress: password-spraying attacks up 155x in H1 2026: One campaign alone generated more than 81 million login attempts in two weeks, exploiting legacy authentication and gaps in MFA coverage. Bleeping Computer
AI Security
Researchers demonstrate self-propagating "mind virus" payloads spreading between AI agents: Anthropic and Switzerland's EPFL show that malicious payloads can spread from one AI agent to the next through the editable system-prompt files agent harnesses use to carry state across sessions, validated in a simulated six-agent coding environment. Preprint released August 10, 2026. The Hacker News
Other
U.S. charges 17 Iranian hackers over $3.4 billion IP theft: The defendants are alleged members of hacker-for-hire company Mabna Institute, accused of years-long data theft operations against American organizations. Bleeping Computer
CISA/FBI: Medusa ransomware has breached 500+ critical infrastructure organizations since 2021: The largest tally the agencies have disclosed for this group to date. Bleeping Computer
Hardware wallet maker SafePal discloses data exposure affecting ~40,000 customers: An authorization flaw in an order-tracking plug-in exposed names, emails, shipping addresses, phone numbers, and purchase details; affected customers were notified individually on August 16. The Hacker News