Critical Gitea RCE Added to CISA KEV After Active Exploitation Deploys Miner Payloads
CISA added CVE-2026-60004, a critical unauthenticated-to-authenticated remote code execution flaw in self-hosted Gitea instances, to its Known Exploited Vulnerabilities catalog on August 25 after attackers were observed using it to drop cryptomining-style payloads.
Flash Briefings
All briefings →Critical Gitea RCE Added to CISA KEV After Active Exploitation Deploys Miner Payloads
CISA added CVE-2026-60004, a critical unauthenticated-to-authenticated remote code execution flaw in self-hosted Gitea instances, to its Known Exploited Vulnerabilities catalog on August 25 after attackers were observed using it to drop cryptomining-style payloads.
CVE-2026-21962: Max-Severity Oracle WebLogic Proxy Flaw Under Active Exploitation — CISA Sets 3-Day Deadline
CISA added CVE-2026-21962, a CVSS 10.0 unauthenticated bypass in the Oracle WebLogic Server Proxy Plug-in and Oracle HTTP Server, to its Known Exploited Vulnerabilities catalog on August 24, 2026 — issuing its tightest-ever three-day federal patching deadline. Attackers are chaining path traversal and header manipulation to reach backend WebLogic instances directly.
The Gentlemen Ransomware Hijacks Hospital's Facebook Page to Pressure AnMed Health
The Gentlemen ransomware group escalated its extortion of nonprofit health system AnMed by seizing control of the hospital's Facebook page to publicize ransom demands, two weeks after an initial breach claiming 6TB of patient data.
Emperador Extortion Group Claims Breach of Vietnam's Largest Power Utility
A newly surfaced extortion group calling itself Emperador claims to have breached EVNHANOI, part of Vietnam Electricity, exposing over 300GB of customer and account data. The claim is unconfirmed by EVN or Vietnamese authorities.
Deep Analysis
All analysis →SafePay: How a LockBit Code Derivative Became 2026's Most Active Ransomware Group
SafePay went from an obscure late-2024 leak site to the most active ransomware operation tracked in 2026, built on leaked LockBit code, a centralized non-affiliate model, and a deliberate focus on MSPs and their downstream clients.
UNC6671: Inside the Vishing Crew Behind BlackFile, Redact, Pink, Helix, and Falcon
A single financially motivated intrusion group has spent 2026 impersonating IT helpdesks to bypass MFA at scale, quietly cycling through five extortion brands -- and this summer set its sights on Wall Street's largest hedge funds.
The CareCloud Breach: 3.75 Million Patients Exposed in an Unattributed AWS Intrusion
New Jersey-based EHR vendor CareCloud disclosed that attackers spent six days inside an Amazon Web Services environment in March, exfiltrating Social Security numbers, government IDs, financial data, and medical records for 3.75 million patients — the fifth-largest US healthcare breach of 2026.
Commentary
All commentary →Banned in Name, Present in Network: What the House Salt Typhoon Probe Actually Found
The House Select Committee's August 2026 report on Salt Typhoon is not primarily about the hack. It is about how the regulatory framework meant to prevent it failed at the infrastructure level — and why rip-and-replace alone will not close the gap.
Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality
Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.
The Agentic Attack Surface: Your AI Assistant Is the New Endpoint
Enterprise AI assistants now hold privileged access to code repositories, cloud credentials, internal APIs, and production systems. Security teams are not monitoring them. This is a structural blind spot with material consequences — and it's arriving faster than most organisations realise.