Daily cybersecurity intelligence digest from CyberNetSec.io - August 18, 2026
π 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. CISA Medusa Ransomware Advisory Update
A joint advisory from CISA, the FBI, and HHS reveals the Medusa ransomware group has compromised over 500 organizations by April 2026. The updated report details the group's accelerated tactics, including exploiting new vulnerabilities within 24 hours of disclosure and paying up to $1 million for initial access. The group continues to heavily target the Healthcare and Public Health (HPH) sector using a double-extortion model, disabling security tools, and leveraging living-off-the-land techniques to evade detection.
2. Lazarus Group Exploits Windows Zero-Day
The North Korean state-sponsored Lazarus Group is actively exploiting a Windows privilege escalation zero-day, CVE-2026-68820, in its 'Operation Dream Job' espionage campaign. The vulnerability, rated 7.0 CVSS, allows attackers to gain SYSTEM privileges. The campaign targets defense and aerospace professionals with fake job offers, using the exploit to deploy a new backdoor called 'Troy' and a kernel-mode rootkit. CISA has added the CVE to its KEV catalog, mandating federal agencies to patch.
3. China-Nexus APT Exploits VMware vCenter Flaw
A suspected China-linked APT group is exploiting a critical directory traversal vulnerability (CVE-2026-59310, CVSS 9.8) in VMware vCenter Server. The campaign has compromised hundreds of IPs globally, targeting tech, education, and telecom sectors. Attackers gain root access, deploy backdoors, and in some cases, Babuk-derived ransomware. The rapid weaponization of the flaw, just five days after a patch was released, highlights the significant risk to organizations with internet-facing vCenter instances.
4. Umbraco Patches High-Severity Vulnerability
Umbraco has released security patches for four vulnerabilities, including a high-severity privilege escalation flaw in its CMS backoffice Management API. This flaw could allow a low-privilege user to perform administrative actions, potentially leading to remote code execution (RCE). The update also addresses moderate-severity issues in Umbraco Forms and Umbraco AI, including sensitive data exposure and cross-site scripting. Users are urged to upgrade to the latest versions to mitigate the risks.
5. Ransomware Disrupts Winnipeg Hospital
A ransomware attack at Health Sciences Centre (HSC) Winnipeg, Manitoba's largest hospital, continues to cause operational disruption. An update on August 17 confirmed that while direct patient care remains unaffected, the attack, discovered on August 10, has impacted building systems including HVAC, elevators, and physical security access controls. Shared Health, the provincial authority, has deployed additional security and is investigating the scope of the breach, stating an initial review shows no personal health information was accessed.
6. Poland Investigates MyDr Healthcare Data Breach
Polish authorities are investigating a massive data breach at MyDr, a healthcare software provider, which may have exposed the sensitive data of nearly 19 million people. Attackers claim to have stolen 2.5TB of data, including national ID numbers, prescriptions, and medical records. To prove their access, the hackers leaked the data of a prominent Polish politician. The incident is being described as one of the largest data leaks in Poland's history, prompting a national response.
7. MLflow SSRF Flaw Exploited in the Wild
A critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-64849, CVSS 9.3) in the open-source AI platform MLflow is being actively exploited. Attackers are using the flaw to bypass security controls by abusing HTTP redirects in the webhook feature. This allows them to make requests to internal network services, including cloud metadata endpoints, to steal sensitive credentials and secrets. MLflow versions prior to 3.15.0 are affected, and users are urged to upgrade immediately.
8. StubMaker Typosquatting on RubyGems
A new typosquatting campaign on the RubyGems repository, dubbed 'StubMaker,' is distributing 16 malicious packages. These packages, which use names that are slight misspellings of popular gems, install a Windows-based information stealer. The malware, a Go-based stealer delivered by a Rust loader, is designed to harvest browser credentials, cryptocurrency wallets, and data from Telegram. The campaign highlights the ongoing threat of supply chain attacks targeting open-source registries.
9. Ransomware Hits Colombia's Justice Ministry
Colombia's Ministry of Justice has confirmed it was hit by a ransomware attack on August 2, 2026, just days before a presidential transition. The attack disrupted several digital public services and encrypted files, though the government stated no data was exfiltrated. The ministry isolated affected systems and worked with ColCERT and Microsoft's DART to restore services. The incident is part of a broader trend of increased ransomware activity targeting the nation.
10. GeoServer Zero-Day Exploited for RCE
A critical, unpatched SQL injection zero-day vulnerability in the open-source GeoServer platform is under active exploitation. The flaw (GHSA-mqjf-5f49-2fjh, CVSS 9.8) in the Web Feature Service (WFS) can be escalated to achieve remote code execution (RCE). Attackers began scanning for and exploiting vulnerable systems within hours of its public disclosure on August 12. GeoServer maintainers have since released patched versions, and all users are urged to update immediately.
11. Intraverse.io Leaks 16.9M Records
The Web3 gambling platform Intraverse.io has exposed nearly 16.9 million records due to an unsecured Firebase Realtime Database. A threat actor discovered the database was publicly accessible without any authentication. The leaked data includes player information, the platform's automated gambling bot configurations, funding wallet details, and a working RPC provider key. The incident highlights the severe risks of misconfigured cloud databases.
12. NIST Calls for Comment on Human-Centered Security
The U.S. National Institute of Standards and Technology (NIST) is seeking public feedback on a draft concept paper for a human-centered approach to cybersecurity. This initiative aims to move beyond traditional employee awareness training and address the systemic root causes of human-related security incidents, such as poor usability and organizational culture. NIST views people as a key part of the defense and aims to develop new guidance based on the public comments, which are due by September 30, 2026.
π Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.










