CVE-2024-55591, CVE-2025-24472, CVE-2026-19560, CVE-2026-65400, CVE-2026-69414, CVE-2026-72970
Get tomorrow's brief in your inbox
Today: Microsoft Defender zero-day "ShieldBreak" (CVE-2026-69414) is unpatched and under active advisory, with Microsoft working on a fix. A macOS screen sharing vulnerability (CVE-2026-65400) is being actively exploited to deploy Monero miners on systems with port 5900 exposed. Gunra ransomware, linked to North Korean actors, is targeting critical infrastructure via FortiOS/FortiProxy flaws. ShinyHunters dumped 1.6 million RingCentral records after a social engineering attack. The Trivy supply chain compromise affected 2,500+ organizations, far beyond the initially blamed LiteLLM package.
Microsoft Defender "ShieldBreak" Elevation of Privilege Zero-Day (CVE-2026-69414)
Microsoft has acknowledged an elevation of privilege vulnerability in the Microsoft Malware Protection Engine, publicly referred to as "ShieldBreak." No patch is available yet. Microsoft is working on a security update and will provide information when it is ready.
macOS Screen Sharing Remote Code Execution Under Active Exploitation (CVE-2026-65400)
A state management flaw in macOS screen sharing (port 5900) allows unauthenticated remote attackers to gain root access. The Netherlands NCSC confirmed active exploitation across multiple systems with port 5900 exposed to the internet, with attackers deploying Monero cryptocurrency miners. Apple patched this in updates for macOS Tahoe, Sequoia, and Sonoma. CVSS 7.1.
Gunra Ransomware Joint Advisory: FortiOS/FortiProxy Exploitation (CVE-2024-55591, CVE-2025-24472)
US, UK, and South Korean agencies issued a joint advisory on Gunra ransomware, a Conti-derived RaaS operation targeting public health, financial, and government sectors. Operators exploit CVE-2024-55591 (EPSS 0.983, 100th percentile, CISA KEV) and CVE-2025-24472 (EPSS 0.036, 88th percentile, CISA KEV) in FortiOS/FortiProxy for initial access. The group launched a RaaS affiliate program ("Golden Community") in January 2026 and has expanded to Linux. Strong links to North Korean state-backed actors have been identified. A cryptographic flaw in the Linux variant allows full file recovery.
RingCentral Breach: 1.6 Million Records Dumped by ShinyHunters
ShinyHunters compromised RingCentral via a social engineering campaign in July, exfiltrating 623 GB of data. After RingCentral refused extortion demands, ShinyHunters published a 280 GB archive containing approximately 1.6 million unique email addresses, names, physical addresses, and phone numbers. The data has been added to HaveIBeenPwned. RingCentral states core platform services were not impacted.
French Tax Authority (DGFiP) Breach Confirmed
France's Directorate General of Public Finances confirmed unauthorized access via a stolen identity in late June. A threat actor claims 600,000 victim records, though France's Economy Ministry reports 2 million records involved. The investigation is ongoing.
Trivy Supply Chain Compromise Affected 2,500+ Organizations (Corrected Attribution)
SOCRadar's analysis reveals that the supply chain compromise attributed to LiteLLM actually originated with Aqua Security's Trivy scanner. The Shai-Hulud worm from threat actor TeamPCP propagated from Trivy downstream through automated builds. Of 2,188 identified victim organizations, 95% had data collected before the poisoned LiteLLM packages even hit PyPI on March 24. The malware used a .pth file that Python automatically executed at interpreter startup, bypassing ignore-scripts protections. Six CI/CD platforms were affected (GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, Buildkite). Over 1,000 organizations exposed JWT/auth tokens; hundreds exposed AWS keys, private keys, and API secrets.
Trezor Confirms 13,000 Customers Exposed via Logistics Breach
Crypto hardware wallet maker Trezor confirmed a data breach at third-party logistics provider ShipMonk exposed customer shipping details for approximately 13,000-14,000 customers. No wallet keys or cryptocurrency were at risk.
LexisNexis Investigating Potential Third Hack
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after detecting suspicious activity on servers managed by a third-party vendor. This would be the third data breach suffered by LexisNexis in recent years.
Microsoft Edge RCE via Heap Overflow (CVE-2026-72970)
A heap-based buffer overflow in Microsoft Edge (Chromium-based) allows remote code execution over a network.
Chromium Use-After-Free in Blink (CVE-2026-19560)
Use-after-free vulnerability in Blink addressed in Chromium. Edge inherits the fix.
On-Prem SharePoint Under Zero-Day Attack
Microsoft patches failed to fully fix an on-premises SharePoint vulnerability, which is now being exploited as a zero-day.
NIST Seeks Public Comment on NVD Modernization with AI
NIST published an RFI on integrating AI into NVD operations. Vulnerability volumes have surged 72% year-over-year in 2026 (50,340 CVEs through mid-August), driven partly by AI-augmented research. Less than 1% of vulnerabilities from GitHub and VulnCheck sources are exploitable. NIST is prioritizing enrichment for CISA KEV entries, federal software, and critical software per EO 14028. Comments are open.
Scottish Government Data Breach via Third-Party Assessment
Scotland's Crown Office and Procurator Fiscal Service disclosed that a third-party managing a government data maturity assessment was breached, exposing approximately 300 employees' names, roles, and work emails. Other Scottish government agencies using the same assessment process may also be affected.
NHS Data Breach via Unencrypted Pagers
The NHS admitted to routinely sending patient transplant data, including names, dates of birth, and organ types, over unencrypted pager networks.
"The Com" Cybercrime Syndicate Member Sentenced
A UK court sentenced Justin Swaddle to two years for blackmail and child abuse tied to "The Com," a decentralized online crime collective. The NCA identified 117 female victims aged 13-17 across multiple countries. The Com operates factions covering sexual coercion, financial extortion, and corporate ransomware.
DecryptAds: New Free Adtech Transparency Tool
A new service at decryptads.com scrapes ads.txt, app-ads.txt, buyers.json, and sellers.json files to map ad ecosystem relationships. Use cases include tracking malvertising sources, identifying ad networks in adversarial nations, and detecting AI-generated spam sites.
Google Cloud Post-Quantum Cryptography Roadmap: 2029 Target
Google Cloud published its PQC migration roadmap. ML-KEM hybrid key exchange is live on API endpoints. SNDL risk mitigation targeted for end of 2027. Signature integrity and identity protections targeted for end of 2028. Customers should inventory cryptographic assets, update tooling to PQC-capable libraries, and test against available quantum-safe APIs.
CVE-2026-65400 - macOS Screen Sharing RCE
State management flaw in macOS screen sharing allows unauthenticated remote root access. CVSS 7.1. Patched in macOS Tahoe, Sequoia, and Sonoma updates. Actively exploited for Monero mining.
CVE-2026-69414 - Microsoft Defender "ShieldBreak" EoP
Elevation of privilege in Microsoft Malware Protection Engine. No patch available. Microsoft is developing a fix.
CVE-2026-72970 - Microsoft Edge RCE
Heap-based buffer overflow in Edge (Chromium-based) enabling remote code execution.
CVE-2026-19560 - Chromium Blink Use-After-Free
Use-after-free in Blink rendering engine. Patched in Chromium, inherited by Edge.
Commercial Refrigeration Controller Vulnerabilities
Claroty found 23 vulnerabilities in Copeland XWEB Pro controllers (chainable to root RCE) and multiple RCE flaws in Danfoss AK-SM 800A controllers. Both vendors have released patches.
Supply chain attacks continue to compound: the Trivy/Shai-Hulud worm demonstrated how a single compromised build tool can ripple across 2,500+ organizations and six CI/CD platforms in under a week, stealing thousands of secrets per victim. The Gunra ransomware joint advisory underscores the convergence of nation-state (North Korean) resources with RaaS ecosystems, now actively recruiting affiliates. The surge to 50,000+ CVEs in 2026 (up 72%) is forcing NIST to explore AI-driven triage, a sign that manual vulnerability management at scale is no longer viable.