Daily Briefing

Cybersecurity & Geopolitics Briefing — Tuesday, August 18, 2026

Geopolitical cyber intelligence in 5 minutes
Tuesday, August 18, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Tuesday, August 18, 2026, and 8 disclosed vulnerabilities (CVE-2025-62593, CVE-2026-54121, CVE-2026-65640, CVE-2026-66795 and others). Each entry links to the original reporting.

Share this digest:

Iran-Linked Hackers Evolve Cavern C2 to Exploit DNS and Google Services (1 minute read)

Kaspersky identified new components of the Cavern C2 framework used by Iranian nation-state actors against Israeli targets, blending malicious traffic through DNS and Google Apps Script since December 2025.

The Hacker News · 13h ago · Read full article →

Ukraine's GUR Hits Wildberries in Cyberattack Timed to Drone Strikes (1 minute read)

Ukraine's military intelligence disrupted Wildberries, Russia's largest e-commerce platform, coordinating the cyberattack with simultaneous drone strikes on the company's physical infrastructure.

The Record · 19h ago · Read full article →

U.S.-Iran Nuclear Deadline Collapses as 60-Day Memorandum Expires (2 minute read)

The United States and Iran failed to reach a nuclear deal by the agreed 60-day deadline, leaving the conflict's end conditions unresolved. The collapse reopens escalation pathways and puts allied commitments to the memorandum framework under immediate strain.

Just Security · 19h ago · Read full article →

Iran and Tajikistan Finalize Fuel Deal as Russia's Supply Falters (1 minute read)

Tajikistan is finalizing an oil import agreement with Iran after sanctions pressure degraded Russia's capacity as its primary fuel supplier. The deal expands Iran's economic influence in Central Asia at the direct expense of Russian leverage.

The Diplomat · 15h ago · Read full article →

Trump Scales Back US-South Korea Drills to Court Pyongyang (1 minute read)

The U.S. reduced joint military exercises with South Korea as a concession to North Korea amid renewed diplomatic outreach by the Trump administration. The rollback weakens a core deterrence signal to Pyongyang while undermining confidence in U.S. alliance commitments across the Indo-Pacific.

Foreign Policy · 11h ago · Read full article →

U.S. Policy Analysts Urge Test-and-Restrict Regime for Chinese AI Models (1 minute read)

Just Security argues Washington should test Chinese AI models for security risks and apply targeted restrictions rather than outright bans or unguarded adoption. The debate mirrors earlier semiconductor export battles and signals AI models are now treated as a national-security-grade technology category.

Just Security · 18h ago · Read full article →

China's Expanded Jurisdiction Laws Trap Western Firms in Sanctions Crossfire (1 minute read)

Beijing is enacting laws that extend Chinese legal jurisdiction extraterritorially, forcing Western companies operating in China to choose between compliance with U.S. and EU sanctions or Chinese counter-measures. The framework weaponizes market access, giving China a structural tool to blunt Western economic coercion.

Foreign Policy · 19h ago · Read full article →

Mirai-Based Evooo1Bot Hijacks Linux Edge Devices as SOCKS5 Proxies (1 minute read)

Researchers identified Evooo1Bot, a new Linux botnet built on leaked Mirai source code that converts internet-facing edge devices into SOCKS5 proxies for traffic anonymization and DDoS operations.

The Hacker News · 22h ago · Read full article →

SafePal Breach via Plugin Vulnerability Exposes 40,000 Crypto Wallet Customers (1 minute read)

Unknown attackers exploited a flaw in SafePal's order-tracking plugin to steal personal data on nearly 40,000 customers. The breach continues a pattern of supply-chain and plugin-layer attacks against crypto hardware wallet vendors, undermining user trust in hardware-as-security model.

SecurityWeek · 22h ago · Read full article →

SafePal Confirms 40,000-Customer Breach, Stolen Data Includes Order Information (1 minute read)

SafePal disclosed a data breach Sunday affecting nearly 40,000 customers, with personal and order data exfiltrated in the incident. The breach is the latest in a string of hits against crypto hardware wallet companies, raising questions about backend security posture across the sector.

The Record · 14h ago · Read full article →

CEVA Logistics Breach Hits Pokémon Center, Exposes UK and German Customer Data (1 minute read)

Hackers breached third-party logistics provider CEVA Logistics and stole personal and order data belonging to Pokémon Center customers in the UK and Germany. The incident illustrates how a single logistics-layer compromise propagates across multiple consumer brands simultaneously.

BleepingComputer · 12h ago · Read full article →

Microsoft Patches ShieldBreak Zero-Day CVE-2026-69414 After Public Disclosure (1 minute read)

Microsoft is developing a fix for CVE-2026-69414, a zero-day dubbed ShieldBreak disclosed publicly by researcher Nightmare Eclipse, with no patch yet available. Public disclosure before a patch exists leaves all unmitigated Windows Defender deployments exposed during the remediation window.

BleepingComputer · 22h ago · Read full article →

CISA Adds Actively Exploited Ray AI Framework RCE Flaw to KEV Catalog (1 minute read)

CISA added CVE-2025-62593, a critical code-injection vulnerability in the Ray distributed AI computing framework, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Widespread AI/ML workload deployments running Ray create a large attack surface for remote code execution at scale.

The Hacker News · 1h ago · Read full article →

CISA KEV Flags Ray CVE-2025-62593 Browser-Exploitable RCE in AI Framework (2 minute read)

CISA added CVE-2025-62593, a code-injection flaw in Ray exploitable via Firefox and Safari, to the KEV catalog under BOD 26-04, requiring immediate mitigation. Active exploitation of an AI infrastructure framework signals adversaries are targeting the ML development pipeline, not just production systems.

CISA KEV · 1d ago · Read full article →

COMFAST CF-N1-S CVE-2026-75094 OS Command Injection Exploit Published Publicly (2 minute read)

CVE-2026-75094, a CVSS 9.1 OS command injection flaw in COMFAST CF-N1-S 2.6.0.1 routers via the CGI mbox-config interface, is remotely exploitable with a public proof-of-concept already available.

CVE Feed (High Severity) · 5h ago · Read full article →

CVE-2026-70495 Lets Attackers Seize Full Kubernetes Cluster via search-v2-operator (2 minute read)

A flaw in search-v2-operator's search-serviceaccount grants cluster-wide impersonation rights; any attacker reaching one of four affected pods can escalate to system:masters. CVSS 8.8 means this is exploitable without physical access and threatens any Red Hat ACM deployment running the component unpatched.

CVE Feed (High Severity) · 11h ago · Read full article →

CVE-2026-66795 Lets Spoke Cluster Accounts Hijack Hub via Malicious CSRs (2 minute read)

managedcluster-import-controller's CSR auto-approver skips signer-name validation and PEM decoding, letting a privileged spoke-cluster service account submit a malicious certificate request to escalate privileges on the hub.

CVE Feed (High Severity) · 10h ago · Read full article →

CVE-2026-65640 Gives WordPress Author-Level Users Remote Code Execution (3 minute read)

All WordPress versions are vulnerable to RCE via malicious Postscript file upload when Imagick and Ghostscript are active; version 7.0.4 patches the flaw. Author-level access is a low bar for many CMS deployments, making exploitation likely in shared-hosting and media-heavy environments before patching completes.

CVE Feed (High Severity) · 10h ago · Read full article →

CVE-2026-71472 Allows Shell and SQL Injection in ACM Search via Unsanitized work_mem (3 minute read)

Authenticated hub administrators or Search CR editors can inject shell commands or SQL into acm-search-v2-rhel9 by supplying a malicious WORK_MEM value, due to absent input validation in a bash script pipeline.

CVE Feed (High Severity) · 11h ago · Read full article →

CVE-2026-54121 Lets Standard Domain Users Compromise Enterprise Certificate Authority (1 minute read)

CVE-2026-54121 allows an ordinary domain user to elevate a misconfigured Enterprise CA to Domain Controller equivalence, effectively handing over Tier 0 identity infrastructure. The flaw exposes how standing privilege and implicit PKI trust convert routine user accounts into full Active Directory takeover vectors.

BleepingComputer · 17h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now