Cybersecurity Intelligence Report — 21 August 2026

Written by

in

> CRITICAL SECTION

[15] Critical Zimbra RCE flaw now actively exploited in attacks (BleepingComputer)
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). […]

[11] Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities (SecurityWeek)
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek .

> CISA KEV (last 14 days)

CVE Vendor/Product Score Required action
CVE-2026-72529 [CISA KEV] CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability – TrueConf Server 9 TrueConf Server Missing Authentication for Critical Function Vulnerability – TrueConf Server. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations
CVE-2026-72530 [CISA KEV] CVE-2026-72530: TrueConf Server Code Injection Vulnerability – TrueConf Server 6 TrueConf Server Code Injection Vulnerability – TrueConf Server. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders

> RANSOMWARE VICTIMS (today)

  • anubis: Interim HealthCare [Head office]
  • direwolf: NorthStar, Aztec Software, The Revel Collective, ProSim Aviation Research, Authenticate Information Systems, Diaco Global, iSON XPERIENCES, Deer Creek-Mackinaw CUSD, Allstar Industries, HP Carriers, MCT Group of Companies, Reviso Cloud Accounting Limited, Studee

> NEWS

[8] Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code (TheHackerNews)
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

[7] Critical Elementor Pro bug exposes WordPress sites to RCE attacks (BleepingComputer)
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. […]

[7] CISA warns of hackers exploiting critical MLflow vulnerability (BleepingComputer)
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. […]

[7] Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE (TheHackerNews)
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

[7] Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers (TheHackerNews)
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

[7] Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution (TheHackerNews)
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra

[7] Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities (SecurityWeek)
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek .

[7] Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler (SecurityWeek)
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek .

[7] 8,539 reasons to rethink how vulnerabilities get patched (HelpNetSecurity)
The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapid7 The increase adds pressure to a patching process that requires teams to decide which problems

[7] [RANSOMWARE] DYSPHOR1A leaked The University of Delhi (DU) (ransomware.live/DYSPHOR1A)
Victim: The University of Delhi (DU) | Group: DYSPHOR1A | Country: IN | Details: The University of Delhi (DU) is a major public university in New Delhi, India, founded in 1922. It is one of India's most well-known universities, offering undergraduate, postgraduate, and doctoral programs across subjects like science, arts, commerce, law, and technology.

[7] [RANSOMWARE] titan leaked Elbor S.p.A. (ransomware.live/titan)
Victim: Elbor S.p.A. | Group: titan | Website: www.elbor.it | Country: IT | Details: [AI generated] Elbor S.p.A. is an Italian company operating in the distribution and wholesale sector. Based in Italy, it specializes in the commercialization of industrial and technical products, serving businesses across various sectors. The company functions as a trading and supply chain intermedi

[6] Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads (TheHackerNews)
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

[6] ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More (TheHackerNews)
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

[5] US agencies warn of AI-powered attacks on Siemens industrial controllers (HelpNetSecurity)
Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industrial computers that open valves, run pumps, and control machinery in factories, water plants, and power stations. The NSA, CISA, FBI, Department of Energy (DOE), and Environmental Protection Agency (EPA) issued the joi

[5] [RANSOMWARE] SilentRansomGroup leaked D… (ransomware.live/SilentRansomGroup)
Victim: D… | Group: SilentRansomGroup | Details: Redacted entry – full company name pending disclosure (FULL DATA TIMER active).

[5] [RANSOMWARE] xpl0itrs leaked Gruppo Spaggiari Parma (ransomware.live/xpl0itrs)
Victim: Gruppo Spaggiari Parma | Group: xpl0itrs | Country: IT | Details: School management software

[5] [RANSOMWARE] kairos leaked Ayuntamiento de Velilla de San Antonio (ransomware.live/kairos)
Victim: Ayuntamiento de Velilla de San Antonio | Group: kairos | Country: ES | Details: El Ayuntamiento de Velilla de San Antonio es el organismo oficial de gobierno local y administración del municipio de Velilla de San Antonio, situado en la Comunidad de Madrid, España. Gestiona los servicios públicos, el padrón, los impuestos locales y la vida ciudadana de la localidad.

[5] [RANSOMWARE] shinyhunters leaked Cyrus****** (ransomware.live/shinyhunters)
Victim: Cyrus****** | Group: shinyhunters | Details: This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 20 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK

[5] [RANSOMWARE] emperador leaked NetExam (ransomware.live/emperador)
Victim: NetExam | Group: emperador | Website: netexam.com | Details: NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification trac

[5] [RANSOMWARE] play leaked Be Media (ransomware.live/play)
Victim: Be Media | Group: play | Website: www.bemedia.com | Details: United States

> SUMMARY

New items collected: 102. Critical items: 2. Active ransomware groups represented today: 2. CVEs to prioritise for review: CVE-2026-72529, CVE-2026-72530, CVE-2026-32475, CVE-2026-73570.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Open the companion interactive HTML intelligence report

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *