HERMES // CYBER INTELLIGENCE // 2026-08-21

Cybersecurity Intelligence Report — 21 August 2026

CRITICAL 2

KEV 2

[9] [CISA KEV] CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability - TrueConf Server

TrueConf Server Missing Authentication for Critical Function Vulnerability - TrueConf Server. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-23

[6] [CISA KEV] CVE-2026-72530: TrueConf Server Code Injection Vulnerability - TrueConf Server

TrueConf Server Code Injection Vulnerability - TrueConf Server. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-09-03

DLS VICTIMS 14

[5] [RANSOMWARE] direwolf leaked Reviso Cloud Accounting Limited

Victim: Reviso Cloud Accounting Limited | Group: direwolf | Website: reviso.com | Country: DK | Details: [AI generated] Reviso Cloud Accounting Limited is a software company that provides cloud-based accounting solutions primarily targeting small and medium-sized businesses. The platform offers tools for bookkeeping, invoicing, financial reporting, and VAT management. The company operates within the fi

[5] [RANSOMWARE] direwolf leaked Studee

Victim: Studee | Group: direwolf | Website: studee.com | Details: [AI generated] Studee is an online platform that helps international students find and apply to universities around the world. Operating in the education technology industry, the company is based in the United Kingdom. It connects prospective students with hundreds of universities globally, offering

NEWS 20

[8] Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

[7] Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

[7] Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

[7] Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra

[7] 8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapid7 The increase adds pressure to a patching process that requires teams to decide which problems

[7] [RANSOMWARE] DYSPHOR1A leaked The University of Delhi (DU)

Victim: The University of Delhi (DU) | Group: DYSPHOR1A | Country: IN | Details: The University of Delhi (DU) is a major public university in New Delhi, India, founded in 1922. It is one of India's most well-known universities, offering undergraduate, postgraduate, and doctoral programs across subjects like science, arts, commerce, law, and technology.

[7] [RANSOMWARE] titan leaked Elbor S.p.A.

Victim: Elbor S.p.A. | Group: titan | Website: www.elbor.it | Country: IT | Details: [AI generated] Elbor S.p.A. is an Italian company operating in the distribution and wholesale sector. Based in Italy, it specializes in the commercialization of industrial and technical products, serving businesses across various sectors. The company functions as a trading and supply chain intermedi

[6] Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

[6] ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

[5] US agencies warn of AI-powered attacks on Siemens industrial controllers

Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industrial computers that open valves, run pumps, and control machinery in factories, water plants, and power stations. The NSA, CISA, FBI, Department of Energy (DOE), and Environmental Protection Agency (EPA) issued the joi

[5] [RANSOMWARE] kairos leaked Ayuntamiento de Velilla de San Antonio

Victim: Ayuntamiento de Velilla de San Antonio | Group: kairos | Country: ES | Details: El Ayuntamiento de Velilla de San Antonio es el organismo oficial de gobierno local y administración del municipio de Velilla de San Antonio, situado en la Comunidad de Madrid, España. Gestiona los servicios públicos, el padrón, los impuestos locales y la vida ciudadana de la localidad.

[5] [RANSOMWARE] shinyhunters leaked Cyrus******

Victim: Cyrus****** | Group: shinyhunters | Details: This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 20 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK

[5] [RANSOMWARE] emperador leaked NetExam

Victim: NetExam | Group: emperador | Website: netexam.com | Details: NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification trac