Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 20, 2026·4m

Cyber Security News for August 20 2026 - Daily DefSec Brief

Show notes

1. Feds warn of active AI-scripted attacks on internet-exposed Siemens S7 PLCs — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
2. Critical Citrix NetScaler auth-bypass patched, exploitation expected — CVE-2026-19490, CVE-2026-19489 — SecurityWeek — https://www.securityweek.com/exploitation-expected-for-critical-authentication-bypass-patched-in-citrix-netscaler/
3. UAT-10147 deploys cross-platform SPECTRE implant with Linux rootkit and BYOVD — CVE-2019-16098, CVE-2021-21551 — Cisco Talos — https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/
4. RDK-B broadband gateway WebUI has five flaws including auth bypass and possible RCE — CVE-2026-19505 through CVE-2026-19509 — CERT/CC — https://kb.cert.org/vuls/id/874418
5. ToxicPanda 2.0 Android trojan adds PIN theft and expands to 349 institutions — The Hacker News — https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html
6. New Manic Android malware exfiltrates data through nearby infected devices — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
7. Fake Google Gemini installer delivers Vidar infostealer via Colab lure — Help Net Security — https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/
8. 15 malicious Firefox extensions abuse Cloudflare Workers to steal crypto wallets — Cyber Security News — https://cybersecuritynews.com/malicious-firefox-extensions-2/
9. 41 fake download sites show a real link, then redirect to Download Studio installer — Malwarebytes Labs — https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else
10. Password spraying surged 155x, driven by Azure CLI targeting — BleepingComputer — https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
11. Cisco RoomOS USB stack overflow allows root code execution — CVE-2026-20302 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-bof-vTMANZgu
12. Cisco BroadWorks XXE flaw leaks config files to unauthenticated attackers — CVE-2026-20320 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt
13. Geekom mini PC LAN driver shipped with the Asruex backdoor — SC World — https://www.scworld.com/brief/geekom-admits-malware-found-in-legacy-mini-pc-driver-download
14. Def Con attendees hit by persistent phishing that abuses Google Apps Script — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/def-con-attendees-persistent/
15. Rogue ransomware affiliate poses as a recovery firm to double-dip on victims — BleepingComputer — https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/