
Cyber Security News for August 19 2026 - Daily DefSec Brief
Show notes
1. Windows IKE Extension RCE added to CISA KEV, now exploited — CVE-2026-33824 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. macOS Screen Sharing auth bypass added to CISA KEV — CVE-2026-65400 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
3. MLflow SSRF and FUXA auth-bypass under active exploitation — CVE-2026-64849, CVE-2026-25895 — The Hacker News — https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html
4. Cursor IDE zero-day runs code on repo open — Cyber Security News — https://cybersecuritynews.com/cursor-0-day-vulnerability/
5. CoSnitch: one-click Copilot data exfiltration — CVE-2026-24301, CVE-2026-24299 — The Hacker News — https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html
6. Chrome ships two critical graphics-component fixes — CVE-2026-76034, CVE-2026-76036 — Chrome Releases — http://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html
7. Firefox 154 patches 58 flaws, 20 high-severity — SecurityWeek — https://www.securityweek.com/chrome-firefox-updates-patch-dozens-of-vulnerabilities/
8. Oracle August CSPU ships 943 patches for 925 CVEs — Tenable — https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves
9. TWINLOOT runs C2 inside Microsoft cloud services — The Hacker News — https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html
10. NASA AIT-GUI flaw lets unauthenticated spacecraft commands — GHSA-p9r8-2q67-fp86 — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/nasa-ground-control-software-flaw/
11. BeyondTrust EPM for Windows privilege-escalation flaws — CVE-2026-40144, CVE-2026-40145 — Cyber Security News — https://cybersecuritynews.com/beyondtrust-windows-epm-vulnerabilities/
12. 50,000 Stripe merchant API keys leaked in public code — Security Affairs — https://securityaffairs.com/197504/cyber-crime/50000-stripe-secrets-leaked-in-public-code.html
13. Slovakia finds Russian SMS-triggered backdoor in traffic cameras — Risky Business News — https://news.risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/
14. Rapid7 report: volume and speed outpace traditional patch cycles — SecurityWeek — https://www.securityweek.com/ai-driven-vulnerability-surge-breaks-the-traditional-patching-model/
15. Self-propagating payloads spread between AI agents via shared prompt files — The Hacker News — https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html← Previous
Cyber Security News for August 18 2026 - Daily DefSec Brief
Next →
Cyber Security News for August 20 2026 - Daily DefSec Brief