Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 18, 2026·4m

Cyber Security News for August 18 2026 - Daily DefSec Brief

Show notes

1. Windows Task Host privesc actively exploited by ransomware gangs — CVE-2025-60710 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
2. Ray unauthenticated RCE via DNS rebinding, actively exploited — CVE-2025-62593 — The Hacker News — https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html
3. GitLab GraphQL flaw lets unauth attackers delete public projects — CVE-2026-19478, CVE-2026-19650 — SecurityWeek — https://www.securityweek.com/gitlab-patches-critical-code-injection-vulnerability/
4. Certighost: low-priv AD user coerces Enterprise CA into issuing a cert — CVE-2026-54121 — BleepingComputer — https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/
5. Unisoc modem chain gives Android kernel access via VoLTE video call — CVE-2022-20210, CVE-2025-31718 — The Hacker News — https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
6. Claude Code drives nearly every stage of a ransomware intrusion — Cyber Security News — https://cybersecuritynews.com/claude-code-helps-ransomware-operator/
7. C2Looper: Rust backdoor delivered via ClickFix, GitHub C2 — Zscaler — https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2
8. Cavern C2 uses DNS A-records and Google Apps Script — The Hacker News — https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html
9. Storm-0501 hijacks Azure tenants for cloud-native ransomware — Tenable — https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response
10. Attackers use AI to identify high-value files worth stealing — Help Net Security — https://www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/
11. Microsoft removes WMIC LOLBin from Windows 11 24H2/25H2 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/
12. Operation ASTERIX: crypto-fraud kit built with AI coding assistants — Rapid7 — https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing
13. Windows Server 2022 hits end of mainstream support Oct 13, 2026 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/