Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 11, 2026·5m

Cyber Security News for August 11 2026 - Daily DefSec Brief

Show notes

1. Gunra ransomware exploits Fortinet and Schneider Electric flaws — joint FBI/CISA/South Korea advisory — CVE-2024-55591, CVE-2025-24472, CVE-2024-5559 (verify) — The Hacker News — https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
2. Metabase SQL-injection zero-day exploited in the wild — no CVE assigned — SecurityWeek — https://www.securityweek.com/metabase-patches-vulnerability-exploited-as-zero-day/
3. SonicWall SMA1000 flaws added to CISA KEV, used in ransomware — CVE-2026-15409, CVE-2026-15410 — Cyber Security News — https://cybersecuritynews.com/sonicwall-sma1000-vulnerabilities-exploited/
4. Attackers scanning exposed VMware vCenter after auth-bypass disclosed — CVE-2026-59309, CVE-2026-47876, CVE-2026-59310 — Cyber Security News — https://cybersecuritynews.com/hackers-scan-vmware-vcenter-vulnerabilities/
5. Windows 11 USB Plug-and-Play auto-install chained to SYSTEM — The Hacker News — https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
6. OpenAI ships GPT-5.6-Cyber with a lower refusal rate for exploit work — Help Net Security — https://www.helpnetsecurity.com/2026/08/11/openai-gpt-5-6-cyber-model/ · SecurityWeek — https://www.securityweek.com/openai-unveils-new-cybersecurity-model-gpt-5-6-cyber/
7. StormEncryptor deployed by former Medusa affiliate via N-central flaw — CVE-2026-18577 (bypass of CVE-2026-18556) — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/
8. Malicious MCP servers split instructions to make AI agents exfiltrate secrets — The Hacker News — https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
9. Ghostjacking — poisoned logs and alerts hijack AI coding agents — Cyber Security News — https://cybersecuritynews.com/ghostjacking-attack/ · SecurityWeek — https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/
10. LiteLLM supply-chain compromise via poisoned Trivy scanner — Cyber Security News — https://cybersecuritynews.com/litellm-supply-chain-attack/
11. OpenSSH 10.5 fixes locked ssh-agent exposing local-only keys — Help Net Security — https://www.helpnetsecurity.com/2026/08/11/openssh-10-5-ssh-agent-flaw/
12. TrueConf server flaws exploited to swap client installers with PhantomCore — CVE-2026-3502; KLCERT-26-057, KLCERT-26-058 — The Hacker News — https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html
13. OpenCart extension installer directory-traversal allows web-shell upload — CVE-2026-18412 — CERT/CC — https://kb.cert.org/vuls/id/614868
14. Mozilla rotates Firefox GPG signing subkey after GitHub exposure — SecurityWeek — https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/
15. AI tool finds 84 flaws in 4G/5G core software, 23 still unfixed — CVE-2026-8233 (one of set) — Help Net Security — https://www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
16. Valve notifies Steam hardware buyers of breach at shipping partner CEVA — Help Net Security — https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/