Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 13, 2026·4m

Cyber Security News for August 13 2026 - Daily DefSec Brief

Show notes

1. VMware vCenter path-traversal RCE now APT-exploited — CVE-2026-59310 — SecurityWeek — https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/
2. Fortinet FortiWeb auth bypass (any-password login) — CVE-2026-26035, CVE-2026-49975, CVE-2026-70465, CVE-2026-70468 — SecurityWeek — https://www.securityweek.com/fortinet-patches-authentication-flaws-in-fortiweb-and-fortimanager/
3. City-Forum campaign reads Salesforce/ServiceNow portals as guest (block 158.220.87.79) — BleepingComputer — https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/
4. WordPress Imagick RCE via crafted upload — CVE-2026-65640 — Cyber Security News — https://cybersecuritynews.com/wordpress-imagick-rce-vulnerability/
5. Akira reboots Windows into Safe Mode to bypass EDR — Cyber Security News — https://cybersecuritynews.com/akira-uses-windows-safe-mode/
6. LiteLLM supply-chain breach: 153GB of CI/CD secrets, 2,488 firms — Help Net Security — https://www.helpnetsecurity.com/2026/08/13/litellm-breach-stolen-credentials-leak/
7. JWR phishing framework, live operator-steered checkout scams — Cisco Talos — https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/
8. Phantom Stealer hides next stage in PNG files — Cyber Security News — https://cybersecuritynews.com/phantom-stealer-inside-png/
9. 737 fake Chrome VPN extensions route traffic through one proxy — The Hacker News — https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html
10. Reasoning-API flaw lets a weaker model decode hidden reasoning — The Hacker News — https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
11. Intel and AMD ship August patches for 80+ vulnerabilities — SecurityWeek — https://www.securityweek.com/chipmaker-patch-tuesday-intel-amd-fix-over-80-vulnerabilities-combined/