Daily Briefing

Cybersecurity & Geopolitics Briefing — Wednesday, August 12, 2026

Geopolitical cyber intelligence in 5 minutes
Wednesday, August 12, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Wednesday, August 12, 2026, including activity involving Sandworm, Russia, and 6 disclosed vulnerabilities (CVE-2026-19594, CVE-2026-20349, CVE-2026-50656, CVE-2026-68820 and others). Each entry links to the original reporting.

Share this digest:

Sandworm's UAC-0145 Poses as Recruiters to Plant Trojanized VPN on Ukrainian IT Workers (1 minute read)

CERT-UA attributes a fake job interview campaign to UAC-0145, a Sandworm subgroup, which tricks Ukrainian IT professionals into installing a weaponized WireGuard VPN client capable of executing remote commands.

The Hacker News · 13h ago · Read full article →

🇷🇺 Sandworm · Russia

Sandworm Deploys Trojanized WireGuard VPN Against System Administrators Since May (1 minute read)

Russia's Sandworm has run fake job-offer lures targeting system administrators since at least May, delivering a trojanized WireGuard client that provides remote command execution. Persistence on admin workstations grants lateral movement potential across entire enterprise networks.

BleepingComputer · 11h ago · Read full article →

🇷🇺 Sandworm · Russia

Ukraine War and Iran Conflict Drive DDoS Attacks to 1 Tbps, Up 519 Percent (1 minute read)

Geopolitically motivated DDoS campaigns tied to the Ukraine war, Iran conflict, and the World Cup pushed attack traffic to 1 Tbps peaks, a 519% volume surge hitting media publishers.

The Register Security · 16h ago · Read full article →

OpenAI Releases GPT-5.6-Cyber Model With Reduced Refusals for Exploit Development (1 minute read)

OpenAI launched GPT-5.6-Cyber, trained specifically for zero-day discovery, exploit chain development, and penetration testing, with safety guardrails deliberately lowered for high-risk cybersecurity tasks.

The Hacker News · 19h ago · Read full article →

Turkey, Saudi Arabia, and Pakistan Forge Trilateral Defense Pact (1 minute read)

Turkey, Saudi Arabia, and Pakistan are deepening a formal defense arrangement that analysts are comparing to a Middle Eastern NATO construct. The alignment signals a non-Western security bloc taking shape outside U.S.-anchored frameworks as Washington's regional influence contracts.

Foreign Policy · 9h ago · Read full article →

NSA Installs DHS Lawyer Kerianne Tobitsch as New General Counsel (1 minute read)

Kerianne Tobitsch, formerly a senior attorney at the Department of Homeland Security, has been appointed NSA general counsel. The cross-agency move positions a DHS legal perspective inside NSA at a moment of heightened scrutiny over surveillance authorities and intelligence community oversight.

The Record · 12h ago · Read full article →

Western LNG Sanctions Force Russia to Reroute Arctic Exports Through China (1 minute read)

Russia faces mounting pressure to redirect a growing share of Arctic LNG exports to Asian buyers as Western sanctions tighten, deepening Moscow's structural dependence on Beijing as a market of last resort. This accelerates a Sino-Russian energy alignment that complicates Western leverage over both states.

Foreign Policy · 3h ago · Read full article →

Gunra Ransomware Hits Global Critical Infrastructure via Fortinet and Schneider Electric Flaws (1 minute read)

US and South Korean agencies warn that Gunra ransomware is exploiting unpatched Fortinet and Schneider Electric vulnerabilities to breach healthcare, finance, and government sectors worldwide. Gunra follows the RaaS commoditization trend, extending ransomware pressure to operational technology environments.

The Hacker News · 23h ago · Read full article →

US and South Korea Issue Joint Warning on Gunra Ransomware Hitting Government Networks (1 minute read)

CISA and South Korea's National Policy Agency jointly warned global government and critical infrastructure operators to patch against active Gunra ransomware intrusions. The joint advisory signals cross-border coordination as Gunra expands beyond initial target sets.

BleepingComputer · 22h ago · Read full article →

CISA Confirms Ransomware Gangs Actively Exploit High-Severity Microsoft SharePoint RCE (1 minute read)

CISA confirmed ransomware operators are exploiting a high-severity Microsoft SharePoint remote code execution flaw flagged as actively exploited since early July. SharePoint's ubiquity in enterprise environments makes this a high-yield initial access vector with broad downstream impact.

BleepingComputer · 20h ago · Read full article →

Ransomware Gang Hijacks Hospital's Facebook Page, Claims 6TB Health Data Theft (1 minute read)

An unnamed ransomware group seized a hospital system's Facebook page and claims to have stolen 6TB of records including sexual assault, mental health, and abortion data. Weaponizing victim communications channels as extortion leverage marks an escalating harassment tactic against healthcare targets.

The Record · 13h ago · Read full article →

Gunra Ransomware Hits Critical Infrastructure Using Leaked Conti Code and Fortinet Flaws (1 minute read)

The Gunra ransomware-as-a-service operation is breaching critical infrastructure by exploiting unpatched Fortinet firewall and VPN vulnerabilities while bypassing MFA, using leaked Conti source code as its base.

Dark Reading · 11h ago · Read full article →

CISA Adds CVE-2026-20349 Cisco ASA and FTD DoS Flaw to Known Exploited Vulnerabilities (3 minute read)

CISA added CVE-2026-20349, a heap inspection vulnerability in Cisco ASA and FTD enabling unauthenticated remote denial-of-service, to its KEV catalog under BOD 26-04. Firewall availability is a prerequisite for network defense; exploitation forces emergency patching cycles across federal and enterprise environments.

CISA KEV · 1d ago · Read full article →

ShieldBreak PoC Bypasses Microsoft Defender Patch CVE-2026-50656 to Gain SYSTEM Access (1 minute read)

Researcher Chaotic Eclipse published a proof-of-concept dubbed ShieldBreak demonstrating a patch bypass for CVE-2026-50656 (CVSS 7.8) in Microsoft Defender, achieving SYSTEM-level privilege escalation. Public PoC availability compresses the window before threat actors weaponize the bypass in active campaigns.

The Hacker News · 1h ago · Read full article →

CISA Adds CVE-2026-68820 Windows WinSock Use-After-Free Privilege Escalation to KEV Catalog (2 minute read)

CISA added CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock enabling local privilege escalation by authorized attackers, to its KEV catalog under BOD 26-04.

CISA KEV · 1d ago · Read full article →

CISA Flags CVE-2026-72898: Metabase SQL Injection Grants Unauthenticated Admin Access (3 minute read)

Unauthenticated attackers can exploit CVE-2026-72898 in Metabase to inject arbitrary SQL, seize admin control, and exfiltrate connected database credentials. Any internet-exposed Metabase instance is a credential-theft vector; CISA's KEV listing signals active exploitation risk.

CISA KEV · 1d ago · Read full article →

Cisco ASA and FTD CVE-2026-20349 Exploited in Wild, Enables Remote DoS (1 minute read)

Cisco confirmed active exploitation of CVE-2026-20349 (CVSS 8.6) in ASA and FTD firewall software, allowing unauthenticated remote attackers to trigger denial-of-service via malformed HTTP requests.

The Hacker News · 2h ago · Read full article →

Microsoft Patches CVE-2026-68820 Windows Driver Zero-Day Under Active Attack (2 minute read)

Microsoft's monthly update closes 398 flaws including CVE-2026-68820 (CVSS 7.0), a zero-day in a Windows kernel network socket driver enabling local privilege escalation to SYSTEM. Active exploitation before patch release confirms attackers had a working local-to-SYSTEM pathway in production environments.

The Hacker News · 12h ago · Read full article →

CVE-2026-19594: Snowflake Python API Path Traversal Enables Privilege Escalation (3 minute read)

Snowflake Python API versions before 1.13.0 carry CVE-2026-19594, allowing confused-deputy privilege escalation via path traversal and HTTP parameter pollution by any attacker with downstream application access.

CVE Feed (High Severity) · 1h ago · Read full article →

CVE-2026-72526: Multicloud-Integrations Flaw Lets Hub Tenant Hijack Arbitrary Spoke Clusters (3 minute read)

CVE-2026-72526 in the multicloud-integrations component allows a hub-cluster tenant to target arbitrary managed spoke clusters by submitting an unvalidated ocm-managed-cluster annotation, forcing rogue ArgoCD synchronization.

CVE Feed (High Severity) · 6h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now