Weekly Cybersecurity Report | Week 33, 2026

As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.

Weekly Cybersecurity Report | Week 33, 2026

Information security updates and events from the past week

       1.Microsoft August 2026 Patch Tuesday Fixes Actively Exploited Kernel Zero-Day (CVE-2026-68820)

  • Summary: On August 11, 2026, Microsoft released its monthly security update addressing more than 400 vulnerabilities across Windows and server products, including 42 Critical flaws. Among them is CVE-2026-68820, an actively exploited high-severity zero-day vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The use-after-free defect allows local authenticated attackers to elevate privileges to SYSTEM without user interaction.
  • Impact / Significance: Privilege escalation vulnerabilities in kernel-mode drivers like afd.sys allow attackers with low-level footholds to gain complete administrative and kernel control. This facilitates disabling endpoint detection (EDR), manipulating memory, and deploying secondary ransomware or espionage payloads.
  • Recommendations:
    • Prioritize immediate deployment of the August 2026 Windows cumulative updates (KB5121003, KB5120240, or KB5120249).
    • Audit endpoint telemetry for anomalous child processes spawned by WinSock network drivers.
    • Restrict local account creation and enforce the principle of least privilege across all user endpoints.
  • Source: SecurityWeek — Microsoft Fixes 421 CVEs, One Exploited Zero-Day | BleepingComputer — Microsoft August 2026 Patch Tuesday  

         2.Unpatched Zero-Day in GeoServer Targeted in In-the-Wild Exploits

  • Summary: On August 12, 2026, a security researcher publicly disclosed an unauthenticated SQL injection vulnerability affecting the open-source GeoServer mapping platform. Within hours of disclosure, threat actors began scanning and actively attempting to exploit internet-exposed deployments. The flaw resides in GeoServer’s jsonArrayContains filter function used with PostGIS and Oracle JDBC data stores, allowing remote attackers to execute arbitrary SQL commands and achieve Remote Code Execution (RCE) in configurations where database privileges are elevated.
  • Impact / Significance: GeoServer powers location-based data services and mapping across government agencies, utilities, logistics networks, and environmental monitoring systems. Because the vulnerability currently lacks an official vendor patch, public-facing instances face imminent compromise and unauthorized access to underlying spatial and enterprise databases.
  • Recommendations:
    • Remove GeoServer instances from direct public internet exposure by placing them behind a secure VPN or authenticated reverse proxy.
    • Implement Web Application Firewall (WAF) rules to inspect and block malformed queries containing jsonArrayContains filter parameters.
    • Restrict GeoServer database accounts to read-only access where possible, ensuring connections do not run with database administrator (sa / postgres) privileges.
    •  
  • Source: SecurityWeek — Hackers Exploiting Unpatched GeoServer Zero-Day | The Hacker News — Unpatched GeoServer Zero-Day Targeted

         3.Six-Agency Joint Advisory Details Gunra Ransomware Operations (AA26-222A)

  • Summary: On August 10, 2026, the FBI, CISA, NSA, U.S. Secret Service, DC3, and the Republic of Korea’s National Police Agency released a joint cybersecurity advisory warning of Gunra, an aggressive Ransomware-as-a-Service (RaaS) operation derived from leaked Conti source code. The advisory highlighted a double-extortion model targeting healthcare, banking, utilities, and government infrastructure. Forensic data revealed that Gunra actors deleted backup and archive systems across both primary and disaster recovery data centers after obtaining access keys from perimeter network devices (including unpatched FortiOS firewalls).
  • Impact / Significance: Gunra combines automated network exploitation with destructive backup wiping, leaving victims without standard recovery pathways and multiplying extortion pressure. Compromising centralized identity stores allows attackers to compromise both production and failover environments simultaneously.
  • Recommendations:
    • Deploy offline, immutable, and air-gapped backups that reside in an isolated network segment with dedicated authentication credentials.
    • Patch internet-facing network appliances immediately, with specific priority on VPN gateways and firewall appliances.
    • Enforce phishing-resistant multi-factor authentication (MFA) across all administrative access points.
  • Source: CISA Cybersecurity Advisory AA26-222A — #StopRansomware: Gunra Ransomware | NSA Press Release — Guidance to Defend Against Gunra Ransomware

        4.Maximum-Severity SAP Commerce Cloud Vulnerability Faces Active Exploitation (CVE-2026-58231)

  • Summary: Security intelligence teams observed active exploitation attempts targeting CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw in SAP Commerce Cloud, just three days after SAP released its August 2026 patch update. The vulnerability stems from insufficient authorization checks and missing input validation within default authentication client handlers, enabling remote unauthenticated actors to execute arbitrary code on vulnerable servers.
  • Impact / Significance: SAP Commerce Cloud handles mission-critical enterprise e-commerce pipelines. Exploitation grants attackers the ability to compromise core application servers, alter ordering pipelines, inject payment skimmers, and exfiltrate proprietary corporate data.
  • Recommendations:
    • Apply SAP Security Note 3765948 and the corresponding August 2026 security patch immediately.
    • Audit external-facing endpoints for unauthorized access to default authentication handlers.
    • Isolate SAP management and integration adapters behind internal network zones.
    •  
  • Source: The Hacker News — SAP Commerce Cloud Targeted in Exploitation Attempts | SAP Support Portal — Security Patch Day August 2026

       5.Third-Party Supply Chain Breaches: Wesco Incident and Trezor Customer Data Exposure

  • Summary: On August 14, 2026, global supply chain and distribution corporation Wesco confirmed it is investigating a cybersecurity incident after extortion group ExfilSquad claimed theft of 2.6 million records containing customer and employee PII, CRM profiles, and authentication metadata. Separately, hardware wallet maker Trezor disclosed a breach impacting approximately 14,000 customers who placed orders between May and August 2026, caused by a compromise of its third-party shipping and logistics vendor, ShipMonk.
  • Impact / Significance: These incidents highlight third-party vendor vulnerabilities. The exposure of hardware wallet customer names and physical addresses presents distinct risks of targeted physical intimidation and highly customized social engineering attacks against cryptocurrency holders.
  • Recommendations:
    • For Organizations: Enforce strict data retention limits on third-party logistics and CRM vendors, requiring suppliers to purge customer shipping details once fulfillment completes.
    • For Individuals: Trezor customers should stay alert to postal mail scams, phone phishing, or fraudulent emails requesting seed phrase verification or hardware replacement.
  • Source: Privacy Guides — Data Breach Roundup (August 7–13, 2026)

The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.