Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: August 21, 2026 - August 21, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Friday, August 21, 2026 +229% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[HIGH]

CVE-2026-73570 — Zimbra Collaboration Suite

Command injection vulnerability in Zimbra Collaboration before version 10.1.20 with CVSS 8.9, actively exploited in the wild. Affects installations with optional zimbra-snmp package and SNMP notifications enabled. Improper sanitization allows unauthenticated attackers to execute arbitrary OS commands as zimbra user via crafted SMTP requests.

REMEDIATION

Upgrade to Zimbra Collaboration Suite 10.1.20 immediately. Check /var/log/zimbra.log for suspicious service restarts and review files created in last 30 days. Assume compromise if zimbra-snmp was installed and initiate incident response procedures.

Source: CISA  •  Published: 2026-08-17

AI & Supply Chain

[CRITICAL]

CVE-2026-64849 — MLflow AI Platform

Server-Side Request Forgery vulnerability in MLflow with CVSS 9.3, actively exploited in the wild. Unauthenticated SSRF allows attackers to send HTTP requests to internal endpoints, with confirmed incidents of AWS/GCP/Azure metadata endpoint targeting for cloud credential exfiltration. Affects all versions before 3.15.0.

REMEDIATION

Upgrade to MLflow 3.15.0 immediately. Review cloud IAM logs for unauthorized credential usage. Rotate all API keys and cloud credentials accessible from MLflow servers. Implement strict egress filtering and network segmentation.

Source: CISA  •  Published: 2026-08-21

[HIGH]

SNOWFLAKE-GITHUB-ACTIONS-2026 — Snowflake GitHub Actions Workflows

Wiz Research's Red Agent autonomous AI security agent discovered critical GitHub Actions workflow vulnerability in Snowflake's public repository. Demonstrates that AI coding agents can introduce vulnerabilities that pass automated security checks, while autonomous AI security agents can rapidly discover and exploit them.

REMEDIATION

Audit all GitHub Actions workflows for security vulnerabilities. Implement workflow approval requirements for AI-generated code. Use GitHub's dependency review action and CodeQL scanning. Restrict workflow permissions using principle of least privilege.

Source: Wiz  •  Published: 2026-06-23

[HIGH]

AI-CODING-AGENT-SUPPLY-CHAIN-2026 — AI Coding Agents (Claude Opus, GitHub Copilot)

AI coding agent supply chain attacks peaked in 2026 with North Korean APTs and autonomous worms exploiting package-verification blind spots. Legitimate Solana Graveyard Hackathon project found with malicious dependency added in commit co-authored by Claude Opus in January 2026.

REMEDIATION

Implement Software Bill of Materials (SBOM) for all dependencies. Restrict AI agents to pre-approved dependency lists in sensitive environments. Use Socket Firewall or npm staged publishing to enforce policies. Require human approval for high-impact actions.

Source: GTIG  •  Published: 2026-01-01

[HIGH]

ECHOLEAK-M365-COPILOT-2026 — Microsoft 365 Copilot

EchoLeak zero-click prompt injection vulnerability in Microsoft 365 Copilot enables silent exfiltration of enterprise data without user interaction. Demonstrates critical security risks in enterprise AI assistants.

REMEDIATION

Apply Microsoft 365 Copilot security updates. Implement data loss prevention (DLP) policies for Copilot interactions. Monitor and log all Copilot queries and responses. Restrict Copilot access to sensitive data repositories.

Source: GTIG  •  Published: 2026-05-15

[MEDIUM]

VERACODE-AI-CODE-SECURITY-2026 — AI Code Generation Tools (100+ LLMs tested)

Veracode testing of 100+ LLMs across 80 coding tasks in Java, Python, C#, and JavaScript found 45% of AI-generated code failed security tests. Java had worst performance at 72% failure rate. 86% vulnerable to XSS and 88% vulnerable to log injection.

REMEDIATION

Mandate code review for all AI-generated code. Implement automated SAST/DAST scanning in CI/CD pipelines. Train developers on secure coding practices for AI-generated patterns. Use GitHub Copilot Autofix with CodeQL integration to identify and remediate vulnerabilities.

Source: Veracode  •  Published: 2026-08-21

Threat Actors & Dark Web

[CRITICAL]

LAZARUS-FUDMODULE-2026 — Windows systems globally

North Korean Lazarus group exploited CVE-2026-68820 Windows WinSock zero-day to deploy new version of FudModule kernel-mode rootkit. Demonstrates continued advanced capability of DPRK cyber operations combining zero-day exploitation with sophisticated malware deployment.

REMEDIATION

Apply Microsoft August 2026 security updates immediately. Deploy EDR solutions capable of detecting kernel-mode rootkits. Implement application whitelisting and least privilege access. Conduct threat hunting for FudModule indicators of compromise.

Source: GTIG  •  Published: 2026-08-21

[CRITICAL]

SALT-TYPHOON-CRITICAL-INFRASTRUCTURE-2026 — Telecommunications, Transportation, Government globally

Chinese APT Salt Typhoon compromised networks in 80+ countries in 2026, targeting telecommunications, transportation, and government. Chinese actors previously dwelled in U.S. electric grid for 300 days in 2023 before discovery. Now testing fully autonomous AI-driven attack pipelines.

REMEDIATION

Implement zero trust architecture with continuous authentication. Deploy advanced threat detection and threat hunting programs. Conduct regular security assessments of critical infrastructure systems. Implement network segmentation and microsegmentation. Maintain comprehensive logging with SIEM correlation.

Source: GTIG  •  Published: 2026-08-21

[CRITICAL]

OPENSOURCE-DEV-ECOSYSTEM-ATTACKS-2026 — Aqua Security Trivy, Bitwarden, Checkmarx, OpenAI, Vercel

Series of ongoing concurrent attacks on open source developers resulted in massive hacks targeting Big Tech and customers. Compromises included Aqua Security's Trivy tool, Bitwarden, and Checkmarx in 2026, with attacks using stolen credentials to spread and enable downstream compromises of OpenAI and Vercel.

REMEDIATION

Implement hardware security keys for developer authentication. Enable audit logging for all code repositories and package registries. Conduct regular security reviews of dependencies. Implement software supply chain security scanning. Use signed commits and verify signatures.

Source: GTIG  •  Published: 2026-08-21

[CRITICAL]

AI-SCRIPTS-SIEMENS-S7-PLC-2026 — Siemens S7 Series Programmable Logic Controllers

U.S. cybersecurity agencies warn threat actors using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers in U.S. critical infrastructure, demonstrating weaponization of AI for ICS/SCADA attacks.

REMEDIATION

Update Siemens S7 PLCs to latest firmware versions. Implement network segmentation isolating ICS/SCADA networks. Deploy industrial security monitoring solutions. Restrict remote access to PLCs. Conduct regular security assessments of industrial control systems.

Source: CISA  •  Published: 2026-08-21

[HIGH]

QILIN-RANSOMWARE-CHECKPOINT-2026 — Organizations using Check Point VPN

Qilin ransomware affiliate linked with medium confidence to exploitation of Check Point CVE-2026-50751. Qilin rose to prominence by end of 2025, publicly claiming highest number of victims through open recruitment model, though suffers higher non-payment rates compared to other groups.

REMEDIATION

Apply Check Point security updates immediately. Review VPN access logs dating back to May 2026 for unauthorized access. Implement zero trust architecture with network segmentation. Deploy EDR solutions and maintain offline backups.

Source: GTIG  •  Published: 2026-06-08

[HIGH]

LAZARUS-STONEFLY-RANSOMWARE-2026 — Healthcare, Defense, Technology, Government sectors

Lazarus subgroup Stonefly (Andariel) shifted from traditional espionage to ransomware-driven extortion. U.S. indicted member Rim Jong Hyok in July 2025 over hospital attacks, with ransomware proceeds funding espionage targeting defense, tech, and government in U.S., Taiwan, and South Korea.

REMEDIATION

Implement defense-in-depth security controls. Deploy advanced threat detection for APT TTPs. Enforce network segmentation and zero trust architecture. Maintain comprehensive logging with extended retention. Conduct regular threat hunting exercises.

Source: GTIG  •  Published: 2026-08-21

[HIGH]

RUSSIAN-APT-ZIMBRA-CAMPAIGN-2026 — Western government and commercial organizations using Zimbra

Russian state-supported cyber actors targeting and compromising Western government and commercial organizations using Zimbra Collaboration Suite software since at least July 2025, continuing through 2026.

REMEDIATION

Upgrade Zimbra to version 10.1.20 immediately. Conduct forensic investigation of Zimbra servers for compromise indicators. Implement enhanced monitoring and logging. Deploy multi-factor authentication for all email access.

Source: GTIG  •  Published: 2026-07-01

[HIGH]

APT28-CVE-2026-21509-UKRAINE-2026 — Ukrainian government ministries

APT28 (Russian GRU) exploited CVE-2026-21509 in Microsoft Office via malicious DOC files targeting Ukrainian government ministries in 2026, continuing long-running campaign against Ukrainian interests.

REMEDIATION

Apply Microsoft Office security updates. Implement email security gateway with advanced threat protection. Deploy application whitelisting and disable Office macros by default. Conduct security awareness training on phishing and document-based attacks.

Source: GTIG  •  Published: 2026-08-21

[HIGH]

SHINYHUNTERS-LUMENIS-BREACH-2026 — Lumenis

ShinyHunters ransomware group targeted Lumenis, claiming to steal over 1.1 million records including customer and employee PII and over 176 GB of internal corporate data.

REMEDIATION

Organizations should implement data loss prevention (DLP) solutions, enforce encryption for sensitive data at rest and in transit, conduct regular security assessments, and maintain incident response capabilities including breach notification procedures.

Source: BleepingComputer  •  Published: 2026-08-21

[HIGH]

PASSWORD-SPRAYING-SURGE-H1-2026 — Organizations with cloud services and legacy authentication

Huntress observed 155x increase in password spraying attacks in H1 2026, including campaign generating over 81 million login attempts in two weeks. Attacks exploit legacy authentication and gaps in MFA policies leaving some login flows unprotected.

REMEDIATION

Enforce MFA across all authentication flows including legacy protocols. Disable legacy authentication where possible. Implement account lockout policies and rate limiting. Deploy advanced threat protection with behavior-based detection. Monitor authentication logs for password spraying patterns.

Source: GTIG  •  Published: 2026-08-21

[MEDIUM]

DEADLOCK-RANSOMWARE-BLOCKCHAIN-2026 — Multiple organizations

DeadLock ransomware group observed using decentralized blockchain-based infrastructure for victim communications and data leak operations to improve operational resilience and evade takedown efforts.

REMEDIATION

Implement network monitoring for blockchain-related traffic. Deploy EDR solutions with behavioral detection. Maintain comprehensive logging and incident response capabilities. Consider threat intelligence feeds tracking ransomware infrastructure.

Source: GTIG  •  Published: 2026-08-21

[MEDIUM]

FRAMEWORK-COMPUTER-BREACH-2026 — Framework Computer Customers

Framework informed all customers that hackers accessed names, email addresses, phone numbers, and physical addresses in data breach.

REMEDIATION

Implement comprehensive data protection controls including encryption, access controls, and monitoring. Deploy intrusion detection systems. Conduct regular security assessments and penetration testing. Maintain incident response capabilities with customer notification procedures.

Source: BleepingComputer  •  Published: 2026-08-21

AI & Cybersecurity News

[INFO]

EU-AI-ACT-IMPLEMENTATION-2026 — Organizations deploying AI systems in EU market

EU AI Act high-risk AI system provisions applied from August 2, 2026. Digital Omnibus Regulation (EU) 2026/1744 deferred standalone high-risk AI compliance to December 2, 2027 and embedded AI to August 2, 2028. Major obligations include continuous risk management, data governance with inference-time protections, technical documentation, tamper-evident logging (6 months minimum), transparency, human oversight, cybersecurity resilience, quality management, and post-market monitoring.

REMEDIATION

Organizations deploying AI in EU must implement required technical controls immediately: establish risk management systems, implement data governance frameworks, create technical documentation, deploy tamper-evident logging with 6-month retention, ensure human oversight capabilities, implement cybersecurity controls, establish quality management systems, and begin post-market monitoring.

Source: GTIG  •  Published: 2026-08-02

[INFO]

MICROSOFT-AI-PATCH-TUESDAY-INCREASE-2026 — Organizations using Microsoft products

Microsoft warned Patch Tuesday security updates could increase as it began using AI-powered vulnerability discovery system. August 2026 volume of 421 CVEs represents continuation of elevated disclosure rates driven by AI-enhanced security testing.

REMEDIATION

Organizations should enhance patch management capabilities to handle increased volume of security updates. Implement automated patch testing and deployment workflows. Prioritize patches based on CVSS scores, exploitation status, and business impact.

Source: MSRC  •  Published: 2026-08-21

[INFO]

GITHUB-OUTAGE-COPILOT-2026 — GitHub and GitHub Copilot users

GitHub experienced three hour nineteen minute outage on August 17, 2026, with ~20% of requests returning errors and ~50% of archive downloads and raw repository content failing. GitHub Copilot remained down after other services recovered, demonstrating dependency risks of AI development tools.

REMEDIATION

Organizations should implement redundancy for critical development tools, maintain local mirrors of essential repositories, establish offline development capabilities, and develop contingency procedures for AI tool unavailability.

Source: GitHub  •  Published: 2026-08-17

[INFO]

NIST-AI-NVD-MODERNIZATION-2026 — NIST National Vulnerability Database

NIST published RFI seeking input on modernizing National Vulnerability Database by leveraging AI to enhance documentation and response to cybersecurity weaknesses. Demonstrates government adoption of AI for security operations.

REMEDIATION

Security organizations should monitor NIST guidance development and participate in public comment periods. Prepare for AI-enhanced vulnerability disclosure processes and adjust vulnerability management workflows accordingly.

Source: NIST  •  Published: 2026-08-12

[INFO]

NIST-AI-CSF-QUICKSTART-2026 — Organizations using NIST Cybersecurity Framework

NIST released initial public draft of Special Publication 1353, Quick-Start Guide for Using Artificial Intelligence for CSF Analysis and Reporting. Public comment period open through October 15, 2026.

REMEDIATION

Organizations should review draft SP 1353 and provide comments during public comment period. Begin planning for integration of AI tools into cybersecurity framework analysis and reporting processes.

Source: NIST  •  Published: 2026-08-12

Priority Action Matrix

01DO NOWCVE-2026-64849 (MLflow AI Platform): Upgrade to MLflow 3.15.0 immediately. Review cloud IAM logs for unauthorized credential usage. Rotate all API keys and cloud credentials accessible from MLflow servers. Implement strict egress filteri...
02DO NOWLAZARUS-FUDMODULE-2026 (Windows systems globally): Apply Microsoft August 2026 security updates immediately. Deploy EDR solutions capable of detecting kernel-mode rootkits. Implement application whitelisting and least privilege access. Conduct threat ...
03DO NOWSALT-TYPHOON-CRITICAL-INFRASTRUCTURE-2026 (Telecommunications, Transportation, Government globally): Implement zero trust architecture with continuous authentication. Deploy advanced threat detection and threat hunting programs. Conduct regular security assessments of critical infrastructure systems....
04DO NOWOPENSOURCE-DEV-ECOSYSTEM-ATTACKS-2026 (Aqua Security Trivy, Bitwarden, Checkmarx, OpenAI, Vercel): Implement hardware security keys for developer authentication. Enable audit logging for all code repositories and package registries. Conduct regular security reviews of dependencies. Implement softwa...
05DO NOWAI-SCRIPTS-SIEMENS-S7-PLC-2026 (Siemens S7 Series Programmable Logic Controllers): Update Siemens S7 PLCs to latest firmware versions. Implement network segmentation isolating ICS/SCADA networks. Deploy industrial security monitoring solutions. Restrict remote access to PLCs. Conduc...
06TODAYCVE-2026-73570 (Zimbra Collaboration Suite): Upgrade to Zimbra Collaboration Suite 10.1.20 immediately. Check /var/log/zimbra.log for suspicious service restarts and review files created in last 30 days. Assume compromise if zimbra-snmp was inst...
07TODAYSNOWFLAKE-GITHUB-ACTIONS-2026 (Snowflake GitHub Actions Workflows): Audit all GitHub Actions workflows for security vulnerabilities. Implement workflow approval requirements for AI-generated code. Use GitHub's dependency review action and CodeQL scanning. Restrict wor...
08TODAYAI-CODING-AGENT-SUPPLY-CHAIN-2026 (AI Coding Agents (Claude Opus, GitHub Copilot)): Implement Software Bill of Materials (SBOM) for all dependencies. Restrict AI agents to pre-approved dependency lists in sensitive environments. Use Socket Firewall or npm staged publishing to enforce...
09TODAYECHOLEAK-M365-COPILOT-2026 (Microsoft 365 Copilot): Apply Microsoft 365 Copilot security updates. Implement data loss prevention (DLP) policies for Copilot interactions. Monitor and log all Copilot queries and responses. Restrict Copilot access to sens...
10TODAYQILIN-RANSOMWARE-CHECKPOINT-2026 (Organizations using Check Point VPN): Apply Check Point security updates immediately. Review VPN access logs dating back to May 2026 for unauthorized access. Implement zero trust architecture with network segmentation. Deploy EDR solution...
11TODAYLAZARUS-STONEFLY-RANSOMWARE-2026 (Healthcare, Defense, Technology, Government sectors): Implement defense-in-depth security controls. Deploy advanced threat detection for APT TTPs. Enforce network segmentation and zero trust architecture. Maintain comprehensive logging with extended rete...
12TODAYRUSSIAN-APT-ZIMBRA-CAMPAIGN-2026 (Western government and commercial organizations using Zimbra): Upgrade Zimbra to version 10.1.20 immediately. Conduct forensic investigation of Zimbra servers for compromise indicators. Implement enhanced monitoring and logging. Deploy multi-factor authentication...
13TODAYAPT28-CVE-2026-21509-UKRAINE-2026 (Ukrainian government ministries): Apply Microsoft Office security updates. Implement email security gateway with advanced threat protection. Deploy application whitelisting and disable Office macros by default. Conduct security awaren...
14TODAYSHINYHUNTERS-LUMENIS-BREACH-2026 (Lumenis): Organizations should implement data loss prevention (DLP) solutions, enforce encryption for sensitive data at rest and in transit, conduct regular security assessments, and maintain incident response ...
15TODAYPASSWORD-SPRAYING-SURGE-H1-2026 (Organizations with cloud services and legacy authentication): Enforce MFA across all authentication flows including legacy protocols. Disable legacy authentication where possible. Implement account lockout policies and rate limiting. Deploy advanced threat prote...
16THIS WEEKVERACODE-AI-CODE-SECURITY-2026 (AI Code Generation Tools (100+ LLMs tested)): Mandate code review for all AI-generated code. Implement automated SAST/DAST scanning in CI/CD pipelines. Train developers on secure coding practices for AI-generated patterns. Use GitHub Copilot Auto...
17THIS WEEKDEADLOCK-RANSOMWARE-BLOCKCHAIN-2026 (Multiple organizations): Implement network monitoring for blockchain-related traffic. Deploy EDR solutions with behavioral detection. Maintain comprehensive logging and incident response capabilities. Consider threat intellig...
18THIS WEEKFRAMEWORK-COMPUTER-BREACH-2026 (Framework Computer Customers): Implement comprehensive data protection controls including encryption, access controls, and monitoring. Deploy intrusion detection systems. Conduct regular security assessments and penetration testing...

Biggest Risk This Period

BIGGEST RISK

CVE-2026-64849: Server-Side Request Forgery vulnerability in MLflow with CVSS 9.3, actively exploited in the wild. Unauthenticated SSRF allows attackers to send HTTP requests to internal endpoints, with confirmed incidents of AWS/GCP/Azure metadata endpoint targeting for cloud credential exfiltration. Affects all versions before 3.15.0.