HERMES // CYBER INTELLIGENCE // 2026-08-19

Cybersecurity Intelligence Report — 19 August 2026

CRITICAL 1

[13] CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

KEV 4

[6] [CISA KEV] CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - Microsoft Internet Key Exchange (IKE) Service Extensions

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - Microsoft Internet Key Exchange (IKE) Service Extensions. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines..

[6] [CISA KEV] CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability - Broadcom VMware vCenter

Broadcom VMware vCenter Path Traversal Vulnerability - Broadcom VMware vCenter. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-21

[6] [CISA KEV] CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability - Microsoft SharePoint

Microsoft SharePoint Weak Authentication Vulnerability - Microsoft SharePoint. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-21

[6] [CISA KEV] CVE-2026-65400: Apple macOS Improper Authentication Vulnerability - Apple macOS

Apple macOS Improper Authentication Vulnerability - Apple macOS. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-21

DLS VICTIMS 4

NEWS 20

[8] 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn

[7] Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -

[7] Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research

[7] [RANSOMWARE] dragonforce leaked R & D Machine and Engineering

Victim: R & D Machine and Engineering | Group: dragonforce | Website: rdmachine.com | Country: US | Details: &D Machine and Engineering, LLC specializes in CNC machining of precision metal components primarily for the aerospace, defense, and space industries. The company is known for its ability to maintain tight tolerances and produce complex geometries using advanced 5-axis milling and coordinate measuri

[7] [RANSOMWARE] Storm leaked Standard Tool & Die

Victim: Standard Tool & Die | Group: Storm | Website: standardtool.net | Country: US | Details: Standard Tool & Die specializes in designing and manufacturing die cast dies, plastic molds, and trim dies for various industries including automotive, appliance, furniture, and household goods. The company offers single source manufacturing solutions and focuses on precision machining for both dome

[6] NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation

NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber devices from disrupting their own networks, consuming costly capacity and attacking customers and organizations across the internet. Consumer broadband routers, cameras and other IoT devices are in

[6] Google’s $10,000 refund test shows why AI agents need zero trust

Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The project tests an approach that assumes an AI agent could be manipulated or compromised and puts security controls around it to limit what the agent can do. The architecture uses safeguards outside the model to verify a

[6] [RANSOMWARE] emperador leaked Prefeitura Municipal de Arcos

Victim: Prefeitura Municipal de Arcos | Group: emperador | Website: arcos.mg.gov.br | Country: BR | Details: We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin credentials have been exfiltrated. Critical systems have been encrypted. We have your data. You do not. You have 14 days to respond. No response = data published + permanent loss. Cont

[5] Download: 2026 Credential Risk Report

85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move toward Continuous Credential Defense. Learn: Where gaps remain across credential detection, monitoring, and response Why MFA and point-in-time password screening do not fully address credential exposure

[5] [RANSOMWARE] akira leaked Borchert & LaSpina

Victim: Borchert & LaSpina | Group: akira | Details: Borchert & LaSpina, P.C. is a respected law firm located in Queens, New York, with a team of si x experienced attorneys specializing in various areas of law including real estate, mortgage fo reclosure, commercial litigation, personal injury, and elder law. We will upload corporate data soon. Clien

[5] [RANSOMWARE] shinyhunters leaked Logitech/ Streamlabs

Victim: Logitech/ Streamlabs | Group: shinyhunters | Website: logitech.com | Country: CH | Details: This is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK

[5] [RANSOMWARE] gunra leaked BOMOHSA

Victim: BOMOHSA | Group: gunra | Website: bomohsa.com | Country: HN | Details: Sector: Service Contractor | Revenue: US$ 20,000,000

[5] [RANSOMWARE] incransom leaked SpearFin Ltd

Victim: SpearFin Ltd | Group: incransom | Country: MU | Details: SpearFin Ltd https://spearfin.net SpearFin offers a wide range of services including fund administration, corporate services, compliance support, and investor relations. Assets Under Administration US$10 billion. The leak occurred on June 26, 2026. Total leak: 416 GB Leak included: NDA,

[5] [RANSOMWARE] incransom leaked ssf-int.com ssf-ing.de

Victim: ssf-int.com ssf-ing.de | Group: incransom | Website: ssf-int.com | Country: DE | Details: SSF International GmbH is an engineering firm headquartered in Munich, Germany. A subsidiary of SSF Ingenieure AG, the company provides comprehensive engineering services in project management, supervision, consultancy, design, quality management, and special construction design worldwide. It specia